Why Does My Client Require Cyber Essentials?

A customer has asked you to hold Cyber Essentials, and you're wondering why. Short answer: the UK is pushing the certification down supply chains, and your client is passing that requirement on to you. Here's what's driving it — and how quickly you can satisfy it.

Trigger
Client / supplier questionnaire
Driver
Cyber Resilience Pledge + procurement
What you need
Cyber Essentials
How fast
Often within days

It's a supply-chain policy, not personal

You've almost certainly been asked because your client has adopted a supply-chain security policy. Three forces are behind it:

  • The Cyber Resilience Pledge. Launched by the government at CYBERUK in April 2026, it asks major organisations to audit Cyber Essentials coverage across their supply chains and take a risk-based approach to requiring it from suppliers — using a Cyber Essentials Supplier Check Tool. Signatories are now working through their supplier lists, which is why the requests are landing.
  • The NCSC Supply Chain Playbook. The NCSC is openly calling on large organisations to make Cyber Essentials a standard requirement for suppliers, because a weakness in one supplier can cascade through everyone they serve.
  • Procurement rules (PPN 014). Public-sector buyers must require Cyber Essentials or CE Plus for higher-risk contracts, and that requirement flows down to subcontractors who handle personal or OFFICIAL data.

In other words: for a growing number of buyers, Cyber Essentials has moved from ‘nice to have’ to the minimum entry requirement for doing business.

What Cyber Essentials actually is

It's a Government-backed certification, run by the NCSC's partner IASME, covering five technical controls that block the majority of common attacks: firewalls, secure configuration, security update management, user access control and malware protection. Most organisations can achieve it quickly — provided someone tells you honestly what to change first.

What to do now

Send us the requirement (the questionnaire line or contract clause) and your deadline. We'll tell you which level you actually need, get your controls in order, and support you through the assessment — often within days when things are already in reasonable shape.

Common questions

Do I have to get Cyber Essentials just because a client asked?

You're not legally obliged, but if a client has made it a condition of working with you, not holding it usually means losing the work. It's increasingly the cost of staying in the supply chain.

Is my client allowed to require this?

Yes — buyers are entitled to set security requirements for their suppliers, and government policy actively encourages it. Many large organisations have signed the Cyber Resilience Pledge, which commits them to requiring it across their supply chains.

How quickly can I get certified?

Often within days if your controls are already in order. If not, we tell you exactly what to fix first. See our urgent certification page if you're against a client deadline.

Do they want Cyber Essentials or Cyber Essentials Plus?

Check the wording — many suppliers only need the self-assessed Cyber Essentials, but larger clients, public-sector and defence chains often specify the audited Plus. We read the requirement with you before you commit.

Related

Turn the requirement into a certificate

Send us the questionnaire or clause and your deadline. We'll tell you what you need and how fast it's achievable.