Is Cyber Essentials a legal requirement?
Cyber Essentials is not a general UK legal requirement. Check the actual tender, MOD contract, insurer conditions and permitted equivalent controls.

Section 01
Is Cyber Essentials a legal requirement?
No - Cyber Essentials is not a legal requirement for UK businesses in general. It is a voluntary NCSC-backed certification scheme. However, it is contractually mandatory for many UK central government contracts, for MOD sub-contracting, for St. James's Place partner practices, and for a growing number of regulated supply chains.
Section 02
Where Cyber Essentials is contractually mandatory
Central government and NHS procurement. PPN 014 applies to relevant procurements commenced from 24 February 2025 by central-government departments, their executive agencies, non-departmental public bodies and NHS bodies. Controls must be relevant and proportionate, with permitted equivalents; the policy does not require certification for every contract or select Plus automatically by value.
MOD contracts and subcontracting. Check DEFCON 658, Def Stan 05-138 issue 4, the buyer’s numeric profile/RAR and flowed-down terms. DCC can provide independent evidence, but the full SAQ remains mandatory under current MOD guidance. CE is a DCC certification prerequisite; Plus applies at Levels 2 and 3. The industry request for Level 0 by end-2026 is separate from the actual contract condition.
NHS supplier frameworks. Many NHS procurement frameworks - including those operated through NHS Shared Business Services - reference CE or Plus in supplier-onboarding requirements.
SJP partner practices. SJP's published reporting describes Cyber Essentials Plus or use of its Device as a Service solution. Confirm the applicable route with SJP; see our sourced Partner Practice guide.
Insurance. Many UK cyber-insurance and PI policies reference CE in underwriting - not legally mandatory, but commercially very close to it for firms facing PI renewal cycles.
Section 03
Where Cyber Essentials is strongly expected but not legally mandated
SRA-regulated law firms. Verify the firm’s actual regulatory and customer requirements. Cyber Essentials can support baseline assurance but is not a substitute for all professional or data-protection duties; this guide establishes no profession-wide certification mandate.
FCA-regulated firms. Apply the relevant operational resilience and security rules to the actual regulated activity. Do not infer a universal Cyber Essentials mandate or regulator endorsement from general technical-control expectations.
UK GDPR Article 32. Appropriate technical and organisational measures depend on risk. CE can provide technical evidence but does not establish full GDPR compliance or replace information-governance obligations; see the GDPR guide.
Section 04
Where Cyber Essentials is not legally required
Most UK SMEs have no general statutory duty to hold CE. A contract or insurer may still require it. Any IASME-arranged cyber liability cover depends on current eligibility, whole-organisation scope, opt-in requirements and policy terms; certification does not guarantee activation or insurance suitability.
Section 05
Will Cyber Essentials become a legal requirement?
The Cyber Security and Resilience Bill is a separate legislative proposal; do not treat a Bill as enacted duties or a general CE mandate. Check final legislation, commencement and sector guidance before applying any new obligation.
Section 06
Bottom line
Cyber Essentials is not a general UK legal requirement. It may be required by a particular tender, subcontract or insurance policy; read those terms, permitted equivalents and scope before purchasing.
Start Cyber Essentials from £299.99 + VAT | Free readiness check | Cyber Essentials for government contracts
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Want to see how Fig Group handles this?
Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.
Request a demoRelated guides
Continue reading
Frameworks
Does Your G-Cloud Contract Require Cyber Essentials?
A G-Cloud listing does not automatically require a Cyber Essentials certificate, but many call-off contracts can require Cyber Essentials, Cyber Essentials Plus, or equivalent controls. Here is how to identify the requirement and act before contract award.
Read articleFrameworks
Cyber Essentials vs ISO 27001: which does your customer actually want?
Check the exact customer or tender requirement before choosing Cyber Essentials, Plus or ISO 27001. Compare their different assurance purposes and permitted evidence.
Read articleCompliance
Last-Minute Cyber Essentials: Getting Certified Before Your Deadline
Facing a tender deadline or contract requirement that demands Cyber Essentials certification? Here is how to get certified fast without cutting corners.
Read article

