Does PPN 014 require Cyber Essentials?
By Alfred Obeng, Founder, Goldline Consultancy
ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP
6 min read
Contents
It requires it, and in the same sentence it expressly accepts equivalent controls instead. Both halves of that are in the primary text. The second half is the one that usually gets dropped.
What PPN 014 is
Procurement Policy Note 014 was published on 17 February 2025 and applies to procurements commencing on or after 24 February 2025, replacing PPN 09/23.
Who it reaches, quoted from the note itself:
"This PPN applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies."
The sentence that matters
"Since 2014 the government has required suppliers bidding for certain types of public contracts to hold Cyber Essentials or Cyber Essentials Plus certification (or demonstrate that equivalent controls are in place)."
The parenthesis is doing real work and it is easy to miss. It sits at the end of a long sentence, and most summaries of the note paraphrase the first half and stop. Read in full, equivalent controls are expressly preserved as an alternative route.
What that means when you are bidding
The certificate is the cheapest and fastest way to satisfy the requirement. It is not the only way the note allows. If you already hold ISO 27001 at a scope that genuinely covers the contract, the equivalence route is open to you on the face of the note.
Whether a particular buyer accepts it is then a conversation with that buyer, not a rule. Buyers routinely ask for the certificate because it is simple to evidence and simple to check, and a bid that argues equivalence is a bid asking an evaluator to do more work.
The version trap
Cyber Essentials requirements version 3.3 took effect on 27 April 2026. A certificate has to be current against the prevailing requirements, not merely inside its twelve months, so a certificate issued against an earlier version late in its cycle is worth checking before you rely on it in a bid.
What this does not settle
PPN 014 binds the buyer groups it names and nobody else. A private-sector buyer asking you for Cyber Essentials is doing so as a contract term of its own, and nothing in the note reaches that request or constrains it.
And "equivalent controls" is not defined in the note with a checklist. The route exists, and the burden of demonstrating equivalence sits with the supplier. That is a real cost, and for most organisations it is higher than the cost of certifying.
Source
Procurement Policy Note 014, gov.uk. Read at source 10 September 2026. Cyber Essentials requirements for IT infrastructure v3.3, NCSC, effective 27 April 2026.
Book a free diagnosticAlfred Obeng
Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.
