Does Your G-Cloud Contract Require Cyber Essentials?
A G-Cloud listing does not automatically require a Cyber Essentials certificate, but many call-off contracts can require Cyber Essentials, Cyber Essentials Plus, or equivalent controls. Here is how to identify the requirement and act before contract award.
Section 01
Does Your G-Cloud Contract Require Cyber Essentials?
If you supply cloud software, hosting or support through G-Cloud, a buyer may require you to hold Cyber Essentials or Cyber Essentials Plus before awarding a call-off contract. Certification is not a blanket requirement for every supplier on the framework. It is particularly relevant when a contract involves personal information, government information or ICT systems designed to store or process data classified as OFFICIAL.
Being listed on G-Cloud can open the door to valuable public-sector opportunities. It also means buyers must consider whether suppliers are managing relevant cyber risks effectively before awarding a call-off contract.
For many suppliers, this is where Cyber Essentials enters the procurement process. You may have been shortlisted for a contract, received a security questionnaire or been told that certification is required before an award can proceed.
This guide explains when that requirement can apply, which certification level you may need and what to do next.
Section 02
What is G-Cloud?
G-Cloud is a UK government procurement framework and online catalogue for cloud-based services. Public-sector organisations and other eligible customers can use it to buy:
- Cloud hosting
- Cloud software
- Cloud support
- Associated setup and maintenance services
The current framework, G-Cloud 14, provides access to more than 46,000 services from more than 4,000 suppliers. It is administered by the Government Commercial Agency, which brought together Crown Commercial Service and several Cabinet Office central commercial teams in April 2026.
G-Cloud provides an established route to market with standard framework and call-off terms. A buyer must still assess its requirements, evaluate the available services and satisfy itself that the selected supplier is managing relevant security risks.
Section 03
Is Cyber Essentials mandatory for every G-Cloud supplier?
No. Cyber Essentials certification is not a blanket requirement for every organisation listed on G-Cloud.
The government's current Procurement Policy Note 014 on the Cyber Essentials scheme says that suppliers on G-Cloud commercial agreements must demonstrate compliance with the government's Cloud Security Principles. It also says suppliers are encouraged to state whether they have Cyber Essentials or Cyber Essentials Plus, but holding either certificate is not a requirement of the G-Cloud commercial agreement itself.
The position can change at call-off contract level.
When buying through G-Cloud, an in-scope organisation must consider the cyber risks relevant to the proposed contract. Depending on those risks, the procurement may require Cyber Essentials, Cyber Essentials Plus or evidence of independently verified equivalent controls.
The practical distinction is that being accepted onto G-Cloud does not automatically mean you must hold a Cyber Essentials certificate. The particular call-off contract you want to win may still require one.
PPN 014 applies directly to central government departments, their executive agencies and non-departmental public bodies, and NHS bodies. Other public-sector organisations may choose to apply the same approach or specify their own proportionate security requirements. The policy behind the note is not new: government has required suppliers bidding for certain types of public contracts to demonstrate these controls since 2014.
Section 04
Which G-Cloud contracts are likely to require Cyber Essentials?
Under PPN 014, Cyber Essentials requirements are particularly relevant to contracts or services with characteristics including:
- A supplier handling citizens' personal information, such as home addresses, bank details or payment information
- A supplier handling personal information about government employees, ministers or special advisers
- ICT systems or services designed to store or process data classified as OFFICIAL under the Government Security Classifications Policy
- Contracts dealing with information related to the day-to-day business of government, service delivery, public finances, criminal justice, enforcement, defence, security, resilience or commercial interests
These characteristics can occur in cloud hosting, software-as-a-service, contact centre, payroll, HR, finance and managed IT services. This is why a significant range of G-Cloud call-off contracts can legitimately include a Cyber Essentials requirement even though the framework does not impose one universally.
The requirement is contractual or procurement-related. Cyber Essentials is not a general legal requirement for every UK business.
Government guidance also prohibits a blanket approach. A buyer should only require Cyber Essentials or equivalent controls where they are relevant, proportionate and necessary to manage the risks of the goods or services being procured.
Section 05
When must you provide evidence?
Where Cyber Essentials applies, evidence of a current Cyber Essentials certificate, Cyber Essentials Plus certificate or acceptable equivalent controls is required before contract award.
In exceptional circumstances, an in-scope buyer may make a risk-based decision to let a contract commence while an expired certificate is being renewed. The supplier must still demonstrate the appropriate current certification or equivalent controls before data is passed to it.
This means certification should not be left until onboarding. If a tender, call-off document or buyer questionnaire mentions Cyber Essentials, start preparing as early as possible. A delayed or unsuccessful assessment could delay the award or place the opportunity at risk.
Section 06
Do you need Cyber Essentials or Cyber Essentials Plus?
The procurement or contract documents should specify the required level.
Cyber Essentials
Cyber Essentials is an independently verified self-assessment covering five technical controls:
- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
Your organisation completes an assessment questionnaire and a licensed certification body reviews the answers. This is normally the correct starting point when a requirement says "Cyber Essentials" without specifying the Plus level.
Cyber Essentials Plus
Cyber Essentials Plus assesses the same five technical controls but adds independent technical testing. A qualified assessor tests a representative sample of the devices, servers, cloud services and user accounts within the agreed scope.
PPN 014 says the more rigorous Plus assessment should be used where there is a higher risk of cyber security threats. Do not assume Plus is required solely because you sell through G-Cloud. Check the procurement documents and ask the buyer to clarify if the required level is not stated.
Section 07
Does ISO 27001 replace Cyber Essentials?
Not automatically.
ISO 27001 is an important information security management standard, but PPN 014 explains that an organisation certified to ISO 27001 will not automatically conform to Cyber Essentials. Its ISO 27001 implementation may not include all five Cyber Essentials controls in scope, and those controls may not have been tested in the way the Cyber Essentials scheme requires.
A supplier with ISO 27001 may therefore still need Cyber Essentials or may need to provide independently verified evidence that equivalent controls are in place. If a buyer explicitly asks for a Cyber Essentials certificate, do not assume that an ISO 27001 certificate will satisfy the requirement without confirmation from the buyer.
Section 08
How long does Cyber Essentials remain valid?
Cyber Essentials and Cyber Essentials Plus certificates are valid for 12 months.
Where certification is required under a government contract, the supplier must renew it annually for the duration of that contract. Certification should therefore be treated as an ongoing supplier obligation rather than a one-off tender exercise.
Before presenting a certificate, check its scope. Cyber Essentials applies to the legal entity providing the goods or services by default, although certification can be restricted to part of that entity. Buyers are advised to examine the certificate's scope and consider risks created by subcontractors or third-party service providers that are not covered.
Section 09
What should you do if a G-Cloud buyer requests Cyber Essentials?
Start by reviewing the exact wording in the tender, call-off documentation or security schedule. Confirm:
1. Whether the requirement is Cyber Essentials or Cyber Essentials Plus
2. Whether the buyer will accept independently verified equivalent controls
3. When the evidence must be supplied
4. Which legal entity will enter the contract
5. Which systems, users and cloud services need to be included in the assessment scope
6. Whether subcontractors or other service providers need separate assurance
7. Whether annual renewal is written into the contract
You can then assess your organisation against the five controls and resolve any gaps before submitting your application.
Common issues include unsupported software, missing security updates, excessive administrator access, incomplete multi-factor authentication and uncertainty about which cloud services belong inside the assessment scope.
Section 10
Get Cyber Essentials for your G-Cloud opportunity
If a G-Cloud buyer has asked for Cyber Essentials, Fig Group can help you understand the certification requirement, prepare your scope and complete the assessment.
Fig Compliance Ltd is an IASME-licensed Cyber Essentials certification body. Fig's published Cyber Essentials pricing starts from £299.99 plus VAT and includes three free resubmissions. Complete and compliant Cyber Essentials submissions received before midday on a UK business day are covered by Fig's six-working-hour certification guarantee, subject to the published service terms.
Start your Cyber Essentials certification or use the free Cyber Essentials readiness checker to identify potential gaps before applying.
---
This article provides general information about Cyber Essentials and G-Cloud procurement. Always check the requirements in your particular procurement documents and call-off contract. Government sources and scheme requirements were reviewed on 12 August 2026.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig handles this?
See how Fig simplifies certification and framework alignment for your organisation.
Request a demoRelated solutions
Continue exploring Fig
More from Frameworks