My Customer Has Asked for Cyber Essentials – What Do I Do?
Published 14 September 2026
First, work out exactly what they asked for
The request usually arrives in one of three forms: a line in a supplier questionnaire, a clause in a contract or framework agreement, or an email from a procurement or security contact. The wording matters more than the tone.
- "Do you hold Cyber Essentials?" – standard Cyber Essentials. A certificate number and expiry date answers it.
- "Cyber Essentials Plus is required" – you need the audited version. See CE vs CE Plus.
- "Cyber Essentials or equivalent" – ISO 27001 or IASME Cyber Assurance may be accepted, but CE is usually the fastest and cheapest route to a yes.
- "Certification required before contract award" – you can usually respond and bid while certification is in progress, provided the certificate exists by award.
What you can send them today
If you are not certified yet, do not go quiet. A short, honest reply protects the relationship:
"We are working with an IASME-licensed Certification Body and expect our Cyber Essentials certificate to be issued by [date]. We will send the certificate number and IASME registry link as soon as it is issued."
Buyers are used to this. What loses contracts is silence or a vague claim that you are "compliant" without a certificate.
What Cyber Essentials actually asks of you
Five technical control areas: firewalls, secure configuration, user access control, malware protection and security update management. In practice, most small organisations pass or fail on four things:
- Multi-factor authentication enforced on every cloud account, not just administrators.
- No unsupported operating systems in scope – old Windows builds and out-of-support phones are the usual blocker.
- High and critical security updates applied within 14 days.
- Administrator accounts separated from day-to-day accounts.
Full detail is in the five controls guide and the readiness checklist.
Cost and timescale, honestly
- Cyber Essentials: £320 + VAT, priced by organisation size. Prepared organisations certify in 24 to 48 hours; two to four weeks is realistic if MFA is not yet in place.
- Cyber Essentials Plus: £1,400 + VAT, one to three weeks, and it requires a valid Cyber Essentials certificate first.
See Cyber Essentials cost for the pricing bands, and hidden costs for the kit and licences that occasionally need upgrading.
What if we cannot pass right now?
That is common and it is fixable. A failed self-assessment is not published anywhere, and there is no penalty for finding gaps before you submit. The usual remediation list is MFA rollout, replacing or removing two or three unsupported devices, and pulling a patch report together. Most organisations complete it in days rather than months.
Send us the request and we will tell you which certification you need
If you forward the exact wording your customer sent, we will tell you whether you need Cyber Essentials or Cyber Essentials Plus, what it will cost for your size of organisation, and whether your timeline is realistic. No obligation.
Related reading: why customers ask for Cyber Essentials during onboarding and how to handle supplier security questionnaires.
