Skip to main content
    NixInfinity-AI
    Getting Started

    My Customer Has Asked for Cyber Essentials – What Do I Do?

    Published 14 September 2026

    First, work out exactly what they asked for

    The request usually arrives in one of three forms: a line in a supplier questionnaire, a clause in a contract or framework agreement, or an email from a procurement or security contact. The wording matters more than the tone.

    • "Do you hold Cyber Essentials?" – standard Cyber Essentials. A certificate number and expiry date answers it.
    • "Cyber Essentials Plus is required" – you need the audited version. See CE vs CE Plus.
    • "Cyber Essentials or equivalent" – ISO 27001 or IASME Cyber Assurance may be accepted, but CE is usually the fastest and cheapest route to a yes.
    • "Certification required before contract award" – you can usually respond and bid while certification is in progress, provided the certificate exists by award.

    What you can send them today

    If you are not certified yet, do not go quiet. A short, honest reply protects the relationship:

    "We are working with an IASME-licensed Certification Body and expect our Cyber Essentials certificate to be issued by [date]. We will send the certificate number and IASME registry link as soon as it is issued."

    Buyers are used to this. What loses contracts is silence or a vague claim that you are "compliant" without a certificate.

    What Cyber Essentials actually asks of you

    Five technical control areas: firewalls, secure configuration, user access control, malware protection and security update management. In practice, most small organisations pass or fail on four things:

    • Multi-factor authentication enforced on every cloud account, not just administrators.
    • No unsupported operating systems in scope – old Windows builds and out-of-support phones are the usual blocker.
    • High and critical security updates applied within 14 days.
    • Administrator accounts separated from day-to-day accounts.

    Full detail is in the five controls guide and the readiness checklist.

    Cost and timescale, honestly

    • Cyber Essentials: £320 + VAT, priced by organisation size. Prepared organisations certify in 24 to 48 hours; two to four weeks is realistic if MFA is not yet in place.
    • Cyber Essentials Plus: £1,400 + VAT, one to three weeks, and it requires a valid Cyber Essentials certificate first.

    See Cyber Essentials cost for the pricing bands, and hidden costs for the kit and licences that occasionally need upgrading.

    What if we cannot pass right now?

    That is common and it is fixable. A failed self-assessment is not published anywhere, and there is no penalty for finding gaps before you submit. The usual remediation list is MFA rollout, replacing or removing two or three unsupported devices, and pulling a patch report together. Most organisations complete it in days rather than months.

    Send us the request and we will tell you which certification you need

    If you forward the exact wording your customer sent, we will tell you whether you need Cyber Essentials or Cyber Essentials Plus, what it will cost for your size of organisation, and whether your timeline is realistic. No obligation.

    Related reading: why customers ask for Cyber Essentials during onboarding and how to handle supplier security questionnaires.

    Not sure which certification your customer needs?

    Book a 30-minute call with a named IASME assessor. Bring the wording your customer sent and we will tell you exactly what is required.

    Frequently Asked Questions

    Related Cyber Essentials Guides