Skip to main content
    NixInfinity-AI
    G-Cloud 15

    G-Cloud 15 Cyber Essentials Requirements: 2026 Supplier Guide

    Published 29 July 2026

    What G-Cloud 15 actually requires

    G-Cloud 15 (RM1557.15) has five lots: 1a and 1b cloud hosting, 2a infrastructure software as a service, 2b software as a service, and 3 cloud support. The security expectation is set per lot rather than applied as one blanket rule, and the authoritative wording sits in the framework tender documents. Always read the technical ability certificate for the lot you are bidding on before you decide which certificate to buy. You can download them from the official G-Cloud 15 tender documents page, and the framework notice itself is on Find a Tender.

    Standard Cyber Essentials vs CE Plus

    The hosting lots (1a and 1b) carry the highest risk because you hold the buyer's data and workloads, and they look for Cyber Essentials Plus. The software and support lots (2a, 2b and 3) look for standard Cyber Essentials. Beyond that, a contracting authority can specify Cyber Essentials Plus at call-off for work involving higher-impact data (typically OFFICIAL-SENSITIVE, health data or defence-related work). Do not buy CE Plus for a software or support lot unless a specific call-off names it – you will spend more than you need to.

    Do subcontractors need Cyber Essentials?

    Yes, if they touch in-scope data. The prime contractor is accountable for its supply chain and GCA auditors will ask. Onboarding a subcontractor without a valid certificate is one of the most common failure points at contract-award stage. If you are onboarding fast, we can certify the subcontractor within 24 to 48 hours – see fast Cyber Essentials certification.

    Overseas suppliers

    Non-UK companies can and must hold Cyber Essentials to trade on G-Cloud 15. The scheme is UK-run but accepts overseas entities. The assessor is UK-based (IASME accredited); the scope covers the systems used to deliver the service, wherever they are hosted.

    The five technical controls in G-Cloud 15 context

    • Firewalls at every internet boundary and on end-user devices.
    • Secure configuration of laptops, servers, cloud tenants and mobile devices.
    • User access control including MFA on every cloud account under the 2026 Danzell question set.
    • Malware protection on every in-scope device.
    • Security update management within the 14-day rule for high or critical vulnerabilities.

    Full breakdown in the five controls guide.

    Timeline pressures

    G-Cloud submission windows are short and often overlap with year-end procurement pushes. If your certificate is not valid at contract award, the award can be withdrawn. Realistic timings:

    • Prepared, in-scope, MFA already deployed: 24 to 48 hours (fast-track).
    • Standard organisation, 10 to 49 staff, no blockers: 5 to 10 working days.
    • Larger org or MFA rollout still needed: 2 to 4 weeks.

    Common G-Cloud 15 certification blockers

    • MFA not yet enforced on all cloud user accounts (Danzell 2026 tightened this).
    • Unsupported operating systems still in use – see unsupported software guide.
    • BYOD scope unclear or admin accounts shared.
    • Patch policy documented but not evidenced.

    Ready to move? Start with the G-Cloud 15 supplier hub or the readiness checklist.

    Need Cyber Essentials for G-Cloud 15?

    Named IASME assessor, 24 to 48 hour fast-track, unlimited retests. £320 + VAT.

    Frequently Asked Questions

    Related Cyber Essentials Guides