Skip to main content
ExplainerCyber Essentials6 min read

Cyber Essentials Tender Requirements: What PPN 014 Means for Your Bid

What PPN 014 asks named central-government and NHS bodies to do, when Cyber Essentials, Plus, or equivalent controls apply, how buyers verify certificates, and how to answer the security section from your own records.

BylineWritten by Alec Pedersen · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 22 August 2026 · Review due 7 November 2026

At a glance

Read the tender wording carefully and prepare evidence for the exact Cyber Essentials requirement before award.

On this pageArticle contents

Share this article

LinkedInEmail

If a tender or supplier questionnaire has just asked you for Cyber Essentials, you are in a common route into the scheme. PPN 014 requires named central-government and NHS bodies to apply proportionate cyber controls to relevant contracts; other public bodies and private customers may use similar wording. This article explains what the rule actually says, how buyers verify a certificate, and how to stop the security section of every future bid starting from a blank page.

The rule buyers are following: PPN 014

Procurement Policy Note 014 is the UK government's current Cyber Essentials instruction for central government departments, their executive agencies and non-departmental public bodies, and NHS bodies. Other public-sector bodies may choose to apply the same approach. It applies to procurements commenced on or after 24 February 2025 and uses Procurement Act 2023 terminology. PPN 09/23 remains relevant to procurements commenced, or contracts awarded, before that date. The full text is on GOV.UK: PPN 014: Cyber Essentials scheme.

The practical content for a supplier is short:

  • The named in-scope bodies must require suppliers to demonstrate proportionate technical controls for relevant contracts, including those involving specified citizen or government-employee personal information, ICT designed to store or process OFFICIAL information, and other listed government business information.
  • Cyber Essentials or Cyber Essentials Plus is the standard certification route described by the PPN, but in-scope bodies must accept equivalent controls. PPN 014's FAQ says evidence of the applicable certificate or equivalent is required before contract award. Check the tender notice for the procurement's exact timetable.
  • The requirement must be stated in the tender notice, so you can see exactly which level is demanded before you commit to a bid.

Private-sector buyers are not bound by PPN 014. The NCSC Cyber Essentials overview says a growing number of organisations require suppliers to be Cyber Essentials certified to bid for work, so for a non-PPN tender follow the buyer's own wording.

Basic or Plus: read the tender notice, not the folklore

The tender notice wording decides. PPN 014 describes Cyber Essentials as the basic-assurance route and Cyber Essentials Plus as the more rigorous route for higher cyber risk; it also requires in-scope bodies to accept equivalent controls. Do not buy Plus on assumption — it is quote-based and materially more expensive — and equally do not bid on a Plus requirement with only Basic in hand and hope. If the notice is ambiguous, ask the buyer through the tender's clarification route and keep the answer.

How buyers check: the certificate register

Cyber Essentials certificates are verifiable by anyone on the NCSC Certificate Search hosted by IASME. It can be searched by organisation name or certificate number and lists certificates issued in the last 12 months.

Three practical consequences:

  • The certificate identity and scope matter. The current Danzell question set records one primary legal entity and can include additional legal entities within scope. Check that the supplier identity and scope shown on the digital certificate match the bid.
  • Expiry dates matter. Certificates last 12 months. If yours lapses between bid submission and contract award, the evidence-before-award check can fail at the worst possible moment. Check the expiry against the procurement timetable before you bid.
  • You do not need to prove anything exotic. Quote your certificate number and level, and point the buyer at the register. An independently checkable claim is stronger than any PDF you could attach.

The part nobody budgets for: the security questionnaire

The certificate is usually only one line of the security section. The same tender typically asks you to describe your patch management, access control, MFA position, and malware protection in your own words. Suppliers who prepared Cyber Essentials properly already wrote all of this down once — the waste is writing it again from memory for every bid, slightly differently each time, with no dates behind any claim.

The fix is boring and effective: keep the record you built for certification as a living working record. When you know which question set answer covers "describe your patch management process", the security section becomes an exercise in copying your own evidenced answers rather than drafting under deadline.

If you are not certified yet and a tender is live

Be honest with the timeline. Certification requires preparing and submitting the self-assessment and having it assessed, and preparation is the long part for most small organisations — the self-assessment questions are previewable, and there are over a hundred of them. For an applicable PPN 014 requirement, evidence is normally required before award rather than at bid submission, so a live procurement can still be biddable if the tender permits it and the timetable is realistic. Use the tender's clarification route rather than assuming: say precisely what is done, what is open, and when you expect to certify, and never claim the certificate before it is issued.

Check the current Cyber Essentials fee and likely preparation costs before committing to the procurement timetable.

Keep the certificate worth more each year

Cyber Essentials certificates expire after 12 months, and PPN 014 says certification must be renewed annually for the duration of an applicable contract. Keep previous answers, evidence context and certificate details as a working record so you can review them rather than reconstructing them from memory.

Provenance

Sources reviewed

Reviewed 22 August 2026

Sources reviewed by RightCyber on 22 August 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is an independent cyber security organisation and is not affiliated with or endorsed by IASME or the NCSC. This article is general guidance, not legal or professional advice.

Clarifications

Frequently asked questions

Do I need Cyber Essentials to bid for government contracts?
Not for every government contract. PPN 014 applies to central government departments, executive agencies, non-departmental public bodies, and NHS bodies; other public bodies may choose to use its approach. For relevant and proportionate procurements, suppliers must demonstrate the specified controls through Cyber Essentials, Cyber Essentials Plus, or accepted equivalent controls. Check the tender notice.
Do tenders need Cyber Essentials Plus or just Cyber Essentials?
The tender notice states the applicable requirement. PPN 014 describes Plus as the more rigorous route for higher cyber risk, while also requiring in-scope bodies to accept equivalent controls. If the wording is ambiguous, use the tender's clarification route and keep the buyer's answer.
How do buyers check a Cyber Essentials certificate is real?
On the NCSC Certificate Search hosted by IASME, which anyone can search by organisation name or certificate number. It lists certificates issued in the last 12 months, so an expired certificate will not appear.
Can I bid while my certification is still in progress?
PPN 014's FAQ says evidence is required before contract award, but the tender notice controls the procurement's exact timetable. Be precise about your current status and planned certification date if asked, use the clarification route when needed, and never claim a certificate before it is issued.

Relevant RightCyber product

RightCyber Certification Workspace — In-house

In the In-house workspace, Tender Outputs drafts the security section of a bid from your own answers, the evidence and open actions recorded against each control, and the certificate dates you entered, and points the buyer at the official certificate register.

Keep exploring

Browse the RightCyber Blog