ISMS Copilot

Learn

Do I need Cyber Essentials?

A UK tender applicability guide. Not a certifier pitch, and not a legal duty on every UK company.

Last reviewed 2026-09-17. Next review 2026-12-17, or sooner if PPN 014 is replaced or the NCSC scheme version changes. Vendor-neutral. Not a certification body.

1. It is a contract question, not a company-type question

Cyber Essentials is a UK government-backed scheme (NCSC, delivered by IASME). It is not a statute that binds every UK company the way UK GDPR binds a UK controller. Start with the tender pack. For public contracts covered by PPN 014, the buyer must accept demonstrated equivalent controls. Private purchasers can insist on the named scheme, and other public buyers follow their own procurement law and guidance. Evidence of the equivalent still has to match what the pack asked for.

2. Read PPN 014, not a blog that says 'mandatory for government'

Cabinet Office PPN 014 tells in-scope contracting authorities (including NHS bodies in that PPN) to take a proportionate approach. They can require Cyber Essentials, Plus, or equivalent controls, and they must accept demonstrated equivalents. Independent, technically competent verification is normally expected for a CE-equivalent case and required for a Plus-equivalent case (PPN 014 Annex C). Ministry of Defence work uses Cyber Security Model v4 and Defence Cyber Certification. DCC still includes the appropriate CE or CE Plus baseline for applicable business-critical systems (CE for all levels, CE Plus for levels 2 and 3, per IASME). It is not a substitute that always drops CE, and it is not a blanket defence-adjacent rule.

3. CE and CE Plus are certification levels

Cyber Essentials is a self-assessment against five technical themes, submitted to a certification body. Cyber Essentials Plus adds a hands-on technical verification. That is a certification level inside the scheme, not a philosophy debate. ISO 27001 comparison lives on Cyber Essentials vs ISO 27001.

4. Scope the network the certificate will cover

The certificate is scoped. Whole-company, a named network, or a service boundary: the tender usually says which. An out-of-scope laptop that still handles the contract data is a scope risk assessors look for. Prepare the five themes against the scoped environment, not against a generic office.

5. A licensed body issues the certificate. A copilot does not.

IASME-backed certification bodies issue Cyber Essentials and Plus. ISMS Copilot drafts a five-theme preparation pack from the requirements you supply. It does not complete the IASME question set, run the Plus test, or certify you. Product page: Cyber Essentials Copilot.

Decision table

Look atIf you seeThen
PurchaserIn-scope PPN 014 authority, including NHS bodies in that PPNProportionate CE, Plus, or demonstrated equivalent. Equivalents must be accepted
Other buyersPPN 014 does not bind themPrivate buyers follow the contract they wrote. Other public buyers follow their own procurement law and guidance, so check the pack before assuming CE alone
LevelCE or CE PlusPlus adds a hands-on technical verification by a certification body
ScopeNamed network or whole organisationThe certificate boundary must match the environment the contract covers
MODCSM v4 / DCC namedSeparate regime. DCC still includes the appropriate CE or CE Plus baseline for applicable business-critical systems (CE all levels, CE Plus for levels 2 and 3)

UK hub: ISMS Copilot for UK compliance teams. SaaS buying page: UK SaaS companies.

FAQ

Do all UK companies need Cyber Essentials?

No. There is no general legal duty. PPN 014 is the buyer-side rule for in-scope public contracts, including NHS bodies in that PPN, not a Companies House obligation. Those buyers must accept demonstrated equivalents. Private purchasers follow the contract they wrote.

If the tender allows equivalent controls, can we skip CE?

For PPN 014 public contracts, the buyer must accept demonstrated equivalents. Independent, technically competent verification is normally expected for a CE-equivalent case and required for a Plus-equivalent case (PPN 014 Annex C). Private buyers can refuse equivalents if the contract names CE only. Do not assume ISO 27001 automatically counts unless the pack says so.

We already hold ISO 27001. Does that satisfy a Cyber Essentials requirement?

Only where the pack accepts demonstrated equivalents. A PPN 014 buyer must accept them, with independent, technically competent verification normally expected at CE level and required at Plus level. A private buyer that names CE only can refuse. Where equivalents are accepted, map your ISO controls to the five technical themes inside the certificate scope. The maturity comparison is a separate question.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.