Do I need Cyber Essentials?
Cyber Essentials is the UK government-backed baseline for cyber security. It is voluntary, except that UK central government and NHS buyers require it, or equivalent controls, for contracts that handle personal or OFFICIAL data. Answer four questions to see whether you need it, and whether Plus.
You need Cyber Essentials, or proof of equivalent controls, to win UK central government or NHS contracts that handle citizens' or officials' personal data or OFFICIAL information, under Procurement Policy Note 014. Otherwise it is voluntary, though a growing number of UK buyers ask for it. It certifies five technical controls, renews every year, and Plus adds an independent technical audit.
Result
PPN 014 tells central government departments, their agencies and NHS bodies to require suppliers on contracts like this to meet the Cyber Essentials technical requirements, most simply by holding Cyber Essentials or Plus. You must hold it by the time data passes to you, and renew it every year of the contract. Without it, you must show equivalent controls another way.
- Scope: include every device and cloud service that reaches organisational data, BYOD included. Cloud services cannot be excluded, and a scope without end-user devices is not accepted.
- Prepare: download the current question set from IASME and close the gaps first: unsupported software, missing MFA on cloud services, and patches older than 14 days are the common failures.
- Certify: submit the self-assessment through a certification body. For Plus, the certification body then tests your systems remotely and on site.
What Cyber Essentials is
Cyber Essentials is a UK government-backed certification, run by the NCSC with IASME as its delivery partner, covering five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Basic Cyber Essentials is a self-assessment questionnaire verified by a certification body. Cyber Essentials Plus checks the same controls but adds remote and on-site vulnerability testing. Both renew every year.
When UK government requires it
Procurement Policy Note 014, published in February 2025 under the Procurement Act 2023, replaces PPN 09/14 and 09/23. It applies to central government departments, their executive agencies and non-departmental public bodies, and NHS bodies. For contracts that handle citizens' personal data, personal data of government staff, or ICT systems that store or process OFFICIAL information, suppliers must meet the Cyber Essentials technical requirements: holding Cyber Essentials or Plus is the quickest way, otherwise equivalent controls must be demonstrated. Buyers are told not to apply it to every contract by default.
What changed in v3.3 (April 2026)
The requirements are reviewed every year. Version 3.3, used for assessments bought from 27 April 2026 (IASME's "Danzell" question set), defines cloud services and states that they cannot be excluded from scope, adds FIDO2 to the passwordless authentication definition, introduces the Software Security Code of Practice, drops the reference to untrusted connections in the scope criteria, and stresses backups, though backups are still not a technical requirement. MFA remains mandatory for cloud services, and personal devices that reach organisational data remain in scope.
Sources
- Cabinet Office: PPN 014, Cyber Essentials scheme (February 2025)
- NCSC: Cyber Essentials Requirements for IT Infrastructure v3.3 (April 2026)
- NCSC: Cyber Essentials overview
- IASME: Cyber Essentials question sets and versions
Facts checked against these sources in October 2026. Laws, thresholds and guidance change: check the source before you rely on a figure.
The things people ask us
Is Cyber Essentials mandatory?
Not by law. UK central government departments, their agencies and NHS bodies require it, or equivalent controls, for contracts that handle personal data or OFFICIAL information, under PPN 014. Other buyers may require it by contract.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Both cover the same five controls. Cyber Essentials is a self-assessment verified by a certification body; Plus adds remote and on-site vulnerability testing of your systems, so it gives the buyer more assurance.
How long does Cyber Essentials last?
Twelve months. Government contracts that require it expect you to renew it every year for the life of the contract.
Do I need Cyber Essentials if I have ISO 27001?
If a UK government contract calls for it, usually yes. PPN 014 accepts equivalent controls, but the buyer decides whether an ISO 27001 certificate shows them. The two schemes check different things, so holding both is common.
Are personal devices in scope for Cyber Essentials?
Yes. Personal devices that access organisational data or services are in scope. Devices used only for native voice calls, texts or MFA apps are out of scope.
Does Cyber Essentials require MFA?
Yes, for cloud services: authentication to cloud services must always use MFA. Elsewhere, MFA must be used where it is available.
What is the current Cyber Essentials version?
Requirements for IT Infrastructure v3.3, published by the NCSC in April 2026, used with IASME's Danzell question set for assessments bought from 27 April 2026.
See what applies to you, and track it.
TryTrustable maps your controls to every framework you need and keeps the evidence current.