What Cyber Essentials Plus Means for Your Tender Eligibility in 2026
Cyber Essentials Plus is no longer a nice-to-have in public sector tendering. It is a mandatory requirement on an increasing number of contracts — particularly those involving access to government networks, personal data, or sensitive operational systems. If you do not hold it, you cannot submit a compliant response. The contract goes elsewhere.
This guide covers what Cyber Essentials Plus actually requires, how it differs from the standard Cyber Essentials certification, why its prevalence in public sector procurement is accelerating, and what the certification process involves for organisations pursuing it for the first time.
Cyber Essentials vs Cyber Essentials Plus — What Is the Difference?
Both certifications are part of the UK government’s Cyber Essentials scheme, administered by the National Cyber Security Centre (NCSC). They cover the same five technical controls. The difference is in how compliance is verified.
Cyber Essentials is a self-assessment certification. Your organisation completes a questionnaire confirming that the five controls are in place. An accredited certifying body reviews the answers and issues the certificate. The assessment is based on what you declare — there is no independent technical verification of your systems.
Cyber Essentials Plus goes further. An accredited assessor conducts independent technical testing of your systems — verifying that the five controls are actually implemented and functioning as declared. This includes vulnerability scanning, configuration checking, and hands-on testing of your technical environment. The certificate reflects verified compliance, not self-declared compliance.
Buyers who specify Cyber Essentials Plus as a requirement are specifically requiring the independently verified certification — not the self-assessment version. Submitting a standard Cyber Essentials certificate in response to a Cyber Essentials Plus requirement is a compliance failure.
The Five Controls Cyber Essentials Plus Verifies
Understanding what the five controls cover helps you assess your current position before beginning the certification process.
Firewalls. All devices connected to the internet must be protected by a properly configured firewall — limiting inbound and outbound network traffic to what is necessary for the business. The assessment verifies that firewalls are active, correctly configured, and cover all internet-connected devices including remote workers’ devices.
Secure configuration. All devices and software must be configured securely — default passwords changed, unnecessary software removed, and security settings enabled. The assessment checks that devices are not running unnecessary services, that administrative accounts are appropriately restricted, and that auto-run features are disabled.
User access control. User accounts must have the minimum access necessary for their role. Administrative privileges must be restricted to named individuals with a genuine need. The assessment verifies that standard user accounts cannot install software or access areas of the system beyond their role requirements.
Malware protection. All devices must be protected against malware — through anti-malware software, application whitelisting, or sandboxing. The assessment checks that malware protection is active, current, and configured to scan automatically.
Patch management. All software must be kept up to date — operating systems, applications, and firmware patched within 14 days of a security update being released. The assessment verifies that no high-risk vulnerabilities from unpatched software are present on assessed devices.
Why Cyber Essentials Plus Is Increasingly Mandatory in Tendering
Three converging factors have accelerated the spread of Cyber Essentials Plus as a procurement requirement.
Government mandate expansion. Central government departments have required Cyber Essentials certification for all suppliers handling government data since 2014. From 2023 onwards, many contracts that previously required standard Cyber Essentials have been upgraded to require Cyber Essentials Plus — reflecting the NCSC’s guidance that independently verified certification provides significantly stronger assurance than self-assessment.
Supply chain attack awareness. High-profile supply chain cyber attacks — where attackers gained access to government or critical infrastructure systems through less-secured supplier organisations — have made buyers acutely aware that a supplier’s cyber security posture directly affects their own. Cyber Essentials Plus provides the independently verified assurance that a supplier’s systems are not a vulnerability in the buyer’s supply chain.
NHS and health sector requirements. NHS Digital’s Data Security and Protection Toolkit (DSPT) — the compliance framework for organisations handling NHS patient data — increasingly aligns its requirements with Cyber Essentials Plus. Technology, data, and professional services suppliers to the NHS are encountering Cyber Essentials Plus requirements with growing frequency.
Which Contracts Require It
Cyber Essentials Plus is most consistently required across four procurement categories.
Technology and IT services. Any contract involving software development, IT infrastructure, managed services, or system integration for public sector buyers. If your organisation handles government data or connects to government networks, Cyber Essentials Plus is effectively mandatory.
Professional services involving data access. Consultancy, research, financial services, and legal services contracts where the supplier will have access to personal data, commercially sensitive information, or government systems. The requirement is driven by data protection obligations rather than the nature of the service itself.
Health and care contracts. Any supplier processing NHS patient data or connecting to NHS systems. The combination of DSPT requirements and procurement specifications is making Cyber Essentials Plus standard rather than exceptional in health and care procurement.
Defence and security contracts. Defence Equipment and Support and the broader MOD supply chain have required Cyber Essentials Plus for years. The standard is now spreading into adjacent security and emergency services procurement.
What the Certification Process Involves
The Cyber Essentials Plus assessment process has two stages. You must hold a current standard Cyber Essentials certificate before beginning the Plus assessment — the self-assessment must be completed first.
Stage 1 — Standard Cyber Essentials. Complete the self-assessment questionnaire through an NCSC-accredited certifying body. The questionnaire covers your implementation of the five controls. Most organisations with reasonable IT hygiene complete this stage within two to four weeks. The certificate is valid for twelve months.
Stage 2 — Cyber Essentials Plus assessment. An accredited assessor conducts independent technical testing of a representative sample of your systems — typically within three months of your standard Cyber Essentials certification. The assessment covers devices, network configuration, user accounts, and patch status. The duration varies by organisation size — a small organisation with a simple IT environment may complete the assessment in a single day. A larger organisation with complex infrastructure will take longer.
If vulnerabilities are identified during the assessment, you are typically given a remediation period to address them before the assessment concludes. This is normal — it is not automatically a failure. The assessment identifies what needs fixing. You fix it. The assessor verifies the fix. The certificate is issued.
Cyber Essentials Plus certificates are valid for twelve months. Renewal requires a new assessment annually.
What Cyber Essentials Plus Costs
Costs vary by organisation size, IT complexity, and certifying body. As a general guide:
Standard Cyber Essentials self-assessment typically costs £300 to £500 for small organisations through to £1,000 to £1,500 for larger ones, depending on the certifying body.
Cyber Essentials Plus assessment costs more — reflecting the independent technical testing involved. Small organisations with simple IT environments typically pay £1,500 to £3,000. Larger organisations with more complex infrastructure pay proportionally more.
Remediation costs — if vulnerabilities are identified during assessment — vary depending on what needs fixing. Common remediation activities include updating unpatched software, reconfiguring firewall rules, and reviewing user access permissions. These are activities your IT team or IT provider may be able to complete internally.
The total investment in Cyber Essentials Plus should be assessed against the value of the contracts it unlocks. A certification that costs £3,000 and enables eligibility for a £500,000 per year technology contract is an obvious investment. Our guide to the bid no-bid decision covers how to assess this kind of eligibility investment as part of your broader tendering strategy.
What Happens If You Do Not Have It
If a tender specifies Cyber Essentials Plus as a mandatory requirement and you do not hold it, your submission is non-compliant. It will be rejected before evaluation begins — regardless of the quality of every other element of your response. There is no partial credit for holding standard Cyber Essentials. There is no discretion available to the buyer.
Discovering a mandatory Cyber Essentials Plus requirement after you have invested significant time in preparing a submission is one of the most avoidable and most frustrating compliance failures in tendering. Check the mandatory accreditation requirements in the selection questionnaire at the bid no-bid stage — before committing any writing resource. Our guide to tender compliance covers every category of mandatory requirement and how to audit your compliance position before pursuing any opportunity.
Frequently Asked Questions About Cyber Essentials Plus
Can I use standard Cyber Essentials where Plus is specified?
No. Standard Cyber Essentials and Cyber Essentials Plus are distinct certifications. A buyer who specifies Cyber Essentials Plus requires the independently verified certification. Submitting standard Cyber Essentials in its place is a compliance failure that will disqualify your submission.
How long does Cyber Essentials Plus certification take?
Allow six to ten weeks from starting the process to receiving your Cyber Essentials Plus certificate — including the standard Cyber Essentials self-assessment, any preparatory remediation, and the Plus assessment itself. If vulnerabilities are identified during the assessment, allow additional time for remediation and re-testing. Start the process well in advance of any tender deadline that requires it.
Does Cyber Essentials Plus cover cloud services?
Partially. Cyber Essentials Plus covers devices and systems within your organisational control. Cloud services and infrastructure managed by third-party providers are assessed differently — your responsibility is to ensure that your use of cloud services complies with the five controls, and that you have appropriate contractual assurances from cloud providers. The NCSC guidance on cloud services within the Cyber Essentials scope is specific and worth reading before your assessment.
Does holding Cyber Essentials Plus exempt me from other security questions in tenders?
It provides strong evidential support for your information security responses — particularly questions about your cyber security management system, your approach to vulnerability management, and your staff security awareness. It does not replace other security requirements such as ISO 27001, DSPT compliance, or specific government security classifications. Check what each tender requires specifically rather than assuming Cyber Essentials Plus covers all security criteria.
Get Cyber Ready Before Your Next Tender
Together: The Hudson Collective helps organisations understand and meet their compliance requirements before pursuing public sector opportunities — avoiding the compliance failures that disqualify strong submissions before evaluation begins. Our team holds an 87% win rate across all sectors, working with 3,500+ organisations across 52 countries.
Send us your specification and we will tell you exactly where we can give you the edge.
Tell us about your opportunity.
About the author: Written by Joshua Smith, a seasoned bid-writing expert with experience across the UK, Middle East and US, helping organisations secure the contracts they deserve through high-quality, competitive tender responses.