PPN 09/23: Updates to the Cyber Essentials Scheme · first published 18 September 2023
PPN 09/23 updates the rules under which central government departments, their agencies, Non-Departmental Public Bodies (NDPBs), and NHS bodies must require suppliers to hold Cyber Essentials (CE) or Cyber Essentials Plus (CE+) certification. The requirement applies to specific contract types — mainly those involving personal data of citizens or government staff, ICT systems storing OFFICIAL-level data, or day-to-day government business information. Crucially, buyers are explicitly told NOT to apply the requirement to all contracts as a blanket rule, because over-burdening small businesses would deter them from bidding. If you don't yet hold CE certification, you can still bid by demonstrating equivalent controls, but you must have the certificate (or equivalent evidence) in place before data is passed to you. Certification must be renewed annually for the duration of the contract. Basic CE certification currently costs between £300 and £500 plus VAT for smaller companies.
WHO THIS APPLIES TO
THE ENKII VIEW
The explicit instruction to buyers not to take a "blanket approach" and not to "over-burden suppliers or deter SMEs" is a direct protection for small firms — it means you can challenge a buyer who demands CE where it isn't relevant to the contract. However, if your work involves any personal data or OFFICIAL-level IT systems, CE certification is effectively a gate you must pass before data flows to you, so getting certified early removes a last-minute risk. The annual renewal obligation (£300–£500+VAT) is a manageable, predictable cost that SMEs should budget for as a standard business expense if they regularly bid for government work in these areas.
1. Get Cyber Essentials certified now — don't wait until bid stage. Budget £300–£500+VAT for basic CE and set a calendar reminder to recertify every 12 months before your certificate lapses.
SMEs bidding for any central government, executive agency, NDPB, or NHS contract involving personal data or ICT systems — CE certification (or equivalent) must be in place before data is passed to you, and it must be renewed annually for the duration of the contract. A lapsed certificate makes you non-compliant mid-contract.
2. Do not assume ISO 27001 satisfies the CE requirement. Check your ISO 27001 scope against the five CE technical controls (firewalls, secure configuration, access control, malware protection, patch management) and obtain CE certification or prepare documented equivalent-controls evidence.
SMEs holding ISO 27001 who assume that covers them — The PPN states explicitly that ISO 27001 certification does not automatically conform to CE because the five technical controls are not typically in scope or tested under ISO 27001.
3. Prepare a written 'equivalent controls' pack — a third-party-verified assessment showing you meet the CE technical requirements through alternative means — and have it ready before any data transfer takes place.
SMEs who cannot obtain CE certification in time (e.g. legacy IT elements) — The PPN allows suppliers without CE/CE+ to demonstrate equivalent controls verified by a technically competent and independent third party, so a well-documented equivalence case is a valid alternative route.
4. Challenge a blanket CE requirement by writing to the buyer citing PPN 09/23 paragraphs 15–16, which state buyers 'must not take a blanket approach' and must not 'over-burden suppliers or deter SMEs.'
SMEs bidding for contracts where the buyer has required CE but the work involves no personal data or sensitive IT — The PPN explicitly prohibits buyers from applying CE to all contracts as a matter of course; SMEs have a policy-backed basis to push back where the requirement is not proportionate to the subject matter.
5. Confirm compliance with the Government's Cloud Security Principles (not CE specifically) as your baseline G-Cloud requirement, but proactively state if you also hold CE/CE+ in your service offer, as buyers may check for it before awarding a call-off.
SMEs supplying cloud or IT services via the CCS G-Cloud framework — G-Cloud suppliers are required to meet Cloud Security Principles; CE is not mandatory under the G-Cloud agreement, but the PPN says buyers should assure themselves suppliers manage cyber risks before awarding call-off contracts.
6. Check your subcontract terms for a CE/CE+ requirement — the Model Services Contract requires subcontractors on complex ICT/BPO contracts over £20m to hold CE or CE+ (or equivalent).
SMEs who are subcontractors on large ICT or BPO contracts above £20m — The PPN notes the Model Services Contract mandates CE/CE+ for relevant subcontractors on ICT and BPO contracts exceeding £20m in value.
Every rule below quotes the official document verbatim.
The PPN applies to all Central Government Departments, their Executive Agencies, NDPBs, and NHS bodies; other public sector bodies may choose to apply it. (Central government departments, executive agencies, NDPBs, NHS bodies)
“The contents of this PPN apply to all Central Government Departments, their Executive Agencies and Non-Departmental Public Bodies, and NHS bodies”
In-scope organisations must implement this PPN within three months of its publication date (published 18 September 2023, so by approximately 18 December 2023). (All in-scope organisations)
“In-scope organisations should implement this PPN within three months of its publication date.”
Suppliers must demonstrate CE or CE+ (or equivalent) for contracts where personal data of citizens or government staff is handled, where ICT systems store OFFICIAL-level data, or where contracts deal with day-to-day government business information. (Contracts meeting the specified higher-risk characteristics, all in-scope organisations)
“In-scope organisations must ensure that all suppliers demonstrate that they meet certain technical requirements for contracts or services that include the following characteristics: where personal information of citizens, such as home addresses, bank details, or payment information is handled by a supplier; where personal information of Government employees, Ministers and Special Advisors is handled by a supplier”
Cyber Essentials certification must be in place before data is passed to the supplier. (All suppliers on contracts requiring CE certification)
“evidence of holding a Cyber Essentials certificate (or equivalent) is essential at the point when data is to be passed to the supplier.”
CE certification must be renewed annually by the supplier for the full duration of the contract. (All suppliers on contracts requiring CE certification)
“Where Cyber Essentials certification is required, it must be renewed annually by the supplier for the duration of the contract.”
Suppliers without CE or CE+ certification can still qualify by demonstrating equivalent controls through other means, verified by a technically competent and independent third party. (Suppliers on contracts requiring CE certification, above-threshold procurements under PCR2015)
“Where a supplier does not hold Cyber Essentials or Cyber Essentials Plus they must be able to demonstrate equivalent controls are in place through other means.”
Buyers must NOT apply a blanket Cyber Essentials requirement to all contracts; they must only require it where relevant, proportionate, and necessary. (All in-scope organisations; protects SMEs and VCSEs from unnecessary burden)
“The Cyber Essentials Scheme should not be applied to all contracts as a matter of course. In-scope organisations must not take a blanket approach.”
Buyers are explicitly told not to over-burden suppliers or deter SMEs and VCSEs from bidding by requiring CE where it is not relevant. (All in-scope organisations procuring from SMEs and VCSEs)
“It is important not to over-burden suppliers or deter Small and Medium-Sized Enterprises (SMEs) and Voluntary, Community and Social Enterprises (VCSEs) from bidding for public contracts.”
Basic CE certification currently costs between £300 and £500 plus VAT for smaller companies; CE+ cost depends on network size and complexity. (Smaller companies seeking CE certification)
“The cost for smaller companies to be Cyber Essentials certified is currently expected to range between £300 and £500+ VAT at basic level.”
CE certification must be recertified every 12 months to remain valid; failure to do so renders the organisation uncertified. (All certified suppliers)
“Organisations must recertify every 12 months in order to maintain a valid certificate. Failure to do so renders the organisation uncertified.”
ISO 27001 certification does not automatically satisfy CE requirements; most ISO 27001-certified businesses must also obtain CE or demonstrate equivalent controls. (Suppliers holding ISO 27001)
“companies that attain this standard will not automatically conform to Cyber Essentials. This is because it is not usual for all of the five technical controls in Cyber Essentials to be included in the scope for ISO27001 implementation.”
For G-Cloud call-off contracts, suppliers on G-Cloud are not required to hold CE certification but must demonstrate they comply with the Government's Cloud Security Principles. (Suppliers on CCS G-Cloud Commercial Agreements)
“suppliers on these Agreements are required to demonstrate they comply with the Government's Cloud Security Principles… it is not a requirement of the Commercial Agreement for suppliers to hold this certification.”
CE certification scope defaults to the legal entity supplying the goods/services, not a wider corporate group; organisations can restrict scope to part of the legal entity. (All suppliers seeking CE certification)
“By default, Cyber Essentials applies to the legal entity providing the goods/services rather than any wider corporate entity of which the supplier may be a part.”
The Model Services Contract for complex services contracts exceeding £20 million in value requires suppliers and relevant subcontractors to hold CE or CE+ (or equivalent). (Suppliers and subcontractors on ICT/BPO contracts exceeding £20m in value)
“The Model Services Contract (MSC) is a standard contract used across Government… for complex services contracts, particularly those with ICT and Business Process Outsourcing providers exceeding £20 million in value… This schedule requires that the supplier and relevant subcontractors have Cyber Essentials or Cyber Essentials Plus certifications (or equivalent)”
This PPN replaces the previous PPN 09/14. (All in-scope organisations)
“This PPN replaces PPN 09/14.”
This briefing is enkii's interpretation of the official document — the official text always governs.
Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.