Compliance

Do you need Cyber Essentials to win council contracts?

Do you need Cyber Essentials to win council contracts?

If a tender document has just landed on your desk asking whether you hold Cyber Essentials, you probably have two questions: do we actually need it, and can we get it in time? Here are honest answers to both, including where the requirement genuinely comes from and where it is simply the buyer's own policy.

Where the requirement actually comes from

Cyber Essentials is a UK government-backed certification scheme created by the National Cyber Security Centre and delivered by IASME. Since 2014, UK central government has required suppliers to hold it for certain contracts. Specifically those involving the handling of particular kinds of personal information, and the provision of certain technical products and services.

That is the part that is a genuine rule. Beyond it, things are looser than most articles admit. Local authorities set their own procurement policies. Many now ask for Cyber Essentials, some ask for Cyber Essentials Plus on larger or more sensitive contracts, and some do not ask at all. The same is increasingly true in the private sector, where it turns up in supplier due-diligence questionnaires.

So the accurate answer to “do councils require it” is: read the tender. If it asks, it is a requirement for that contract, and no amount of general argument will get you around it.

Standard or Plus?

Most tenders that ask for certification ask for standard Cyber Essentials. That is a self-assessment questionnaire verified by a certification body, covering five technical controls.

Cyber Essentials Plus covers the identical five controls, but an assessor independently tests a sample of your devices rather than accepting your word. It appears in tenders involving more sensitive data or wider scope.

Two things matter practically. You must hold standard certification before Plus, and the Plus assessment has to happen within three months of it, so if a tender asks for Plus the clock is longer than it looks. And the two are not interchangeable on a submission: answering “we hold Cyber Essentials” to a question asking for Plus is a failed bid, not a technicality.

The five controls, and what usually fails

Certification tests firewalls, secure configuration, user access control, malware protection and security update management. The questionnaire itself is not difficult to read. What catches people out is being able to answer every question truthfully.

In practice, the gaps that hold up small businesses are consistent and mundane:

  • Unsupported software or operating systems still in use. This fails on its own and often needs replacing, which takes time and money.
  • Administrator rights handed out broadly, with no record of who has what.
  • Patching that is not actually automatic, so critical updates drift past the fourteen-day threshold.
  • Home-worker devices nobody counted as in scope. They are in scope, and this surprises people.
  • No asset register, so nobody can say with confidence what needs to comply.

How long it takes, honestly

If your systems are already in reasonable shape, standard certification is a few weeks. If the gap assessment turns up unsupported software, it is longer. You cannot answer the questionnaire honestly until it is dealt with, and replacing a line-of-business system is a project, not a task.

The paperwork is almost never the bottleneck. Remediation is. That is why we run a gap assessment before anything is submitted: it converts an unknown into a list with costs against it, which is what you actually need when a deadline is fixed.

If the deadline is tight

Be realistic with the buyer. Many procurement processes accept a credible, dated commitment to certify where a supplier is otherwise strong, particularly if you can evidence that the work is genuinely under way. That is a conversation worth having early rather than discovering at submission that you cannot tick the box.

What does not work is certifying in name only. The controls have to actually be in place, and Plus will test them directly.

Worth doing even without a tender

Set the procurement question aside for a moment. The five controls block the large majority of common, untargeted attacks. The automated, opportunistic kind that make up most of what actually hits small businesses. Certification also answers most client security questionnaires in a single line, and some insurers price it in.

It is a floor rather than a ceiling. It will not stop a determined targeted attack, and it is not a substitute for tested backups or monitoring. But per pound spent it is among the most useful things a small business can do.

We manage certification for £99 per client per month and Cyber Essentials Plus for £1,755 a year. Full detail on the Cyber Essentials page, and our plain-English guide to the scheme covers the controls in more depth.

Frequently asked questions

Do councils require Cyber Essentials?+

It varies. UK central government has required Cyber Essentials since 2014 for contracts involving the handling of certain personal information and the provision of certain technical products and services. Local authorities set their own procurement rules, and many now ask for it, but it is not a blanket national requirement, so read the specific tender.

Is Cyber Essentials or Cyber Essentials Plus needed for tenders?+

Most tenders that ask for certification ask for standard Cyber Essentials. Plus is requested where the contract involves more sensitive data or larger scope. Check the wording: the two are not interchangeable and Plus takes materially longer to achieve.

How long before a tender deadline should we start?+

Allow a few weeks at minimum for standard certification, and longer if you need Plus, since Plus requires you to hold standard certification first and be assessed within three months of it. The delay is almost never the paperwork. It is fixing whatever the gap assessment finds.

What does it cost?+

We run Cyber Essentials readiness for £99 per client per month, covering the gap assessment, the remediation work and help preparing your submission, then keeping the controls in place between renewals. Cyber Essentials Plus readiness is £1,755 a year. We are not a certification body: the certificate is issued by an assessor at a body licensed by IASME, and you submit it in your own name. Certification body fees are set by the scheme and vary with organisation size.

What if we fail?+

You receive feedback on what did not meet the standard and can remediate and resubmit. This is exactly why we run a gap assessment first. Finding the problems before submission is cheaper and far less stressful than finding them after.

Does certification actually make us more secure?+

The five controls block the large majority of common, untargeted internet attacks, so yes. Meaningfully, for the money. It will not stop a determined targeted attack, and it is not a substitute for backups or monitoring. It is a floor, not a ceiling.

Call usFree consultation