Cyber Essentials for Government Contracts: The Complete Guide
PPN 014 applies Cyber Essentials controls proportionately to certain government and NHS contracts. This guide explains when certification or equivalent controls apply and how the tender determines the level.
Section 01
Cyber Essentials for Government Contracts: The Complete Guide
Cyber Essentials or Cyber Essentials Plus is relevant to certain central-government and NHS contracts with specified cyber-risk characteristics, but it is not a blanket requirement for every public contract. The tender must state the applicable requirement, and equivalent controls must be accepted where procurement law requires them.
That is the position in PPN 014: Cyber essentials scheme, which applies to procurements commenced from 24 February 2025. If you supply goods or services to the public sector, this guide explains what to check. It reflects the position as of July 2026.
Section 02
The Requirement
PPN 014 directs in-scope contracting organisations to apply effective and proportionate controls where contracts have characteristics such as:
- Citizen or government-personnel information - such as home addresses, bank details, payroll, or expenses data
- ICT systems and services - designed to store or process information at OFFICIAL
- Government business information - relating to service delivery, public finances, enforcement, defence, resilience, or commercial interests
The policy explicitly says not to apply the scheme to every contract as a matter of course. Where the tender requires Cyber Essentials, Plus, or equivalent controls, the supplier must meet that stated requirement. Evidence is normally required before contract award and, in all cases, before relevant data is passed to the supplier.
Section 03
Which Level Do I Need?
Cyber Essentials is a verified self-assessment that offers a basic level of assurance across the five technical controls.
Cyber Essentials Plus covers the same controls but adds vulnerability testing and is intended for contracts with higher cyber risk.
PPN 014 does not set a contract-value threshold that automatically selects Plus. The contracting organisation should make a relevant and proportionate risk decision and state the requirement in the tender notice. Read the tender rather than inferring the level from contract value.
Section 04
Tender Deadlines and Same-Day Certification
Government tender deadlines are fixed. Missing the deadline because you do not have Cyber Essentials is not an acceptable excuse in procurement.
If you are facing an imminent deadline, Fig offers same-day Cyber Essentials certification:
1. Purchase before 12:00 midday
2. Complete the self-assessment questionnaire
3. Receive your certificate the same working day
This process has been specifically designed for time-sensitive procurement scenarios. Fig provides structured feedback up to three times on your submission, so minor gaps can be corrected and resubmitted without waiting.
For Plus certification, allow 1-3 working days for the third-party audit. If your tender requires Plus, start the process as early as possible.
Section 05
Framework Agreements and Dynamic Purchasing Systems
Many government contracts are procured through framework agreements. Requirements differ between the framework and the eventual call-off contract.
For example, PPN 014 says G-Cloud suppliers are encouraged to state whether they hold Cyber Essentials or Plus, but certification is not itself a requirement of the G-Cloud commercial agreement. A contracting organisation still needs to assure the relevant cyber risks when awarding a call-off. Check both sets of documents.
Section 06
Subcontractors and Supply Chain
The Cyber Essentials requirement can flow down through supply chains. If you are a subcontractor to a prime contractor on a government contract, the prime may require you to hold Cyber Essentials as a condition of your subcontract.
This is increasingly common in defence, healthcare, and critical infrastructure supply chains. If you supply services to companies that work with government, expect to be asked for Cyber Essentials certification.
Section 07
MoD and defence contracts: Cyber Essentials plus Defence Cyber Certification
Defence is the clearest example of requirements stacking on top of Cyber Essentials. For Ministry of Defence contracts, supplier cyber posture is assessed against DEFSTAN 05-138, and under DEFCON 658 a supplier can evidence compliance through Defence Cyber Certification (DCC) at the level set by the contract's Cyber Risk Profile (Industry Security Notice 2026/02).
On top of that, the MOD has asked all industry partners to achieve DCC Level 0 by 31 December 2026, which explicitly includes obtaining Cyber Essentials for all applicable business-critical systems (MOD Defence Digital blog, 8 May 2026). For defence suppliers, in other words, Cyber Essentials is the foundation and DCC is the layer built on top of it.
If you supply the MOD or sit in a defence supply chain, read our companion guides on whether you need DCC for MOD contracts and DEFSTAN 05-138 explained, or start with the Defence Cyber Certification overview.
Section 08
Beyond Compliance: Competitive Advantage
Certification can reduce procurement friction by giving buyers a recognised way to check baseline controls. Do not assume that holding Plus earns evaluation points unless the published award criteria say so.
Section 09
Getting Started
If you are bidding on government contracts and need Cyber Essentials certification:
1. Check the tender requirements - Determine whether Cyber Essentials or Plus is required
2. Run the readiness checker - Use Fig's free readiness tool to assess your current position
3. Fix any gaps - Address issues before purchasing your assessment
4. Purchase and certify - Visit Fig's pricing page and certify same-day for Cyber Essentials
For ongoing government suppliers, maintain your certification year-round. Do not let it lapse between contracts - renew before expiry to maintain continuous coverage.
Section 10
Frequently asked questions
Do you need Cyber Essentials for government contracts?
For contracts with the risk characteristics described in PPN 014, the tender may require Cyber Essentials, Plus, or equivalent controls. The policy is not a blanket certification rule for every government contract.
Is Cyber Essentials mandatory for public sector tenders?
It is mandatory wherever the tender or framework specifies it, which is the case for most central government and many wider public-sector procurements that involve data. Always check the specific tender and framework requirements.
Which Cyber Essentials level do I need for a government contract?
The tender documentation tells you which. PPN 014 describes Cyber Essentials as basic assurance and Plus as more rigorous assurance for higher cyber risk; it does not define a simple contract-value threshold.
Do MoD contracts need Cyber Essentials or DCC?
Both, in effect. Cyber Essentials is the foundation, and MoD contracts are assessed against DEFSTAN 05-138 through Defence Cyber Certification (DCC) under DEFCON 658. DCC Level 0 - which the MOD has asked all suppliers to achieve by 31 December 2026 - includes obtaining Cyber Essentials for business-critical systems.
How quickly can I get certified for a tender deadline?
Fig issues Cyber Essentials the same working day for compliant submissions ordered before midday. Cyber Essentials Plus takes 1-3 working days for the audit, so start Plus as early as possible.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
Explore how Fig automates compliance mapping, evidence collection, and framework alignment across 65+ standards.
Request a demo