Learn
Do I need Cyber Essentials?
A UK tender applicability guide. Not a certifier pitch, and not a legal duty on every UK company.
Last reviewed 2026-09-17. Next review 2026-12-17, or sooner if PPN 014 is replaced or the NCSC scheme version changes. Vendor-neutral. Not a certification body.
1. It is a contract question, not a company-type question
Cyber Essentials is a UK government-backed scheme (NCSC, delivered by IASME). It is not a statute that binds every UK company the way UK GDPR binds a UK controller. Start with the tender pack. For public contracts covered by PPN 014, the buyer must accept demonstrated equivalent controls. Private purchasers can insist on the named scheme, and other public buyers follow their own procurement law and guidance. Evidence of the equivalent still has to match what the pack asked for.
2. Read PPN 014, not a blog that says 'mandatory for government'
Cabinet Office PPN 014 tells in-scope contracting authorities (including NHS bodies in that PPN) to take a proportionate approach. They can require Cyber Essentials, Plus, or equivalent controls, and they must accept demonstrated equivalents. Independent, technically competent verification is normally expected for a CE-equivalent case and required for a Plus-equivalent case (PPN 014 Annex C). Ministry of Defence work uses Cyber Security Model v4 and Defence Cyber Certification. DCC still includes the appropriate CE or CE Plus baseline for applicable business-critical systems (CE for all levels, CE Plus for levels 2 and 3, per IASME). It is not a substitute that always drops CE, and it is not a blanket defence-adjacent rule.
3. CE and CE Plus are certification levels
Cyber Essentials is a self-assessment against five technical themes, submitted to a certification body. Cyber Essentials Plus adds a hands-on technical verification. That is a certification level inside the scheme, not a philosophy debate. ISO 27001 comparison lives on Cyber Essentials vs ISO 27001.
4. Scope the network the certificate will cover
The certificate is scoped. Whole-company, a named network, or a service boundary: the tender usually says which. An out-of-scope laptop that still handles the contract data is a scope risk assessors look for. Prepare the five themes against the scoped environment, not against a generic office.
5. A licensed body issues the certificate. A copilot does not.
IASME-backed certification bodies issue Cyber Essentials and Plus. ISMS Copilot drafts a five-theme preparation pack from the requirements you supply. It does not complete the IASME question set, run the Plus test, or certify you. Product page: Cyber Essentials Copilot.
Decision table
| Look at | If you see | Then |
|---|---|---|
| Purchaser | In-scope PPN 014 authority, including NHS bodies in that PPN | Proportionate CE, Plus, or demonstrated equivalent. Equivalents must be accepted |
| Other buyers | PPN 014 does not bind them | Private buyers follow the contract they wrote. Other public buyers follow their own procurement law and guidance, so check the pack before assuming CE alone |
| Level | CE or CE Plus | Plus adds a hands-on technical verification by a certification body |
| Scope | Named network or whole organisation | The certificate boundary must match the environment the contract covers |
| MOD | CSM v4 / DCC named | Separate regime. DCC still includes the appropriate CE or CE Plus baseline for applicable business-critical systems (CE all levels, CE Plus for levels 2 and 3) |
UK hub: ISMS Copilot for UK compliance teams. SaaS buying page: UK SaaS companies.
Sources
All sources checked 2026-09-18.
- Cabinet Office, PPN 014: Cyber Essentials scheme (proportionate contract assessment, equivalent controls permitted, Annex C verification expectations)
- NCSC, Cyber Essentials (scheme owner)
- IASME, Defence Cyber Certification FAQ (CE for all levels, CE Plus for levels 2 and 3)
- GOV.UK, Cyber Security Model (MOD CSM v4 / Defence Cyber Certification is a separate regime)
- GOV.UK, Procurement Act 2023 guidance, defining phase: technical specifications (public buyers outside PPN 014 follow their own procurement law)
FAQ
Do all UK companies need Cyber Essentials?
No. There is no general legal duty. PPN 014 is the buyer-side rule for in-scope public contracts, including NHS bodies in that PPN, not a Companies House obligation. Those buyers must accept demonstrated equivalents. Private purchasers follow the contract they wrote.
If the tender allows equivalent controls, can we skip CE?
For PPN 014 public contracts, the buyer must accept demonstrated equivalents. Independent, technically competent verification is normally expected for a CE-equivalent case and required for a Plus-equivalent case (PPN 014 Annex C). Private buyers can refuse equivalents if the contract names CE only. Do not assume ISO 27001 automatically counts unless the pack says so.
We already hold ISO 27001. Does that satisfy a Cyber Essentials requirement?
Only where the pack accepts demonstrated equivalents. A PPN 014 buyer must accept them, with independent, technically competent verification normally expected at CE level and required at Plus level. A private buyer that names CE only can refuse. Where equivalents are accepted, map your ISO controls to the five technical themes inside the certificate scope. The maturity comparison is a separate question.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
