This guide is for training and L&D providers who have been asked for Cyber Essentials certification in a framework application or tender, or expect to be. If you hold learner records, booking details or assessment results for a public sector client, you handle personal data on the buyer's behalf, and that is exactly when buyers start asking.
Cyber Essentials certification is the government-backed baseline for cyber security. It is not difficult for a small, well-run training business to achieve, but it takes some preparation, it costs money, and it has to be renewed every year. Here is what it involves.
What Cyber Essentials is
The National Cyber Security Centre (NCSC) describes Cyber Essentials as the minimum standard of cyber security recommended by the government for organisations of all sizes. IASME is the NCSC's delivery partner and licenses the certification bodies that carry out assessments.
The Cyber Essentials requirements are built around five technical controls:
- Firewalls, controlling traffic between your network and the internet.
- Secure configuration, so devices and software are set up to reduce weak points.
- Security update management, keeping software patched.
- User access control, so people only reach the data and systems they need.
- Malware protection.
Cyber Essentials and Cyber Essentials Plus
Both levels check the same five controls. The difference is how they are checked.
- Cyber Essentials is a self-assessment questionnaire, verified by an independent certification body.
- Cyber Essentials Plus adds a technical audit. An assessor runs internal and external vulnerability scans and tests a sample of your devices, typically around 10 per cent, to confirm the controls work in practice.
If you already hold Cyber Essentials from less than three months earlier, you do not repeat the questionnaire when you go for Plus.
When public buyers ask for it
For central government departments, their agencies and NHS bodies, the rule is Procurement Policy Note 014, issued in February 2025. It replaced PPN 09/14 and PPN 09/23. Other public bodies, such as councils, may choose to follow the same approach.
PPN 014 says that where a contract involves, among other things, a supplier handling citizens' personal information, buyers must make suppliers show they meet the technical requirements, and that the quickest way is to ask for Cyber Essentials or Cyber Essentials Plus. One of its own examples is a service supporting people back into work, where the supplier holds names, addresses, dates of birth and National Insurance numbers. Plenty of funded training looks much the same.
The PPN also limits what buyers can ask:
- It must not be applied to every contract as a matter of course. The requirement has to be relevant and proportionate.
- Any requirement must be stated in the tender notice.
- Buyers must accept equivalent evidence, normally verified by an independent third party.
- Evidence is needed before contract award, and certification must be renewed annually for the life of the contract.
So for Cyber Essentials in government contracts: a leadership programme with no learner data may not need it, while statutory and mandatory training for an NHS trust that involves staff records may. NHS bodies are in scope of PPN 014, so if you plan to bid on NHS work such as the EEAST training framework, check its requirements early.
What it costs
IASME publishes the Cyber Essentials cost by organisation size, based on employee numbers:
- Micro (0–9 employees): £320 + VAT
- Small (10–49): £440 + VAT
- Medium (50–249): £500 + VAT
- Large (250 or more): £600 + VAT
There is no fixed Cyber Essentials Plus cost. It depends on the size and complexity of your network and is quoted individually; IASME can put you in touch with certification bodies for quotes.
NCSC also notes that a UK organisation with turnover under £20 million that certifies its whole organisation is entitled to cyber liability insurance arranged through IASME.
How long it takes
IASME recommends downloading the question set in advance and preparing your answers. If you have, the self-assessment itself can take about an hour. Assessors usually aim to return results within three days. If you fail, you have two working days to fix simple issues and resubmit. You have six months from paying to complete the assessment.
The preparation is where the time goes: patching laptops, removing old accounts, and checking that every device used for learner records is set up to the standard.
Cyber Essentials renewal
Cyber Essentials and Cyber Essentials Plus certificates expire after 12 months. IASME removes lapsed organisations from its list of certified organisations. Put the renewal date in the diary when you certify.
Cyber Essentials sits alongside the other evidence a framework asks for. See our insurance, ICO and DBS checklist, how to become a public sector training provider, and the frameworks we help with on our frameworks page.
Frequently asked questions
What is Cyber Essentials certification?
A government-backed scheme, run by the NCSC with IASME as delivery partner, that certifies an organisation has five basic technical controls in place: firewalls, secure configuration, security update management, user access control and malware protection.
Do training providers need Cyber Essentials for government contracts?
Only when the buyer asks for it. Central government and NHS buyers must require it, or equivalent controls, for contracts where the supplier handles personal information such as learner records. It should not be required for every contract.
How much does Cyber Essentials cost?
IASME prices the basic assessment by organisation size, from £320 + VAT for organisations with up to nine employees to £600 + VAT for 250 or more. Cyber Essentials Plus is quoted individually.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Both cover the same five controls. Cyber Essentials is a verified self-assessment; Cyber Essentials Plus adds a technical audit with vulnerability scans and device testing.
How often does Cyber Essentials need renewing?
Every 12 months. Certificates expire after a year, and central government contracts that require it expect it to be renewed for the life of the contract.
Sources
- NCSC — Cyber Essentials overview
- IASME — Cyber Essentials frequently asked questions
- GOV.UK (Cabinet Office) — PPN 014: Cyber Essentials scheme
- GOV.UK — PPN 014 full text (PDF)