Enquiries: +44 (0) 20 8584 1400

CONTACT

Do You Need Cyber Essentials to Win Government Contracts?

cyber essentials government contracts

The cyber security question sits on page 40 of the tender pack. Your bid team finds it three days before submission. Nobody holds a certificate, and the portal wants evidence uploaded by Friday.

That scramble is avoidable. Cyber Essentials government contracts requirements come from a single document, Procurement Policy Note 014, and they are narrower than the panic suggests.

Cyber Essentials is required for UK government contracts handling citizen or government personnel data, OFFICIAL-level ICT systems, or government business information. Procurement Policy Note 014 applies this across central government departments, executive agencies, non-departmental public bodies and NHS bodies. Evidence is needed before data passes to the supplier.

Is Cyber Essentials Required for Government Contracts in the UK?

Yes, for a large share of public sector work, though not for all of it. PPN 014 tells in-scope buyers to require Cyber Essentials-level controls whenever a contract carries certain characteristics. If your contract carries none of them, the requirement does not apply to you at all.

PPN 014 names four triggers:

  • Citizen data, described as “personal information of citizens, such as home addresses, bank details, or payment information”.
  • Government personnel data, covering “personal information of government employees, ministers and special advisors”.
  • OFFICIAL-level systems, where “ICT systems and services are supplied which are designed to store, or process data at the OFFICIAL level”.
  • Government business information, meaning contracts that deal with the day-to-day business of Government, service delivery and public finances.

The Cyber Essentials government contracts test is the shape of the contract, not its value. A catering contract with no data flow is a different proposition to a case management system, and both can sit with the same buyer.

Do You Need Cyber Essentials to Bid for Public Sector Work?

Not always at the bid stage. PPN 014 ties the evidence to a later point, stating that a certificate “is essential at the point when data is to be passed to the supplier”. In practice that means award. Plenty of buyers still ask at selection stage, so read the specific pack rather than the general rule.

The distinction matters commercially. If the certificate is only needed at award, you can bid honestly with certification in progress and time the assessment against the award date. If the pack makes it a pass or fail selection question, and many do, an uncertified bid is dead on arrival whatever your price.

The safe reading is to treat it as required from the moment you decide to bid. Certification takes weeks from a well-run estate and months from a neglected one, and no buyer moves an award date to accommodate a supplier. Most Cyber Essentials government contracts problems are timing problems wearing a compliance badge.

Bidding for Public Sector Work Without a Certificate?

Cyber Essentials tests firewalls, secure configuration, security update management, user access control and malware protection. Those five controls are what Transputec runs day to day for UK clients. Tell us what your estate looks like and the award date you are working to, and we will map it against those controls before an assessor does. Cyber Essentials government contracts deadlines do not move, but the readiness work is the part you control.

Get a Strategic Consultation

What Does PPN 014 Actually Require?

PPN 014 requires in-scope buyers to apply effective and proportionate cyber security controls to contracts that carry supply chain risk, normally satisfied by Cyber Essentials or Cyber Essentials Plus certification. It was published on 17 February 2025, applies from 24 February 2025, and replaces PPN 09/14 and PPN 09/23.

It is the source document for Cyber Essentials government contracts requirements, and three details in it carry more weight than the headline rule.

  • Equivalence is allowed. Where a supplier holds neither certificate, they “must be able to demonstrate equivalent controls are in place through other means”. That route exists, but it puts the burden of proof on you and slows evaluation down.
  • Subcontractors are in scope. The Model Services Contract requires the supplier and relevant subcontractors to hold Cyber Essentials or Cyber Essentials Plus. Your certificate does not cover your delivery partners.
  • Certificates expire. Suppliers must recertify every 12 months to keep a valid certificate, so a lapse part-way through a contract is a compliance problem rather than an administrative one.

Anyone still quoting PPN 09/23 in a bid library is working from a superseded document. Read the current note in full on GOV.UK before your next submission.

Which Contracts Require Cyber Essentials Plus?

Cyber Essentials Plus applies where the buyer judges there to be a higher risk of cyber security threats. PPN 014 publishes no value threshold and no fixed list of contract types, so the trigger is the buyer’s own risk assessment, written into the tender documents. Read the specification rather than a rule of thumb.

RouteHow it is assessedWhen a buyer asks for it
Cyber EssentialsVerified self-assessment questionnaire, marked by a qualified assessorThe default position for in-scope contracts under PPN 014
Cyber Essentials PlusThe same question set plus remote and on-site vulnerability testing by the assessorWhere the buyer’s risk assessment flags higher cyber security risk
Equivalent controlsEvidence presented by the supplier and judged by the buyerWhere a supplier holds neither certificate but can prove the controls are in place

The practical difference is testing. Cyber Essentials takes your word for it once an assessor has marked the answers. Cyber Essentials Plus sends someone to check, which is why it costs more and takes longer to arrange. Our guide to Cyber Essentials Plus covers what the audit involves, and the cost breakdown sets out the fees for both.

Is There a Separate MOD Cyber Essentials Requirement?

Yes. The MOD Cyber Essentials requirement does not run through PPN 014 at all. Defence contracts use the Cyber Security Model, applied through DEFCON 658, and the controls come from Defence Standard 05-138 at whichever cyber risk profile level the contract is assessed at. Holding the certificate alone may not answer it.

How it works in practice:

  • The contract gets a risk profile. DEFCON 658 must be included in all MOD contracts with a Cyber Risk Profile higher than “Not Applicable”, and Def Stan 05-138 sets the controls required at each level.
  • You complete an SAQ. Where DEFCON 658 applies, tenderers complete a Supplier Assurance Questionnaire on the MOD’s Supplier Cyber Protection Service as part of the tender response.
  • It flows all the way down. Flow down runs from the prime contractor to their subcontractors “and onwards down the sub-contracting tiers to the end of the supply chain”. Third-tier suppliers get caught by this constantly.
  • A gap is not automatically fatal. A supplier who cannot yet meet the requirements submits a Cyber Improvement Plan setting out when they will.

So defence sits outside the usual Cyber Essentials government contracts route, and the certificate is the floor rather than the finish line. The process is documented in the Cyber Security Model guidance. Transputec holds JOSCAR alongside Cyber Essentials Plus, which is the pairing defence buyers ask about first.

Is Cyber Essentials Mandatory Across the Whole Public Sector?

No. Cyber Essentials is mandatory only for the bodies PPN 014 binds, which are “all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies”. Local authorities, universities, housing associations and devolved bodies sit outside that list and set their own supplier requirements.

That is why Cyber Essentials public sector requirements look inconsistent from one buyer to the next. Inconsistent does not mean absent. Three routes pull the certificate into contracts PPN 014 never touches:

  • Framework terms. Buyers purchasing through Crown Commercial Service agreements inherit the security requirements written into the framework, whoever they are.
  • Prime contractor flow-down. If your customer holds a government contract, their obligations arrive as your contract terms.
  • Local policy copying central policy. Many councils and NHS trusts adopt the central government position because it is easier to defend than writing their own.

A supplier serving public sector customers usually needs the certificate even where no single rule mandates it. Transputec sits on G-Cloud 14 and TePAS 2 (RM6098) and holds Cyber Essentials Plus, ISO 27001 and NHS DSPT, because buyers on those routes ask for the evidence pack at award. Our public sector IT procurement page sets out the framework detail.

How Long Does Certification Take Before a Bid Deadline?

Assume weeks, and longer if your estate has gaps. The assessment itself is quick once you submit. The readiness work in front of it is what takes the time: retiring unsupported software, switching on multi-factor authentication everywhere, getting update management under control. None of that compresses to fit a deadline.

The scheme is also getting stricter. IASME has released a new question set, Danzell, replacing Willow. It applies to all assessment accounts created after 26 April 2026, alongside Cyber Essentials Requirements for IT Infrastructure v3.3. Two changes matter if you are planning a bid around it:

  • MFA is now a hard fail. Multi-factor authentication is mandatory for all cloud services where it is available, and organisations that have not implemented it will automatically fail the assessment.
  • Patching windows are enforced. Two new questions, A6.4 and A6.5, make it an automatic failure if high-risk or critical security updates are not installed within 14 days of release across operating systems, router and firewall firmware, and applications.

Both are set out in the IASME update. If your patching runs on a monthly cycle with exceptions, that is now a certification risk rather than a housekeeping one. Certificates last twelve months, so put the recertification date in the same calendar as your framework renewals. A certificate that lapses mid-contract is one of the commonest Cyber Essentials government contracts failures.

Your Cyber Essentials Government Contracts Checklist

Work through this before you commit to a bid. Most Cyber Essentials government contracts decisions come down to four things: whether the contract triggers the requirement, which certificate it names, whether your subcontractors are covered, and whether the timing works. This checklist is the shortest route from “do we qualify” to an answer you can defend.

  1. Find the trigger in the tender pack. Check it against the four PPN 014 characteristics, and note whether evidence is wanted at selection or at award.
  2. Confirm which certificate. Cyber Essentials or Cyber Essentials Plus, taken from the specification rather than assumed.
  3. Check your subcontractors. Delivery partners handling the same data need certificates of their own.
  4. Inventory every device and cloud service. Home workers’ laptops and the SaaS tools nobody in IT owns are where scope disputes start.
  5. Retire unsupported software first. It has no workaround and it fails you on its own.
  6. Switch on MFA everywhere it is available. Under the Danzell question set this is pass or fail.
  7. Evidence 14-day patching. Operating systems, firmware and applications, with proof rather than intent.
  8. Book the assessment against the award date, not the submission date, and leave room for a re-mark.
  9. Diarise recertification twelve months out, so the certificate stays live for the contract term.

Organisations on managed IT services with central patching and device configuration clear this list quickly, because the controls already run as business as usual. Everyone else finds out how long twelve months of drift takes to undo.

Conclusion

The honest answer to the Cyber Essentials government contracts question is that it depends on the contract, and the tender pack tells you which one you are in. If the work touches citizen data, government personnel data, OFFICIAL systems or the day-to-day business of government, expect to need it. If you are bidding into defence, expect the Cyber Security Model on top of it.

What sinks bids is rarely the rule. It’s the timing. A certificate is achievable in weeks from a well-run estate and takes months from a neglected one, and the award date does not move either way. Suppliers who treat the five controls as ongoing operational hygiene bid whenever they like. Suppliers who treat certification as a bid task find out the difference at the worst possible moment.

Getting to the first position is an IT estate problem rather than a paperwork one. Transputec keeps those controls running through cyber security services and day-to-day managed IT for UK organisations bidding into government, defence and the NHS. If you have an award date in mind and no certificate yet, talk to our UK team.

FAQs

No. Cyber Essentials government contracts rules apply where the contract carries one of the characteristics named in Procurement Policy Note 014: citizen data, government personnel data, OFFICIAL-level ICT systems, or government business information. Contracts with none of those are out of scope. PPN 014 binds central government departments, their executive agencies, non-departmental public bodies and NHS bodies.

PPN 014 ties the evidence to the point at which data is passed to the supplier, which usually means award rather than submission. Many buyers still ask at selection stage as a pass or fail question, so read the specific pack. Treating it as required from the bid decision is the safer approach.

Contracts where the buyer’s risk assessment identifies a higher risk of cyber security threats. There is no published value threshold, so the trigger sits in the tender documents rather than in a general rule. Cyber Essentials Plus adds remote and on-site vulnerability testing to the same question set.

Defence contracts use the Cyber Security Model rather than PPN 014. DEFCON 658 is included where a contract’s Cyber Risk Profile is higher than “Not Applicable”, tenderers complete a Supplier Assurance Questionnaire, and the controls come from Def Stan 05-138 at the assessed level. The obligations flow down through every subcontracting tier.

No. The Model Services Contract requires the supplier and relevant subcontractors to hold Cyber Essentials or Cyber Essentials Plus, so check your delivery partners’ certificates and expiry dates before naming them in a bid. Our certifications page lists what Transputec holds.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his “straight-talking” approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch