LIVE · UK MARKET INDEXED
NEWNHS Mersey · Compliance audit Q2 2026·£85k·Manchester
GRANTInnovate UK · SME R&D·£250k·UK-wide
NEWTfL · Cybersecurity SOC·£1.2M·London
INVMercia · Series A · ClimateTech·£3M·Birmingham
CORPBarclays · Diverse supplier programme·Invite·Nationwide
NEWCardiff CC · Schools refurbishment·£420k·Wales
GRANTHorizon EU · Energy transition·€800k·EU
NEWManchester CC · Social housing fire doors·£240k·Manchester
CORPKPMG · Digital procurement partner·£600k·UK
INVNorthwest Growth · Seed fund·£500k·NW England
NEWFind a Tender · Rail signalling·£3.6M·Frankfurt
NEWGovTech Singapore · Public services·SGD 1.1M·Singapore
NEWNHS Mersey · Compliance audit Q2 2026·£85k·Manchester
GRANTInnovate UK · SME R&D·£250k·UK-wide
NEWTfL · Cybersecurity SOC·£1.2M·London
INVMercia · Series A · ClimateTech·£3M·Birmingham
CORPBarclays · Diverse supplier programme·Invite·Nationwide
NEWCardiff CC · Schools refurbishment·£420k·Wales
GRANTHorizon EU · Energy transition·€800k·EU
NEWManchester CC · Social housing fire doors·£240k·Manchester
CORPKPMG · Digital procurement partner·£600k·UK
INVNorthwest Growth · Seed fund·£500k·NW England
NEWFind a Tender · Rail signalling·£3.6M·Frankfurt
NEWGovTech Singapore · Public services·SGD 1.1M·Singapore
PPN 09/14 · UPDATED 26 MAY 2016

Cyber Essentials certification became mandatory for central government contracts involving personal data or ICT products/services advertised after 1 October 2014.

Procurement Policy Note 09/14: Cyber Essentials scheme certification · first published 26 September 2014

What it says, in plain English

Procurement Policy Note (PPN) 09/14 introduces the Cyber Essentials scheme — a government-backed certification that requires organisations to implement basic cyber security controls to protect against common internet-based threats. There are two levels: Cyber Essentials (self-assessed) and Cyber Essentials Plus (independently verified). From 1 October 2014, central government made the certification mandatory for any contract advertised after that date where the work involves handling personal information or delivering certain ICT (Information and Communications Technology) products and services. The scheme is designed for organisations of all sizes and sectors, so small businesses supplying these types of contracts must hold valid certification or risk being excluded from bidding. If you supply anything else to central government, certification is not mandated by this PPN — though it is widely regarded as good practice.

WHO THIS APPLIES TO

Who it binds
Central government buyers
Contract values
any value
Applies from
1 October 2014
Sectors
ICT products and services, and any contracts involving handling of personal information — all other sectors only if personal data or ICT is involved.

THE ENKII VIEW

For small businesses, this is a hard gate: if you bid for central government work involving personal data or ICT, you must hold Cyber Essentials certification — no certification, no contract. The good news is the baseline Cyber Essentials level is designed for organisations of all sizes and is relatively low-cost to obtain, meaning smaller firms are not disadvantaged versus larger competitors. Securing certification proactively (rather than scrambling when a tender appears) is a simple, concrete way to stay bid-ready.

What a small business should do about it

1. Obtain at minimum Cyber Essentials certification before bidding — check the current official certification bodies and complete the self-assessment process so you hold valid certification ready for any tender.

SMEs bidding for central government contracts involving personal data or ICT products/servicesThe PPN makes Cyber Essentials mandatory for central government contracts advertised after 1 October 2014 that involve handling personal information or ICT products/services; without it you will be excluded.

2. Consider upgrading to Cyber Essentials Plus (the independently verified tier) if you are competing for higher-value or higher-sensitivity contracts, to differentiate your bid.

SMEs bidding for central government contracts involving personal data or ICT products/servicesThe document identifies two levels of certification — Cyber Essentials and Cyber Essentials Plus — signalling that buyers may prefer or require the higher level for more sensitive work.

3. Audit your contract scope now: if any element of your delivery involves handling personal data or supplying ICT products/services to central government, treat Cyber Essentials as a hard pre-qualification requirement and get certified before the next opportunity arises.

All SMEs supplying or planning to supply central governmentThe mandatory requirement applies from the contract advertisement date, so a tender can close before you have time to obtain certification if you leave it too late.

The rules, anchored to the text

Every rule below quotes the official document verbatim.

Cyber Essentials certification is mandatory for central government contracts advertised after 1 October 2014 that involve handling personal information or providing certain ICT products and services. (Central government contracts advertised after 1 October 2014 involving personal information or ICT products/services)

We are making the scheme mandatory for central government contracts advertised after 1 October 2014 which involve handling personal information and providing certain ICT products and services.

The Cyber Essentials scheme applies to organisations of all sizes and in all sectors. (All organisations bidding for in-scope central government contracts)

Cyber Essentials is for all organisations of all sizes, and in all sectors.

There are two levels of certification: Cyber Essentials and Cyber Essentials Plus. (All organisations seeking Cyber Essentials certification)

There are 2 levels of certification: Cyber Essentials and Cyber Essentials Plus.

The scheme defines a set of controls that, when properly implemented, provide basic protection from the most prevalent forms of internet-based threat. (All organisations implementing Cyber Essentials)

The scheme defines a set of controls which, when properly implemented, will provide organisations with basic protection from the most prevalent forms of threat coming from the internet.

The policy is directed at reducing cyber security risk in the government supply chain. (Central government supply chain)

The government is taking steps to further reduce the levels of cyber security risk in its supply chain through the Cyber Essentials scheme.

This briefing is enkii's interpretation of the official document — the official text always governs.

Official document on GOV.UK

Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.