← Back to Blog
Cybersecurity

Do I Need Cyber Essentials for Government Contracts?

10 September 2026 · By Ethan Fernandes

Do I Need Cyber Essentials for Government Contracts?

Yes, for most UK government contracts involving sensitive data. Here's exactly which contracts require it, the 2014 mandate, MOD rules, and how to get certified.

The short answer: yes, for most government contracts. Since October 2014, the UK government has required suppliers to hold Cyber Essentials certification for contracts that involve handling sensitive and personal information or providing certain technical products and services. If you're bidding on government work, you almost certainly need it.

The UK government's position is clear: if you want to handle government data or connect to government systems, you need to demonstrate a minimum level of cybersecurity. Cyber Essentials is that minimum.

The 2014 Government Mandate

In October 2014, the UK government introduced a requirement that suppliers bidding for central government contracts must hold Cyber Essentials certification where the contract involves:

  • Handling personal information of government employees or citizens
  • Handling sensitive government data that is not otherwise classified
  • Providing IT products or services to government

This applies to contracts with central government departments, their agencies, and non-departmental public bodies. The requirement appears in the tender documentation, usually as a mandatory pass/fail criterion — if you don't have it, your bid isn't evaluated.

The mandate was part of the government's National Cyber Security Strategy and was designed to raise the baseline security level across the public sector supply chain. It's been in effect for over a decade now, and the requirement has only become more widespread.

Which Contracts Require It?

Not every government contract requires Cyber Essentials, but most do. Here's how to tell:

Contracts That Almost Always Require CE

  • Any contract handling personal data — if you'll process names, addresses, NI numbers, health records, or any other personal information on behalf of a government body
  • IT service contracts — managed IT, cloud services, software development, hosting, consultancy
  • Contracts connected to government networks — if your systems will connect to or integrate with government IT infrastructure
  • Defence contracts — the MOD has additional requirements (see below)
  • NHS and healthcare contracts — particularly those involving patient data or connecting to NHS systems

Contracts That May Not Require CE

  • Commodity supplies with no data handling — office furniture, physical supplies, catering (though even these are increasingly including it)
  • Very low-value contracts — some procurement frameworks have a threshold below which CE isn't mandated
  • Local authority contracts — local councils aren't bound by the central government mandate, but many have adopted it voluntarily, and the trend is clearly toward requiring it

When in doubt, check the tender documentation. If Cyber Essentials is required, it will be stated explicitly in the requirements or pre-qualification questionnaire.

MOD and Defence Requirements

The Ministry of Defence takes this further. For defence contracts:

MOD requirement: All MOD suppliers and their subcontractors that handle MOD information or connect to MOD systems must hold Cyber Essentials as a minimum. For contracts involving more sensitive data, Cyber Essentials Plus or additional controls under the Defence Cyber Protection Partnership (DCPP) framework may be required.

The MOD's Defence Supplier Cyber Protection Partnership categorises contracts into risk profiles, with corresponding security requirements:

  • Low risk: Cyber Essentials (standard) required
  • Moderate risk: Cyber Essentials Plus required, plus additional controls
  • High risk and above: More comprehensive security frameworks apply (ISO 27001, specific MOD standards)

If you're anywhere in the defence supply chain — even as a subcontractor to a subcontractor — Cyber Essentials is effectively mandatory.

Supply Chain Requirements

It's not just direct government contracts. The requirement flows down the supply chain:

  • Prime contractors bidding on government work increasingly require their subcontractors to hold Cyber Essentials
  • Framework agreements (G-Cloud, Digital Outcomes and Specialists, Crown Commercial Service frameworks) often require CE as a condition of being on the framework
  • Large organisations with government clients often require their suppliers to hold CE as part of their own compliance obligations

Even if you don't bid on government contracts directly, your clients might — and their procurement team may require you to hold CE as part of their supply chain assurance.

CE or CE Plus: Which Level Do You Need?

Most government contracts that require Cyber Essentials accept the standard (self-assessment) level. However:

  • Some MOD contracts specifically require Cyber Essentials Plus
  • Higher-risk contracts may specify CE+ as the minimum
  • Some framework agreements score CE+ higher than CE in the evaluation

Check the specific contract requirements. If it just says "Cyber Essentials," the standard level is sufficient. If it says "Cyber Essentials Plus," you need the audited version.

Timeline: How Long Does Certification Take?

If you need Cyber Essentials for an upcoming bid, here's a realistic timeline:

If your IT is already well-managed:

  • Gap assessment: 1-2 days
  • Remediation of minor issues: 1-2 weeks
  • Complete self-assessment questionnaire: 1-2 days
  • Assessment and certification: 1-2 weeks
  • Total: 2-4 weeks

If significant gaps exist:

  • Gap assessment: 1-2 days
  • Remediation (implementing MFA, updating devices, configuring firewalls, addressing BYOD): 2-6 weeks
  • Complete self-assessment: 1-2 days
  • Assessment and certification: 1-2 weeks
  • Total: 4-8 weeks

For CE Plus, add 2-4 weeks for the technical audit scheduling and any remediation from audit findings.

12 months — how long a Cyber Essentials certificate is valid. You need to recertify annually to maintain compliance.

What If You Don't Have It?

If a contract requires Cyber Essentials and you don't have it, your bid will typically be rejected at the pre-qualification stage. It's a binary requirement — you either have a valid certificate or you don't.

Some procurement frameworks allow you to demonstrate that certification is "in progress," but this is becoming less common. Most now require a valid certificate at the time of bid submission.

The certificate must also be current — Cyber Essentials certification is valid for 12 months, so you need to recertify annually. An expired certificate is treated the same as no certificate.

Getting Certified

The process is straightforward:

  1. Choose a certification body. IASME is the sole accreditation body, but assessment is delivered through licensed certification bodies. Your IT provider can typically handle this for you.
  2. Assess your current state. Identify gaps against the five Cyber Essentials controls (firewalls, secure configuration, user access control, malware protection, patch management).
  3. Remediate gaps. Fix what needs fixing — enable MFA, patch devices, configure firewalls, address BYOD.
  4. Complete the self-assessment. Answer the questionnaire accurately, describing your actual setup.
  5. Submit for assessment. The certification body reviews your answers and either certifies you or identifies issues to address.

Key takeaway: If you're bidding on government contracts that involve handling data, providing IT services, or working in the defence supply chain, Cyber Essentials is almost certainly required. It's been mandatory for most central government contracts since 2014, the requirement flows down the supply chain, and you need to recertify every 12 months. Start the process at least 4-6 weeks before you need the certificate.

We help businesses achieve both Cyber Essentials and Cyber Essentials Plus certification — from initial gap assessment through to successful certification and annual recertification. If you have a bid deadline approaching, get in touch and we'll tell you how quickly we can get you there.

Want to talk about this?

Book a free 15-minute call and we'll discuss how this applies to your business.

Get IT tips in your inbox

Practical advice for small businesses. No spam.