eSourcingData - Source-to-Contract Procurement Software

Procurement Policy Note · explained by eSourcing Data

Cyber Essentials in public contracts: PPN 09/23, explained

What PPN 09/23 requires: when public buyers must ask for Cyber Essentials or equivalent controls, which contracts are in scope and how suppliers comply.

Central government commercial and procurement teamsNHS procurement and contract managersSuppliers bidding for contracts that involve personal or official dataCyber and information security teams supporting procurement6 min read

Source document: Procurement Policy Note: Updates to the Cyber Essentials Scheme

The key facts

  • PPN 09/23 applies to all central government departments, their executive agencies, non-departmental public bodies and NHS bodies, and replaces PPN 09/14.
  • In-scope organisations were expected to implement the PPN within three months of its September 2023 publication.
  • Contracts involving citizens' personal data, government employees' personal data, ICT systems handling OFFICIAL information, or the day-to-day business of government must require Cyber Essentials, Cyber Essentials Plus or equivalent controls.
  • Where certification is required it must be renewed annually by the supplier for the duration of the contract.
  • Evidence of certification, or equivalent controls, is required before contract award and is essential at the point data is passed to the supplier.
  • A blanket approach is expressly prohibited: controls must be relevant and proportionate so SMEs and VCSEs are not deterred from bidding.
  • Cyber Essentials covers five technical controls: boundary firewalls and internet gateways, secure configuration, access control, malware protection and security update management.
  • Basic certification is expected to cost smaller companies between £300 and £500 plus VAT; Cyber Essentials Plus costs depend on network size and complexity.

What PPN 09/23 is and who it applies to

Procurement Policy Note 09/23, published in September 2023, sets out how public buyers should identify and mitigate cyber threats when letting certain types of contracts. It updates the government's long-standing use of Cyber Essentials, a government backed certification scheme that helps organisations of any size protect themselves against the most common cyber attacks and demonstrate their commitment to cyber security. Since 2014, suppliers bidding for certain public contracts have been required to hold Cyber Essentials or Cyber Essentials Plus certification, or to demonstrate that equivalent controls are in place. This PPN replaces PPN 09/14.

The note applies to all central government departments, their executive agencies and non-departmental public bodies, and to NHS bodies, referred to collectively as in-scope organisations. Other public sector bodies may choose to apply the same approach. In-scope organisations were expected to implement the PPN within three months of publication and to circulate it to commercial, procurement and contract management staff, as well as to cyber security, information security and digital, data and technology professionals.

When Cyber Essentials must be required

The PPN identifies key characteristics that mark a contract as higher risk. In-scope organisations must ensure suppliers meet technical requirements where a contract involves: personal information of citizens, such as home addresses, bank details or payment information; personal information of government employees, ministers or special advisers, for example payroll, travel booking or expenses data; ICT systems and services designed to store or process data at the OFFICIAL level of the Government Security Classifications Policy; or information relating to the day-to-day business of government, service delivery and public finances. The annex to the PPN gives illustrative examples, including CV writing services, car hire for staff and contact centre services.

For contracts with these characteristics, the quickest and most effective mitigation is to include Cyber Essentials or Cyber Essentials Plus certification in the technical requirements. Where certification is required, the supplier must renew it annually for the duration of the contract. A supplier that does not hold certification must be able to demonstrate equivalent controls through other means. Evidence of certification, or of equivalent controls, is required before contract award, and holding it is essential at the point data is to be passed to the supplier.

Cyber Essentials assesses five technical controls: boundary firewalls and internet gateways, secure configuration, access control, malware protection and security update management. Certification is based on a self assessment questionnaire verified by an independent certification body, which offers a basic level of assurance. Cyber Essentials Plus tests the same controls but adds remote and on-site vulnerability testing, and should be used where the risk of cyber security threats is higher. For smaller companies, basic certification is expected to cost between £300 and £500 plus VAT, with the cost of Plus depending on the size and complexity of the network.

Proportionality: the PPN bans a blanket approach

The PPN is explicit that Cyber Essentials should not be applied to all contracts as a matter of course. In-scope organisations must not take a blanket approach. Security controls must be relevant and proportionate to the product, goods or services being procured, and required only where necessary to manage cyber security risk. The stated concern is practical: overburdening suppliers deters small and medium-sized enterprises and voluntary, community and social enterprises from bidding for public contracts.

The scheme also has limits. It does not assure the specific products or services being supplied, and it is not designed to address more advanced, targeted attacks. Where the risks attached to a contract exceed the scheme's parameters, security teams or experts should be consulted and proportionate additional measures put in place as part of a wider organisational security strategy.

Every decision must leave a record. The PPN requires decisions about appropriate cyber security controls to be captured in the audit trail, including where risks are assessed as very low, not relevant, or where no measures are required at all.

G-Cloud, equivalence and other standards

Suppliers on Crown Commercial Service G-Cloud agreements are required to demonstrate compliance with the government's Cloud Security Principles. They are encouraged to state Cyber Essentials certification as part of their service offer, but the commercial agreement does not require them to hold it. Buyers awarding call-off contracts through G-Cloud must therefore assure themselves that suppliers are managing relevant cyber risks effectively before making an award.

Equivalence matters legally as well as practically. For above threshold procurements, buyers must accept equivalent means of demonstrating that Cyber Essentials requirements are met, normally verified by a technically competent and independent third party. Buyers should also check the scope of a certificate: by default it covers the legal entity providing the goods or services, it can be restricted to part of that entity, and it does not automatically cover third parties such as cloud providers with whom a supplier shares information.

The PPN also positions Cyber Essentials alongside other regimes. The Model Services Contract, used for complex services contracts exceeding £20 million in value, already requires certification for suppliers and relevant subcontractors. The Government Functional Standard GovS 007: Security sets mandatory security outcomes for organisations handling government information. ISO 27001 certification does not automatically satisfy Cyber Essentials, because the five technical controls are not usually within an ISO 27001 scope or tested under it, so most ISO certified businesses still need Cyber Essentials or demonstrable equivalent controls.

How eSourcing Data helps

PPN 09/23 asks buying teams to make defensible, contract-by-contract judgements and to record them. eSourcing Data supports that discipline directly: decisions made in the platform, including a decision that cyber risk is very low and no controls are needed, sit in a full audit trail that can be evidenced later.

Requirements also have to reach the market clearly and early. The platform lets teams build Cyber Essentials requirements into published notices and selection questions, so bidders see certification expectations from the start and have the longest possible time to obtain a certificate. Supplier management records can hold certificate details and renewal dates, helping contract managers track the annual recertification the PPN requires for the life of the contract.

For NHS bodies and other in-scope organisations running high volumes of procurement, consistent templates and reporting make it easier to show that the approach taken is proportionate rather than blanket, which is exactly the balance the PPN demands.

What to do about it

  1. 1Map current and planned contracts against the four higher-risk characteristics set out in the PPN.
  2. 2Specify Cyber Essentials or Cyber Essentials Plus requirements in the contract notice, and raise them as early as pre-market engagement so bidders have time to certify.
  3. 3Check certificates before award, write annual renewal into the contract, and verify certification or equivalence before any data is passed to the supplier.
  4. 4Accept equivalent controls where offered, verified by a technically competent and independent third party.
  5. 5Record every decision, including where cyber risk is assessed as very low or not relevant, in the procurement audit trail.
  6. 6Consult security teams where risks exceed the scheme, and check certificate scope where suppliers share data with third parties such as cloud providers.

Put this into practice on the platform

eSourcing Data runs compliant notices, evaluation, supplier management and audit trails out of the box, so meeting this guidance is the workflow, not extra work.

Read our take on the blog →Back to the Procurement Library

This explainer summarises and interprets an official document for general information; it is not legal advice. Contains public sector information licensed under the Open Government Licence v3.0. Nothing here implies endorsement of eSourcing Data by any government body.

All documents