
A buyer sends you a sentence. Somewhere in a tender pack, a framework agreement or a supplier questionnaire, there is a line asking for Cyber Essentials, or Cyber Essentials Plus, or certification "or equivalent".
That sentence decides whether you can bid this month, next quarter, or at all. It is worth ten minutes of careful reading before anyone in the business promises a date.
Most public sector cyber security clauses trace back to one document. Procurement Policy Note 014 has applied since 24 February 2025, replacing PPN 09/14 and PPN 09/23, and it binds all central government departments, their executive agencies and non-departmental public bodies, along with NHS bodies.
It applies to contracts with particular risk characteristics: those handling personal information, those handling government employee data, those involving ICT systems that process data at OFFICIAL, and those touching information about government business and service delivery. Where a contract has those characteristics, the PPN treats Cyber Essentials or Cyber Essentials Plus certification as the means of managing the risk.
Two details in it are easy to miss and both affect your timeline.
The first is when the certificate has to exist. The PPN puts it at the point when data is to be passed to the supplier. That is often later than contract signature and considerably earlier than go-live, and it is a date you can work backwards from.
The second is proportionality. Certification should only be required where it is relevant to the subject matter of the contract, proportionate and necessary to manage cyber security risks. A requirement that fails that test is one you can reasonably question, and buyers do sometimes copy a clause across from an unrelated contract.
The phrase is not softening language. Under section 56 of the Procurement Act 2023, covering technical specifications, in-scope organisations must accept equivalents. A supplier needs only to demonstrate, to the satisfaction of the buying organisation, that it meets the Cyber Essentials requirements.
Two things follow from that.
The buyer cannot refuse an equivalent outright. If you can show the requirements are met, the door has to stay open, and a procurement that insists on the certificate and nothing else is not applying the policy correctly.
The buyer decides what satisfies it. "To the satisfaction of the in-scope organisations" places the judgement with them, so an equivalent is a conversation you have to win rather than a box you tick. The PPN adds that verification should normally come from a technically competent and independent third party. For Cyber Essentials Plus, that independent verification is required in every case.
In practice, arguing equivalence takes longer than certifying. It needs someone senior enough at the buyer to accept it, and that person has no incentive to carry the risk of an unusual decision. The route exists and it is worth knowing about. It is rarely the fastest way to a signed contract.
This is the assumption that costs suppliers the most time.
The PPN addresses it directly. Organisations holding ISO 27001 will not automatically conform to Cyber Essentials, because the five technical controls are not typically all included in the scope of an ISO 27001 certificate or tested as part of it. ISO 27001 certifies that a management system is operating. Cyber Essentials tests a defined set of technical controls across a defined boundary.
An ISO 27001 certificate is useful evidence towards an equivalence argument, and it does not stand in for the certificate itself. A bid team that assumes otherwise finds out at the point the buyer asks for a certificate number.
Five questions, worth answering in writing before anyone replies to the buyer.
Which level is named. Cyber Essentials and Cyber Essentials Plus are different requirements with different lead times, and Plus needs independent verification in all cases.
What the scope has to cover. A certificate covering part of your estate does not answer a clause that describes the systems handling the buyer's data. Your certificate lists its scope, and a buyer can see it.
When the certificate has to be in place. Contract award, data transfer and service commencement are three different dates, and clauses use all three.
Whether it cascades. Requirements of this kind are pushed down supply chains, so a clause that binds you may also bind the subcontractor doing the part of the work that touches the data.
Who verifies. If you are arguing equivalence, the PPN expects an independent competent third party to confirm it, which is work you need to have commissioned before you make the claim.
One more thing worth knowing. Cyber Essentials certificates are publicly searchable. IASME operates a certificate search covering certificates issued in the last twelve months, by organisation name or certificate number, showing the level, the issue date, the expiry and the scope. A buyer can check your position without asking you, and larger organisations use a separate supplier check platform to do this across many suppliers at once.
For requirement detail, see the Cyber Essentials framework page and the ISO 27001 framework page. For how long each route takes once you have decided, see how long ISO 27001, Cyber Essentials and DSPT take.
Naq is a Cyber Essentials Certifying Body via IASME, so Cyber Essentials and Cyber Essentials Plus run through the platform with the assessment and its evidence held together.
When a clause names a level and a scope, the useful thing is being able to see what you already satisfy. Controls sit against the requirements they answer, with evidence attached, so the gap between the clause and your current position is something you can look at in an afternoon. The same controls and evidence count towards ISO 27001, the NHS DSPT and your GDPR obligations, so preparing for one buyer's clause builds the answer to the next one.
If a clause has landed and you are working out what it commits you to, book a fifteen-minute demo and bring the wording with you.