Skip to main content
    NixInfinity-AI
    Sector Guide

    Cyber Essentials for Digital Agencies in the Public Sector

    Published 29 July 2026

    Why the public sector asks for CE

    Agencies routinely handle brand assets, user research, personal data and access to client CMS platforms. Public-sector buyers treat cyber security as a supplier hygiene test and use Cyber Essentials as the baseline evidence.

    Agency-specific scope questions

    • Freelancers using their own laptops – if they access in-scope systems, MFA and password policy apply. Document it.
    • Cloud tenants (Google Workspace, Microsoft 365) in scope by default.
    • Client CMS access – normally in the client's scope but you need MFA at your end.
    • Design tool tenants (Figma, Adobe CC) – controls apply to the accounts, not the tools themselves.

    The three biggest fail points

    • MFA missing on non-admin cloud accounts (Danzell 2026 tightened this).
    • Unmanaged personal macOS laptops with out-of-date OS.
    • Shared credentials for client CMSes – must be per-user with MFA.

    Route to certified

    1. Enforce MFA in Google Workspace or Microsoft 365 across all users.
    2. Publish a BYOD policy and enforce OS support level.
    3. Move all client CMS access to per-user accounts with MFA.
    4. Book the assessment – fast-track available for bid deadlines.

    For the framework-specific bidding view, see the G-Cloud 15 hub. For consultancies that also bid on tech services and outcomes work, see Cyber Essentials for IT consultants.

    Ready to certify your agency?

    Fast, framework-ready certification with a named IASME assessor.

    Frequently Asked Questions

    Related Cyber Essentials Guides