What Happens if My Supplier Does Not Have Cyber Essentials?
Published 21 September 2026
What the gap actually means
Cyber Essentials is a technical-control baseline reviewed and certified by an IASME-licensed Certification Body. Without it, a supplier's security claims are self-declared and unverified. That matters most when the supplier will:
- hold or process your personal, financial or client data;
- connect to your systems, tenant or network;
- be named in your own contractual or regulatory obligations;
- deliver into a public sector contract where the requirement cascades down.
Your practical options
- Conditional onboarding. Award or onboard with a contractual condition that Cyber Essentials is certified within an agreed window, typically 30 to 60 days.
- Interim evidence. Ask for MFA enforcement screenshots, a patch status report, an asset list and confirmation that no unsupported operating systems are in use. That covers the highest-risk controls while certification runs.
- Reduce exposure. Limit data access, avoid tenant-to-tenant connections and use time-limited guest accounts until the certificate is issued.
- Decline. Appropriate where the contract carries a hard certification requirement you cannot waive.
What to write into the contract
- The supplier holds and maintains current Cyber Essentials for the duration of the contract.
- The certificate scope covers the people, devices and cloud services used to deliver the contract.
- Notification within a set number of days if the certificate lapses or is not renewed.
- Where relevant, an upgrade to Cyber Essentials Plus at a defined point.
How to verify a certificate you have been sent
Check the certificate number and expiry date against the public IASME registry, and read the scope statement rather than just the front page. A certificate that excludes the delivery team, their laptops or the cloud platform used on your contract does not give you the assurance you think it does.
How long certification takes, so your deadline is realistic
- Prepared supplier: 24 to 48 hours.
- Typical small supplier needing an MFA rollout: two to four weeks.
- Cyber Essentials Plus: one to three weeks after standard Cyber Essentials is in place.
If you want to point a supplier somewhere useful, send them this guide for suppliers or the readiness checklist.
