eSourcingData - Source-to-Contract Procurement Software
PA2311 August 2026 · 8 min read · The eSourcing Data team

Cyber Essentials is the floor, not the ceiling: what buyers keep getting wrong about supply chain cyber risk

Most public sector data breaches will not start inside the organisation. They will start with a supplier: the payroll processor, the contact centre, the CV writing service holding thousands of National Insurance numbers. That is why, since 2014, government buyers have required Cyber Essentials certification on certain contracts, and why PPN 014 restates the requirement for the Procurement Act 2023 era. But the PPN is more subtle than the way many organisations apply it. It bans the blanket approach as firmly as it mandates protection for risky contracts, and the interesting failures happen at both ends.

A scheme built for common attacks, not clever ones

Cyber Essentials tests five things: boundary firewalls and internet gateways, secure configuration, access control, malware protection and security update management. At the basic level it is a self assessment questionnaire, verified by an independent certification body, and it currently costs a smaller company somewhere between £300 and £500 plus VAT. Cyber Essentials Plus adds real vulnerability testing, remote and on site, using the same commodity tools an opportunist attacker would use.

That design tells you what the scheme is for. It stops the common, automated, internet borne attacks that look for soft targets. The PPN itself is candid about the limits: certification does not assure the specific product or service being bought, and it is not designed to counter advanced, targeted attacks. If your contract carries those risks, the answer is not a certificate. It is a conversation with your security specialists and a set of additional controls sized to the threat.

The blanket requirement trap

The most common misapplication is not under-use. It is the procurement team that pastes a Cyber Essentials Plus requirement into every tender because it feels safe. PPN 014 prohibits exactly this: controls must be relevant to the subject matter, proportionate and necessary, and buyers are warned not to over-burden suppliers or deter SMEs and VCSEs from bidding.

The PPN's own examples make the point well. A contact centre handling citizens' names, dates of birth and National Insurance numbers clearly needs certification. A sole trader delivering driving lessons to ten people, with incidental IT use, clearly does not. In between sits real judgement: a marketing agency with civil servants' contact details may fall below the threshold where the scheme adds value. The test is the data and the systems, not the contract label.

There is a matching trap on the supplier side. Buyers must accept equivalent controls, verified by a competent independent third party, because section 56 of the Procurement Act 2023 requires equivalents to be accepted in technical specifications. Rejecting a supplier who can demonstrate equivalence is not rigour. It is a challenge waiting to happen.

Timing is where compliance quietly fails

The rules that catch teams out are the timing rules. Evidence of certification, or equivalence, is needed before contract award. The certificate must be held at the point data passes to the supplier. And certification must be renewed every 12 months for the duration of the contract, which means a three year contract needs at least two renewal checks that nobody's procurement checklist naturally prompts.

The PPN also expects requirements to be visible early: stated in the tender notice, and ideally flagged in preliminary market engagement so a supplier who wants the work has time to certify. A requirement that first appears in the ITT, weeks before submission, quietly excludes capable small suppliers who could have certified in time had they known. That is a competition problem as much as a security one.

What a defensible approach looks like

Treat PPN 014 as a decision framework, not a stamp. Screen each contract against the four higher risk characteristics: citizens' personal data, government employees' personal data, ICT at OFFICIAL, and information about the day-to-day business of government. Decide the level, basic, Plus, equivalent or none, and write the reasoning down. The PPN explicitly asks for decisions to be recorded in the audit trail, including the decision that no controls are needed.

Then check what the certificate actually covers. Scope can be restricted to part of a legal entity, and a supplier's cloud provider is not automatically inside it. ISO 27001 does not automatically satisfy the requirement either. The buyers who get this right treat the certificate as the start of assurance, not the end of it.

The takeaways

  • Require Cyber Essentials where the data justifies it, and be ready to defend the decision either way from your audit trail.
  • Never blanket-apply certification: proportionality is a requirement of the PPN, not a nice to have.
  • Check timing: evidence before award, certification held before data transfer, renewal every 12 months for the contract term.
  • Accept verified equivalent controls; section 56 of the Procurement Act 2023 requires it.
  • Read the certificate's scope. The legal entity, not the brand, is what is certified.

Want the full breakdown?

The complete explainer covers the key facts, the requirements in detail and a practical action list, free and printable in the Procurement Library.

Browse the Procurement Library →All articles