- Trigger
- Client / supplier questionnaire
- Driver
- Cyber Resilience Pledge + procurement
- What you need
- Cyber Essentials
- How fast
- Often within days
It's a supply-chain policy, not personal
You've almost certainly been asked because your client has adopted a supply-chain security policy. Three forces are behind it:
- The Cyber Resilience Pledge. Launched by the government at CYBERUK in April 2026, it asks major organisations to audit Cyber Essentials coverage across their supply chains and take a risk-based approach to requiring it from suppliers — using a Cyber Essentials Supplier Check Tool. Signatories are now working through their supplier lists, which is why the requests are landing.
- The NCSC Supply Chain Playbook. The NCSC is openly calling on large organisations to make Cyber Essentials a standard requirement for suppliers, because a weakness in one supplier can cascade through everyone they serve.
- Procurement rules (PPN 014). Public-sector buyers must require Cyber Essentials or CE Plus for higher-risk contracts, and that requirement flows down to subcontractors who handle personal or OFFICIAL data.
In other words: for a growing number of buyers, Cyber Essentials has moved from ‘nice to have’ to the minimum entry requirement for doing business.
What Cyber Essentials actually is
It's a Government-backed certification, run by the NCSC's partner IASME, covering five technical controls that block the majority of common attacks: firewalls, secure configuration, security update management, user access control and malware protection. Most organisations can achieve it quickly — provided someone tells you honestly what to change first.
What to do now
Send us the requirement (the questionnaire line or contract clause) and your deadline. We'll tell you which level you actually need, get your controls in order, and support you through the assessment — often within days when things are already in reasonable shape.
Common questions
Do I have to get Cyber Essentials just because a client asked?
You're not legally obliged, but if a client has made it a condition of working with you, not holding it usually means losing the work. It's increasingly the cost of staying in the supply chain.
Is my client allowed to require this?
Yes — buyers are entitled to set security requirements for their suppliers, and government policy actively encourages it. Many large organisations have signed the Cyber Resilience Pledge, which commits them to requiring it across their supply chains.
How quickly can I get certified?
Often within days if your controls are already in order. If not, we tell you exactly what to fix first. See our urgent certification page if you're against a client deadline.
Do they want Cyber Essentials or Cyber Essentials Plus?
Check the wording — many suppliers only need the self-assessed Cyber Essentials, but larger clients, public-sector and defence chains often specify the audited Plus. We read the requirement with you before you commit.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day