Skip to main content
Cyber Essentials

Does PPN 014 require Cyber Essentials?

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

6 min read

Contents
    Cyber Essentials

    Does PPN 014 require Cyber Essentials?

    By Alfred Obeng, Founder, Goldline Consultancy

    ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

    6 min read

    Contents

      It requires it, and in the same sentence it expressly accepts equivalent controls instead. Both halves of that are in the primary text. The second half is the one that usually gets dropped.

      What PPN 014 is

      Procurement Policy Note 014 was published on 17 February 2025 and applies to procurements commencing on or after 24 February 2025, replacing PPN 09/23.

      Who it reaches, quoted from the note itself:

      "This PPN applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies."

      The sentence that matters

      "Since 2014 the government has required suppliers bidding for certain types of public contracts to hold Cyber Essentials or Cyber Essentials Plus certification (or demonstrate that equivalent controls are in place)."

      The parenthesis is doing real work and it is easy to miss. It sits at the end of a long sentence, and most summaries of the note paraphrase the first half and stop. Read in full, equivalent controls are expressly preserved as an alternative route.

      What that means when you are bidding

      The certificate is the cheapest and fastest way to satisfy the requirement. It is not the only way the note allows. If you already hold ISO 27001 at a scope that genuinely covers the contract, the equivalence route is open to you on the face of the note.

      Whether a particular buyer accepts it is then a conversation with that buyer, not a rule. Buyers routinely ask for the certificate because it is simple to evidence and simple to check, and a bid that argues equivalence is a bid asking an evaluator to do more work.

      The version trap

      Cyber Essentials requirements version 3.3 took effect on 27 April 2026. A certificate has to be current against the prevailing requirements, not merely inside its twelve months, so a certificate issued against an earlier version late in its cycle is worth checking before you rely on it in a bid.

      What this does not settle

      PPN 014 binds the buyer groups it names and nobody else. A private-sector buyer asking you for Cyber Essentials is doing so as a contract term of its own, and nothing in the note reaches that request or constrains it.

      And "equivalent controls" is not defined in the note with a checklist. The route exists, and the burden of demonstrating equivalence sits with the supplier. That is a real cost, and for most organisations it is higher than the cost of certifying.

      Source

      Procurement Policy Note 014, gov.uk. Read at source 10 September 2026. Cyber Essentials requirements for IT infrastructure v3.3, NCSC, effective 27 April 2026.

      Book a free diagnostic

      Alfred Obeng

      Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

      Alfred Obeng

      Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

      We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.