Procurement Policy Note · explained by eSourcing Data
Cyber Essentials in public contracts: PPN 014 explained
PPN 014 explained: when UK public contracts require Cyber Essentials or equivalent controls, which contracts are in scope and how buyers stay proportionate.
Source document: Procurement Policy Note 014: Cyber Essentials Scheme
The key facts
- PPN 014 applies to all central government departments, their executive agencies, non-departmental public bodies and NHS bodies. It replaces PPN 09/14 and PPN 09/23.
- The February 2025 update reflects Procurement Act 2023 terminology and applies to procurements commenced on or after 24 February 2025. Earlier procurements remain under PPN 09/23.
- Contracts are higher risk where a supplier handles citizens' personal information, personal information of government employees, ICT systems at the OFFICIAL classification, or information about the day-to-day business of government.
- Where Cyber Essentials certification is required it must be renewed annually by the supplier for the duration of the contract, and equivalent controls must be accepted under section 56 of the Procurement Act 2023.
- Evidence of certification, or equivalent, is required before contract award, and holding it is essential at the point when data is passed to the supplier.
- A blanket approach is expressly prohibited: requirements must be relevant to the subject matter, proportionate, and must not deter SMEs and VCSEs from bidding.
- Cyber Essentials covers five technical controls: boundary firewalls and internet gateways, secure configuration, access control, malware protection and security update management. Cyber Essentials Plus adds independent vulnerability testing.
- Decisions about cyber security controls, including where no measures are required, should be recorded in the procurement audit trail.
What PPN 014 is and who must follow it
Cyber Essentials is a government backed scheme that helps organisations of any size protect themselves against the most common cyber attacks and demonstrate their commitment to cyber security. Since 2014, the government has required suppliers bidding for certain types of public contract to hold Cyber Essentials or Cyber Essentials Plus certification, or to demonstrate that equivalent controls are in place. PPN 014 sets out the actions in-scope organisations should take to identify and mitigate cyber threats for those contracts.
The PPN applies to all central government departments, their executive agencies and non-departmental public bodies, and to NHS bodies, referred to together as in-scope organisations. Other public sector bodies may wish to apply the same approach. The guidance is aimed at commercial, procurement and contract management roles, and is also relevant to cyber security and digital and data professionals.
PPN 014 replaces PPN 09/14 and PPN 09/23. It was previously issued in September 2023 and updated in February 2025 to reflect the terminology of the Procurement Act 2023 and the Procurement Regulations 2024, which apply to procurements commenced on or after 24 February 2025. For procurements commenced or contracts awarded before that date, buyers should refer to PPN 09/23. The update does not change policy: organisations should continue to apply ongoing obligations but do not need to repeat actions already taken.
The contracts that need cyber security controls
In-scope organisations must ensure that effective and proportionate cyber security controls are applied to contracts to mitigate supply chain risks. The PPN identifies key characteristics of higher risk contracts. Suppliers must demonstrate they meet certain technical requirements where a contract involves handling citizens' personal information such as home addresses, bank details or payment information; handling personal information of government employees, ministers and special advisers, for example payroll, travel booking or expenses data; supplying ICT systems designed to store or process data at the OFFICIAL level of the Government Security Classifications Policy; or dealing with information related to the day-to-day business of government, service delivery and public finances.
For contracts with these characteristics, the quickest and most effective mitigation is to include Cyber Essentials or Cyber Essentials Plus certification in the technical requirements. Where certification is required, the supplier must renew it annually for the duration of the contract. A supplier that does not hold certification must be able to demonstrate equivalent controls through other means. To comply with section 56 of the Procurement Act 2023 on technical specifications, buyers must accept equivalents, normally verified by a technically competent and independent third party. For Cyber Essentials Plus, independent third party verification is required in all cases.
Timing matters. Evidence of holding a certificate, or equivalent, is required before contract award. In exceptional circumstances an organisation may take a risk based decision to let a contract commence while an expired certificate is being renewed, but the supplier must hold appropriate certification at the point when data is to be passed to them. Any applicable requirements must be specified in the tender notice, and the PPN recommends raising them early, ideally during preliminary market engagement, so suppliers have the longest possible time to seek certification.
Proportionality: where the scheme stops
PPN 014 is explicit that Cyber Essentials should not be applied to all contracts as a matter of course. In-scope organisations must not take a blanket approach. Security controls must be relevant to the subject matter of the contract, proportionate and necessary to manage the risk. Over-specifying certification burdens suppliers and can deter small and medium sized enterprises and voluntary, community and social enterprises from bidding for public work.
The scheme also has limits. It does not assure the specific products or services being supplied, so where product assurance is needed further standards should be applied. Where the risks of a contract exceed the parameters of the scheme, security teams or experts should be consulted on additional measures. Cyber Essentials is not designed to address advanced, targeted attacks; organisations facing those threats need a strategic approach as part of a wider security strategy.
Whatever is decided, the reasoning should be captured. The PPN asks organisations to record decisions on cyber security controls in the audit trail, including cases where risks are assessed as very low, not relevant, or where no measures are required. For cloud purchases through the Crown Commercial Service G-Cloud agreements, suppliers must demonstrate compliance with the government's Cloud Security Principles; Cyber Essentials is encouraged but is not a requirement of that commercial agreement, so buyers should assure themselves that risks are managed before awarding a call-off contract.
Cyber Essentials and Cyber Essentials Plus compared
Cyber Essentials assesses five technical controls: boundary firewalls and internet gateways, secure configuration, access control, malware protection and security update management. It is a self assessment option: the organisation completes a questionnaire which is then verified by an independent certification body, accredited through IASME. It offers a basic level of assurance, and the cost for smaller companies at the basic level is currently expected to range between £300 and £500 plus VAT.
Cyber Essentials Plus assesses the same controls but adds remote and on-site vulnerability testing using widely available commodity tools, checking whether the controls actually defend against basic hacking and phishing attacks. It is the more rigorous assessment and should be used where the risk is higher. Certification at either level must be renewed every 12 months; a supplier that fails to recertify becomes uncertified, and more frequent certification can be required on a risk basis.
Buyers should check what a certificate actually covers. By default it applies to the legal entity providing the goods or services, but suppliers can restrict scope to part of the entity, and third parties such as cloud providers are not automatically covered. ISO 27001 does not automatically satisfy Cyber Essentials, because the five controls are not usually in scope of an ISO 27001 implementation. Separately, the Model Services Contract used for complex contracts exceeding £20 million requires Cyber Essentials or equivalent for suppliers and relevant subcontractors through its security management schedule.
How eSourcing Data helps
PPN 014 asks buyers to make case-by-case decisions and to evidence them: which contracts carry the higher risk characteristics, which level of certification is proportionate, and why. eSourcing Data records those decisions as part of a structured audit trail, so the reasoning behind requiring, or not requiring, Cyber Essentials is captured against the procurement rather than sitting in someone's inbox.
The platform helps teams apply the requirement at the right moments. Certification requirements can be built into published notices and tender documentation so suppliers see them early, and supplier management records can hold certificates and expiry dates, supporting the annual renewal checks the PPN expects for the life of the contract.
Because the same workflows cover below threshold purchasing, teams can apply a proportionate version of the same discipline to smaller contracts, asking only what is relevant and keeping a consistent record across the whole pipeline.
What to do about it
- 1Screen every new requirement against the four higher risk characteristics in PPN 014 before drafting the specification.
- 2Choose the proportionate control for each contract: Cyber Essentials, Cyber Essentials Plus or equivalent, and record the reasoning.
- 3State any certification requirement in the tender notice and raise it during preliminary market engagement so suppliers have time to certify.
- 4Verify certificates, or equivalent independent evidence, before contract award and again before any data is passed to the supplier.
- 5Diarise annual recertification checks for the duration of each affected contract.
- 6Check the scope of each certificate covers the legal entity delivering the contract, and consider third parties such as cloud providers who will touch your data.
- 7Record every control decision, including where no measures are required, in the procurement audit trail.
Put this into practice on the platform
eSourcing Data runs compliant notices, evaluation, supplier management and audit trails out of the box, so meeting this guidance is the workflow, not extra work.
This explainer summarises and interprets an official document for general information; it is not legal advice. Contains public sector information licensed under the Open Government Licence v3.0. Nothing here implies endorsement of eSourcing Data by any government body.
