Cyber Essentials is a floor, not a strategy: reading PPN 09/23 properly
For a decade the UK government has pointed suppliers at one scheme, Cyber Essentials, as the entry ticket for contracts that touch personal data or official information. PPN 09/23 refreshed that policy in September 2023, and it is a more nuanced document than its reputation suggests. It tells buyers to demand certification more precisely, not more often, and it puts the audit trail, not the certificate, at the centre of good practice.
Two failure modes, one policy
In practice, public buyers tend to fall into one of two habits. Some stamp a Cyber Essentials requirement on every contract they let, because it feels safe. Others never mention it until contract signature, then scramble. The PPN targets both. It makes technical requirements mandatory where a contract shows any of four risk characteristics: citizens' personal data, personal data of government employees and ministers, ICT systems handling OFFICIAL information, or information about the day-to-day business of government. And in the same breath it prohibits a blanket approach.
The four characteristics are broad, and the honest reading is that most data-handling contracts will qualify. But plenty will not, and the PPN is unusually concrete about it. A sole trader delivering driving lessons with incidental IT use does not need certifying. A communications planning service with access to nothing more than civil servants' contact details may not either. The test is whether the requirement is relevant, proportionate and necessary, not whether it is habitual.
What buying teams get wrong
The first mistake is timing. Evidence of certification, or of equivalent controls, is needed before contract award, and the PPN's own FAQ advises flagging requirements at the pre-procurement stage and in the contract notice so bidders have the longest possible run at certification. A capable SME that first learns of the requirement at tender stage may simply run out of road, which narrows competition for no good reason.
The second is scope illusion. A certificate covers the legal entity providing the service, and can even be restricted to part of it. It does not automatically cover the cloud provider a supplier shares your data with, and ISO 27001 does not stand in for it, because the five Cyber Essentials controls are rarely inside an ISO 27001 scope. Renewal matters too: certification lapses after 12 months, and an organisation that stops patching can fall out of compliance much sooner.
The third is the missing paper trail. Deciding that a contract needs no cyber controls at all is a perfectly legitimate outcome under the PPN. Failing to record that decision is not. The audit trail requirement covers the decision not to act as much as the decision to act.
What suppliers should do now
Certify before you bid, not after you win. At £300 to £500 plus VAT for basic certification, this is one of the cheapest market-access investments available in public sector work, and it doubles as a signal to commercial customers, insurers and investors. If you are targeting higher-risk work, budget for Cyber Essentials Plus, which adds independent vulnerability testing.
Treat renewal as a delivery obligation. Where a contract requires certification, it must stay current for the life of the contract, so put the renewal date in the same system that tracks your insurance and accreditations. Keep the certificate's scope aligned with the entity actually delivering the work, and if you sell through G-Cloud, state your certification in your service offer even though the framework does not force you to hold it.
If you genuinely cannot certify, prepare an equivalence case. Buyers must accept equivalent controls for above threshold procurements, but expect to have them verified by a technically competent, independent third party rather than taken on trust.
The bigger point
Cyber Essentials mitigates common, commodity attacks. It does not assure specific products, and it will not stop a targeted adversary, which is why the PPN tells buyers to escalate to security specialists when the risk profile demands more. The certificate is a floor. The real discipline the PPN asks for is judgement: a buyer who can explain, contract by contract, why they required what they required, and a supplier who treats basic cyber hygiene as a permanent condition of trading with government rather than a one-off hurdle.
The takeaways
- Require certification where the four risk characteristics apply, and record the reasoning either way.
- Evidence is needed before award, so signal requirements at pre-market engagement and in the contract notice.
- Annual renewal and certificate scope are contract management issues, not procurement afterthoughts.
- ISO 27001 is not equivalence: the five controls must be demonstrated specifically.
- For suppliers, basic certification is a small cost against the market it opens.
Want the full breakdown?
The complete explainer covers the key facts, the requirements in detail and a practical action list, free and printable in the Procurement Library.
