- Regime
- Procurement Act 2023 (from Feb 2025)
- Platform
- Find a Tender / Central Digital Platform
- Cyber rule
- PPN 014: CE / CE Plus
- Flows down
- To subcontractors
The lay of the land
The Procurement Act 2023 has governed public procurement since February 2025, with opportunities advertised through Find a Tender and suppliers registering on the Central Digital Platform. The Act didn't change the cyber-security expectations so much as re-state them under new terminology — and those expectations are rising.
Cyber Essentials under PPN 014
The current Procurement Policy Note on cyber security, PPN 014 (which replaced the old PPN 09/14 and PPN 09/23), requires central government departments, their agencies, NDPBs and NHS bodies to make suppliers hold Cyber Essentials — or the audited Cyber Essentials Plus for higher-risk contracts — before a contract is awarded. Key points:
- It applies to contracts with a higher risk of cyber threats, typically where suppliers handle personal or OFFICIAL data.
- The requirement flows down: your subcontractors who process that data are expected to be certified too.
- Certification must be current — you re-certify every 12 months to keep it valid.
- Some frameworks go further: G-Cloud now makes Cyber Essentials mandatory across all lots, with CE Plus for certain lots.
Beyond Cyber Essentials
Higher-value or higher-risk competitions increasingly also ask for evidence of penetration testing, and sometimes ISO 27001 or IASME Cyber Assurance. Defence contracts run their own model on top (CE or CE Plus by risk profile). Read each tender's conditions of participation carefully — the security requirement is usually spelled out there.
Be ready before you bid
The suppliers who win are the ones already certified when the opportunity appears — scrambling for Cyber Essentials after the deadline is published rarely works. We get you certified and, where a tender needs it, tested, so your bid clears the security gate rather than stalling on it.
Common questions
Does every public contract require Cyber Essentials?
No — PPN 014 targets higher-risk contracts, typically where you handle personal or OFFICIAL data. But many frameworks (like G-Cloud) now require it across the board, so if you bid for public work regularly, certification is effectively essential.
What's the difference between PPN 014 and the old PPN 09/14?
PPN 014 replaced PPN 09/14 and PPN 09/23 to reflect the Procurement Act 2023 terminology. The policy is essentially the same: Cyber Essentials (or CE Plus) for higher-risk central government and NHS contracts.
Do my subcontractors need Cyber Essentials too?
Yes, where they handle the personal or OFFICIAL data in scope. The requirement flows down the chain, and buyers can ask you to evidence it.
Do I need Cyber Essentials or Cyber Essentials Plus for a tender?
It depends on the contract's risk level — the tender's conditions of participation will state which. Higher-risk work, and some frameworks and defence contracts, require the audited Plus. We help you read it before you invest.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day