Certification · Last verified
Cyber Essentials
Cyber Essentials is the UK's NCSC-developed certification scheme, delivered through IASME, named as a supplier condition in Procurement Policy Note 09/14. It runs at two levels — the base certification combining self-assessment and independent audit, and Cyber Essentials Plus, which adds more rigorous independent technical testing.
- Class
- Certification
- Owner
- National Cyber Security Centre (NCSC), delivered through IASME as Cyber Essentials Delivery Partner
- Public register
- Not confirmed at our last check
- Last verified
What it is
Cyber Essentials is a UK certification scheme developed by the NCSC and delivered through IASME. It runs at two levels: the base certification, which the NCSC describes as "A combination of self-assessment and independent audit", and Cyber Essentials Plus — "The same protections, but with more rigorous, independent technical testing". The NCSC's own comparison places technical audit and testing only at the Plus level.
Who owns it
The scheme was developed by the National Cyber Security Centre (NCSC). In the NCSC's words: "As the NCSC's official Cyber Essentials Delivery Partner, IASME manages our network of 400+ cyber security organisations across the UK that are available to advise you and help you get certified."
Levels
- Cyber Essentials —
A combination of self-assessment and independent audit
- Cyber Essentials Plus —
The same protections, but with more rigorous, independent technical testing
Who asks for it
Public procurement. Central government contracts within Procurement Policy Note 09/14's scope. Beyond government contracts, demand comes from buyers — in the NCSC's words, "A growing number of organisations require suppliers to be certified to bid for work."
Certification is a supplier condition in part of UK central government procurement: Procurement Policy Note 09/14 states, "We are making the scheme mandatory for central government contracts advertised after 1 October 2014 which involve handling personal information and providing certain ICT products and services." (Published 26 September 2014, last updated 26 May 2016; the page carried no withdrawal notice when re-opened on 29 August 2026 — whether a successor policy note applies was not verified.) Beyond government contracts, demand comes from buyers: "A growing number of organisations require suppliers to be certified to bid for work."
Sources
- NCSC — Cyber Essentials overview (scheme owner) ↗ — accessed
- PPN 09/14 — Cyber Essentials scheme certification (published 26 September 2014, last updated 26 May 2016; no withdrawal notice as of 29 August 2026) ↗ — accessed
- NCSC — Cyber Essentials FAQs (price structure) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.