Fast Cyber Essentials for a tender
What bid documents actually require, the difference between needing it at submission and at award, and how to get certified inside a closing date.
Ready to buy?
Transparent, fixed pricing based on your organisation size. By default we give you access to the IASME portal to complete your Cyber Essentials assessment yourself, and once you submit it we aim to assess within one business day. You can preview the Cyber Essentials self-assessment questions to see where you stand first. Unless you add a gap analysis, there is no call or consultation; we simply send you the questionnaire to complete. Your submission is reviewed by a qualified, certified assessor, never fed into AI. Want us to check your setup first, or need it faster? Add a gap analysis or urgent turnaround below. Buy now to get started, or contact us if you have any questions first.
An appointed IASME Certification Body: your certificate comes directly from us. Verify our credentials on the BlockMark registry, and find us listed on the IASME website.
Most public sector tenders and many private ones require Cyber Essentials, and most bid teams discover this late. Before you panic about the date, read the requirement precisely: a large proportion of tenders ask you to commit to holding Cyber Essentials by contract award, not to attach a certificate at submission. Those are very different deadlines, often weeks apart.
Read the requirement before you buy anything
Procurement documents use four distinct formulations, and they carry four different deadlines. Find yours in the Selection Questionnaire, the ITT, or the contract schedule.
| Typical wording | What it means | Your real deadline |
|---|---|---|
| "Bidders must hold Cyber Essentials" | Certificate attached at submission | The closing date |
| "Bidders must be certified prior to contract commencement" | Commit now, certify later | Contract start, often 6 to 12 weeks out |
| "Bidders must hold Cyber Essentials Plus" | Hands-on audit as well | Add 2 to 3 weeks for scheduling |
| "Evidence of an equivalent standard" | ISO 27001 or IASME Cyber Assurance may be accepted | Ask the buyer in clarifications |
If the wording is ambiguous, submit a clarification question. Buyers answer them, the answer is published to all bidders, and it costs you nothing. It is a far better use of a day than assuming the tightest reading.
Cyber Essentials in government procurement
Cyber Essentials has been mandatory for central government contracts involving the handling of personal information or the provision of certain ICT services since 2014, and the requirement has spread steadily through local government, the NHS, education and the defence supply chain. The Procurement Act has made security requirements more visible in the assessment stage rather than buried in contract schedules.
If you bid into defence, note that Defence Cyber Certification Level 0 requires Cyber Essentials underneath it, and the MoD has asked industry partners to hold Level 0 by 31 December 2026. Certifying once, properly, covers both.
Getting certified inside a closing date
- Confirm the real deadline from the wording above. This alone resolves a large share of "urgent" tender cases.
- Buy with a gap analysis if there is any doubt about your controls. £300, and it produces a remediation list within a day or two instead of a failed submission in week two.
- Fix, submit, and add urgent turnaround. £100 prioritises assessment to within one business day of you submitting.
- Attach the certificate and the registry link. Buyers increasingly verify certificates independently, so give them the registry entry as well as the PDF.
What to do if the certificate will not arrive in time
Say so in the bid, precisely and without spin: name your certification body, state the date you entered assessment, and commit to a date. Buyers see a lot of bids and they can tell the difference between an organisation that is mid-process with an appointed certification body and one that is hoping. What loses marks is silence or a vague assertion.
Price
| Organisation size | Certification | + urgent | + gap analysis |
|---|---|---|---|
| Micro, 1 to 9 staff | £320 | £420 | £720 |
| Small, 10 to 49 staff | £440 | £540 | £840 |
| Medium, 50 to 249 staff | £500 | £600 | £900 |
| Large, 250+ staff | £600 | £700 | £1,000 |
Common questions
Do I need the certificate at submission or at award?
Read the exact wording. "Bidders must hold" usually means at submission. "Must be certified prior to contract commencement" means you can commit in the bid and certify afterwards, which is often six to twelve weeks of extra time. If it is ambiguous, ask a clarification question: the answer is published to all bidders and costs you nothing.
The tender asks for Cyber Essentials Plus. Is that different?
Yes, and it takes longer. Cyber Essentials Plus adds a hands-on technical audit by an assessor, which has to be scheduled, so allow an extra two to three weeks. You need the base Cyber Essentials certification first. Do not assume Plus if the document only says Cyber Essentials.
Will ISO 27001 be accepted instead?
Sometimes, where the wording says "or equivalent". Many buyers accept ISO 27001 or IASME Cyber Assurance as equivalent or better. Others specifically require Cyber Essentials because it is a defined technical baseline rather than a management system. Ask rather than assume.
Can I bid while certification is in progress?
Usually yes, if you state it clearly: name your certification body, give the date you entered assessment, and commit to a completion date. Give the buyer enough to verify your certification body independently. That reads as competent. A vague promise does not.
How fast can you certify us for a closing date?
Assessment within one business day of you submitting, with the urgent option. The variable is how long it takes to get your five controls to the standard beforehand: an afternoon for a managed estate, weeks for an unmanaged one. Start with the gap analysis so you know which you are dealing with.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day
Deadline looming? Let's get you certified.
A quick call, an honest answer on what is achievable, a fixed price, and an assessor who moves fast.