Cyber Essentials for Supplier Onboarding: Why Customers Ask for It
Published 17 September 2026
What changed in supplier onboarding
Supply chain attacks pushed cyber security out of the IT department and into procurement. Large organisations now run supplier risk assessments before onboarding, and Cyber Essentials has become the default screening question because it is binary: you either hold a current certificate or you do not.
What the buyer is actually checking
- Certificate number and expiry date – verified against the public IASME registry.
- Scope – whether the certificate covers the whole organisation or only part of it. A narrow scope that excludes the team delivering their contract is a red flag.
- Level – standard Cyber Essentials or Cyber Essentials Plus, depending on the data you will handle.
- Continuity – whether you have held it consistently or let it lapse and renewed under pressure.
Scope is the one suppliers get wrong. Read good vs bad scope statements before you decide to certify only part of the business.
Where the requirement usually comes from
- Public sector procurement rules for contracts handling personal or sensitive information.
- An enterprise customer's own certification obligations cascading down to their suppliers.
- Cyber insurance conditions on the buyer's policy.
- Framework agreements – see Cyber Essentials for Government Commercial Agency frameworks.
Getting through onboarding without holding up the contract
- Ask the buyer whether standard Cyber Essentials or Plus is required, and by what date.
- Decide scope early – whole organisation is usually simplest and avoids repeat questions.
- Fix the common blockers first: MFA on all cloud accounts, no unsupported devices, patching inside 14 days.
- Certify, then send the certificate number and registry link to their procurement contact directly.
- Diarise renewal 6 to 8 weeks before expiry so onboarding for the next customer is instant.
The commercial upside
Suppliers who hold Cyber Essentials get onboarded faster, spend less time on bespoke security questionnaires and can quote it directly in bids. It is also a prerequisite for IASME Cyber Assurance if a buyer later asks for governance evidence beyond technical controls.
If a customer has just asked you for it, start with what to do when a customer asks for Cyber Essentials.
