Is Cyber Essentials mandatory?

Cyber Essentials is not a blanket legal requirement, but it is mandatory in specific situations. Here is when you actually have to have it.

Cyber Essentials is not a blanket legal requirement, but it is mandatory in specific situations. Here is when you actually have to have it.

The general position

For most UK businesses, Cyber Essentials is not required by law. There is no general statute that says every organisation must hold it.

When it is mandatory

Since 2014, central government has required suppliers handling certain personal and sensitive information to hold Cyber Essentials, and this is written into many contracts and tenders. It is also common across the wider public sector, the NHS, and the MoD supply chain, where defence work brings additional requirements such as DCC Level 0.

When it is effectively required

Even where it is not legally mandatory, it is often unavoidable in practice: private clients make it a condition of working with you, and cyber insurers require it for cover. In those cases, no certificate means no contract or no cover.

Why treat it as a baseline anyway

Mandatory or not, Cyber Essentials covers the five controls that stop the majority of common attacks. Most businesses are better off holding it than not, regardless of who is asking.

Common questions

Is Cyber Essentials required by law?

Not generally. It is mandatory for certain government and public sector contracts, and frequently required contractually elsewhere.

Is Cyber Essentials Plus mandatory?

For some government contracts, yes. The tender or contract will specify whether the hands-on Cyber Essentials Plus is needed.

Does GDPR require Cyber Essentials?

GDPR does not name it, but Cyber Essentials is a recognised way to demonstrate appropriate technical measures, which supports your data protection obligations.

Related

Need Cyber Essentials? Let’s get you certified.

Fixed price, direct from the Certification Body, often done in days.