Free tool · Cyber Essentials

Do I need Cyber Essentials?

Cyber Essentials is the UK government-backed baseline for cyber security. It is voluntary, except that UK central government and NHS buyers require it, or equivalent controls, for contracts that handle personal or OFFICIAL data. Answer four questions to see whether you need it, and whether Plus.

Short answer

You need Cyber Essentials, or proof of equivalent controls, to win UK central government or NHS contracts that handle citizens' or officials' personal data or OFFICIAL information, under Procurement Policy Note 014. Otherwise it is voluntary, though a growing number of UK buyers ask for it. It certifies five technical controls, renews every year, and Plus adds an independent technical audit.

Answer for your organisation

Citizens' personal data (addresses, bank or payment details); personal data of government staff or ministers (payroll, travel, expenses); or ICT systems that store or process OFFICIAL information.
Worked example: a UK supplier bidding for a central government contract that handles citizens' personal data

Result

An indication from your answers, not legal advice. Applicability turns on facts a form cannot see; confirm it with counsel or your auditor before you rely on it.
Required: required for this contract, or equivalent controls

PPN 014 tells central government departments, their agencies and NHS bodies to require suppliers on contracts like this to meet the Cyber Essentials technical requirements, most simply by holding Cyber Essentials or Plus. You must hold it by the time data passes to you, and renew it every year of the contract. Without it, you must show equivalent controls another way.

Firewalls: boundary or software firewall on every in-scope deviceCE v3.3 control 1
Secure configuration: no default passwords, device unlock, auto-run offCE v3.3 control 2
Security updates within 14 days for critical or high-risk fixesCE v3.3 control 3
User access control: MFA on cloud services, separate admin accountsCE v3.3 control 4
Malware protection: anti-malware or application allow-listingCE v3.3 control 5
Renew annually for the life of the contractPPN 014 para 14
  • Scope: include every device and cloud service that reaches organisational data, BYOD included. Cloud services cannot be excluded, and a scope without end-user devices is not accepted.
  • Prepare: download the current question set from IASME and close the gaps first: unsupported software, missing MFA on cloud services, and patches older than 14 days are the common failures.
  • Certify: submit the self-assessment through a certification body. For Plus, the certification body then tests your systems remotely and on site.
01

What Cyber Essentials is

Cyber Essentials is a UK government-backed certification, run by the NCSC with IASME as its delivery partner, covering five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Basic Cyber Essentials is a self-assessment questionnaire verified by a certification body. Cyber Essentials Plus checks the same controls but adds remote and on-site vulnerability testing. Both renew every year.

02

When UK government requires it

Procurement Policy Note 014, published in February 2025 under the Procurement Act 2023, replaces PPN 09/14 and 09/23. It applies to central government departments, their executive agencies and non-departmental public bodies, and NHS bodies. For contracts that handle citizens' personal data, personal data of government staff, or ICT systems that store or process OFFICIAL information, suppliers must meet the Cyber Essentials technical requirements: holding Cyber Essentials or Plus is the quickest way, otherwise equivalent controls must be demonstrated. Buyers are told not to apply it to every contract by default.

03

What changed in v3.3 (April 2026)

The requirements are reviewed every year. Version 3.3, used for assessments bought from 27 April 2026 (IASME's "Danzell" question set), defines cloud services and states that they cannot be excluded from scope, adds FIDO2 to the passwordless authentication definition, introduces the Software Security Code of Practice, drops the reference to untrusted connections in the scope criteria, and stresses backups, though backups are still not a technical requirement. MFA remains mandatory for cloud services, and personal devices that reach organisational data remain in scope.

04

Sources

Questions

The things people ask us

Is Cyber Essentials mandatory?

Not by law. UK central government departments, their agencies and NHS bodies require it, or equivalent controls, for contracts that handle personal data or OFFICIAL information, under PPN 014. Other buyers may require it by contract.

What is the difference between Cyber Essentials and Cyber Essentials Plus?

Both cover the same five controls. Cyber Essentials is a self-assessment verified by a certification body; Plus adds remote and on-site vulnerability testing of your systems, so it gives the buyer more assurance.

How long does Cyber Essentials last?

Twelve months. Government contracts that require it expect you to renew it every year for the life of the contract.

Do I need Cyber Essentials if I have ISO 27001?

If a UK government contract calls for it, usually yes. PPN 014 accepts equivalent controls, but the buyer decides whether an ISO 27001 certificate shows them. The two schemes check different things, so holding both is common.

Are personal devices in scope for Cyber Essentials?

Yes. Personal devices that access organisational data or services are in scope. Devices used only for native voice calls, texts or MFA apps are out of scope.

Does Cyber Essentials require MFA?

Yes, for cloud services: authentication to cloud services must always use MFA. Elsewhere, MFA must be used where it is available.

What is the current Cyber Essentials version?

Requirements for IT Infrastructure v3.3, published by the NCSC in April 2026, used with IASME's Danzell question set for assessments bought from 27 April 2026.

Book a walkthrough

See what applies to you, and track it.

TryTrustable maps your controls to every framework you need and keeps the evidence current.