Do I need Cyber Essentials to win contracts?
Short answer: increasingly, yes — especially for public-sector and larger private contracts. Here’s exactly when it’s required, what it costs, and how to get certified without the pain.
If you’ve been asked whether you hold Cyber Essentials — or spotted it buried in a tender document — you’re not alone. It’s fast becoming a baseline expectation for doing business in the UK, and for some contracts it’s simply non-negotiable.
What is Cyber Essentials?
Cyber Essentials is a UK government-backed certification scheme. It shows that your business has five fundamental security controls in place: firewalls, secure configuration, user access control, malware protection and security update management. It’s designed to protect against the most common internet-based attacks — which account for the vast majority of breaches.
Cyber Essentials is a recognised badge that proves you’ve got the security basics right. It reassures clients, insurers and partners that their data is safe with you.
When is Cyber Essentials actually required?
You’ll typically need it in these situations:
- Government contracts. Central government contracts that involve handling certain sensitive or personal information require suppliers to hold Cyber Essentials. Many public-sector bodies extend this to all suppliers.
- Larger private clients. Enterprises increasingly require their suppliers to be certified as part of vendor due diligence — no certificate, no contract.
- Cyber insurance. Some insurers now expect it, and holding it can reduce your premiums.
- Regulated sectors. Finance, legal and healthcare-adjacent firms often need it to demonstrate due diligence.
Even where it isn’t strictly mandatory, it’s a competitive advantage — it tells prospective clients you take security seriously.
Cyber Essentials vs Cyber Essentials Plus
There are two tiers. Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds a hands-on technical audit by an assessor, who checks the controls really are in place. Some contracts specify Plus, so it’s worth checking the requirement before you start.
What does it cost?
The certification fee for basic Cyber Essentials starts from a few hundred pounds, depending on the size of your organisation. Cyber Essentials Plus costs more because of the audit involved. The bigger variable is usually the work needed to bring your setup up to standard first — which is where many businesses come unstuck on the self-assessment.
How to get certified without the headache
The self-assessment questionnaire is long and technical, and it’s easy to fail if your Microsoft 365 and devices aren’t configured correctly. The smart approach is:
- Have someone assess your setup against the five controls first.
- Fix any gaps — commonly MFA, device configuration and access control.
- Complete the assessment accurately, with evidence.
- Certify with confidence, and plan the annual renewal.
We guide Surrey and London businesses through the whole Cyber Essentials process — from readiness check to certificate. Want a hand?
Book a free auditThe bottom line
If you’re bidding for public-sector or larger private contracts, Cyber Essentials is increasingly the price of entry — and a genuine trust signal for everyone else. It’s achievable, affordable and, with the right preparation, painless.
Related services