Cyber Essentials for suppliers is a procurement decision that most organisations get halfway right. They ask for the certificate during the tender, tick a box when a PDF arrives by email, and then never mention it again for the next three years. The requirement lives in a questionnaire rather than in the contract, which means it has no expiry date, no evidence obligation and no consequence attached to it. When the supplier’s certification quietly lapses eleven months later, nobody notices, because nothing in the agreement was ever written to notice.

The gap matters more every year. Supply chain compromise has become a standard route into an otherwise well-defended organisation, and cybersecurity questions that used to sit with IT now arrive from insurers, auditors and your own largest customers. Asking for Cyber Essentials for suppliers is a cheap, proportionate control — but only when the requirement is contractual, scoped and enforceable rather than aspirational. A certificate you cannot verify, cannot re-request and cannot act on is decoration.

This guide covers how to write Cyber Essentials for suppliers into an agreement properly. It sets out which suppliers belong in scope, the clause wording that actually works, what evidence to demand and how to check it, how the obligation flows down to subcontractors, what happens when a certificate lapses mid-term, and the proportionate remedies that give the clause teeth without frightening off good small suppliers. If you want the background on why buyers ask for the certificate at all, our guide to Cyber Essentials as a supply-chain trust signal is the better starting point.

Why Cyber Essentials for Suppliers Belongs in the Contract

cyber essentials for suppliers contract clauses b rosette seal ribbon plinth

A due diligence questionnaire records what was true on the day somebody filled it in. A contract records what must remain true for the life of the relationship. Those are entirely different instruments, and putting Cyber Essentials for suppliers in the first one while leaving it out of the second is the single most common mistake in supplier security.

A questionnaire answer expires the moment it is submitted

Pre-contract questionnaires are snapshots. The supplier who answered “yes, certified” in March may have let the certificate lapse by the following March, changed their cloud platform, acquired a company with a very different security posture, or moved your data onto a system that was never in the assessed scope. None of that is dishonest. It is simply what happens to organisations over time, and only a continuing contractual obligation tracks it. Treating Cyber Essentials for suppliers as a one-off admission test rather than a standing condition is what lets that drift go unnoticed.

Only a contract creates something you can enforce

If a supplier loses certification and the requirement lives in a tender response, you have a disappointment. If it lives in the contract, you have a breach, a rectification route and — where it matters — a right to restrict access or terminate. That difference is the entire point of writing Cyber Essentials for suppliers into the agreement rather than the procurement file. Good vendor management is mostly the discipline of turning expectations into obligations.

The certificate is a point-in-time statement by design

Certification lasts twelve months and reflects the estate as assessed. It is a floor, not a guarantee, and the scheme has never claimed otherwise. Anyone specifying Cyber Essentials for suppliers should read the certificate as a dated statement rather than a permanent property of the organisation, because the alternative is a folder of expired PDFs and a genuine belief that the supply base is covered.

Your own customers are starting to ask downstream

Larger buyers, public sector frameworks and cyber insurers increasingly ask what you require of your own suppliers. A clause mandating Cyber Essentials for suppliers answers that question in one line. An informal preference does not, and “we ask about it during onboarding” reads badly in an insurance claim or a framework audit.

Where a supplier security requirement typically fails (indicative model of 100 buyer-side requirements that never bite)
Asked at tender, never written into the contract 38%
In the contract, but no evidence obligation 24%
Evidence required once, never re-checked 19%
No defined scope, so any certificate passes 12%
Breach identified, no remedy available 7%

What Cyber Essentials Actually Certifies, and What It Does Not

cyber essentials for suppliers contract clauses c stack five hexagon blocks

Before you can write a sensible clause you need an honest view of what the certificate proves. Overclaiming leads to lazy contracts; underclaiming leads to demanding ISO 27001 from a two-person design agency. Buyers who specify Cyber Essentials for suppliers without understanding the scheme’s boundaries tend to make both errors in the same document. The scheme is backed by the NCSC and delivered through IASME, and its ambition is deliberately narrow.

The five technical controls

Certification covers firewalls and internet gateways, secure configuration, security update management, user access control, and malware protection. These are the controls that stop commodity, untargeted attacks — the overwhelming majority of what any supplier will actually face. They are basic in the sense of foundational, not in the sense of trivial, and a surprising number of organisations fail on patching windows and administrative account separation at the first attempt.

Self-assessment against the audited Plus level

Standard Cyber Essentials is a verified self-assessment: the supplier answers a question set, a senior officer signs it off, and a certification body reviews the answers. Cyber Essentials Plus adds independent technical testing — vulnerability scanning of internet-facing systems and hands-on checks against a sample of end-user devices. Both cover the same five controls. The difference is entirely in how the claim is verified, which is exactly the distinction your contract should draw when it sets the level of Cyber Essentials for suppliers it demands.

Scope is the part everybody misreads

A certificate can cover a whole organisation or a defined, segregated part of it. A supplier can hold a valid certificate whose scope excludes the very division, product or cloud tenancy that serves you. This is legitimate under the scheme and catastrophic in a contract that says only “the Supplier shall hold Cyber Essentials certification”. When you specify Cyber Essentials for suppliers, specify the scope in the same sentence.

What it does not tell you

It says nothing about the supplier’s incident response maturity, their staff vetting, their business continuity arrangements, their subprocessors, their secure development practices or whether they encrypt your data at rest. Those belong in other schedules. Cyber Essentials for suppliers is a threshold test that keeps the obviously unprepared out; it is not a substitute for compliance work on the risks specific to what the supplier actually does for you.

DimensionCyber EssentialsCyber Essentials PlusISO 27001
What it assessesFive technical controlsSame five controlsA management system
How it is verifiedReviewed self-assessmentIndependent technical auditAccredited external audit
Typical effort for an SMEDaysWeeksMonths
Validity12 months12 months3 years with surveillance
Covers policy and governanceNoNoYes
Covers incident responseNoNoYes
Proportionate for a micro supplierYesSometimesRarely
Sensible contractual defaultMost suppliersHigh-access suppliersStrategic or regulated

Scoping Cyber Essentials for Suppliers: Who Needs It, at What Level

cyber essentials for suppliers contract clauses d magnifying glass plinth

The fastest way to discredit a supplier security programme is to send the same demanding clause to every counterparty on the ledger. Your window cleaner does not need Cyber Essentials Plus. Tiering is what makes Cyber Essentials for suppliers defensible when a supplier pushes back, and it is the part most organisations skip.

Tier by access, not by spend

Procurement instinctively segments by contract value, which is the wrong axis for security. A £4,000-a-year marketing automation tool holding your entire customer list is a far larger exposure than a £400,000 construction contract. Sort your supply base by what the supplier can reach: your data, your network, your users’ devices, your production systems. Spend tells you about commercial leverage; access tells you about risk, and access is the only sensible basis for deciding where Cyber Essentials for suppliers applies.

Four questions that decide the tier

Does the supplier process personal data on your behalf? Do they hold credentials, keys or administrative access to any system of yours? Do they connect to your network, or install software on your endpoints? Would their unavailability stop you trading within 48 hours? Any single “yes” puts a supplier above the baseline, and two or more usually justifies the audited level.

Where Cyber Essentials Plus is genuinely justified

Reserve it for suppliers with privileged remote access, bulk personal data, or the ability to push code and configuration into your environment. Managed service providers, payroll bureaux, development partners and anyone holding your production credentials belong here. That population is normally small — often under a tenth of the supplier list — which is precisely what makes the audited tier of Cyber Essentials for suppliers affordable to enforce.

When to accept an alternative

A supplier certified to ISO 27001 with a scope that genuinely covers your service is not improved by being made to also sit a self-assessment, although many buyers still ask for both because the technical controls do not map cleanly. Write an equivalence provision rather than a blanket refusal, and require the alternative’s scope statement so you can check it covers the same ground. Our breakdown of ISO 27001 certification cost explains why insisting on it from small suppliers usually backfires.

Supplier tierTypical accessCertification to requireEvidence cadence
Tier 1 — criticalAdmin credentials, production access, bulk personal dataCyber Essentials PlusAnnually, plus on any change
Tier 2 — data processingProcesses personal data, no network accessCyber EssentialsAnnually
Tier 3 — connectedPortal or VPN access, limited dataCyber EssentialsAnnually
Tier 4 — incidentalNo systems access, no personal dataNone, or self-declarationAt renewal only
Software vendorsCode and updates into your estatePlus, plus secure development termsAnnually
Resellers and brokersContract only, work performed downstreamFlow-down to the performing partyAnnually

Writing the Cyber Essentials for Suppliers Clause

cyber essentials for suppliers contract clauses e three linked rings plinth

Good clauses are short, specific and dated. The failure mode is not aggressive drafting; it is vague drafting that everyone signs happily because nobody could say what it required, and that is how most Cyber Essentials for suppliers wording ends up unusable. Four elements make Cyber Essentials for suppliers enforceable: the obligation, the scope, the date it bites, and the evidence that proves it.

State the obligation as a continuing one

“Shall obtain” is a one-off. “Shall hold and maintain throughout the Term” is a continuing obligation that is breached the moment certification lapses. That single change converts a historical fact into something you can act on, and it costs nothing in negotiation because no reasonable supplier objects to maintaining what they claimed to have.

Define the scope in the clause itself

Name what must be covered: the systems, sites, personnel and cloud services used to deliver the services under this agreement. Without that, a supplier can satisfy the wording with a certificate scoped to a single office that has nothing to do with you. Scope is where Cyber Essentials for suppliers either works or becomes theatre.

Fix the date it applies from

For new suppliers, the commencement date. For incumbents being brought onto new terms, a transition date three to six months out, stated explicitly rather than left to “as soon as reasonably practicable”. A dated obligation is a diary entry; an undated one is a hope.

Model clause — certification obligation
The Supplier shall, from the Commencement Date and throughout the Term, hold and maintain valid [Cyber Essentials / Cyber Essentials Plus] certification issued by a certification body accredited under the scheme, the scope of which shall cover all systems, networks, cloud services, devices and personnel used by the Supplier in the provision of the Services. The Supplier shall provide the certificate number, certifying body, scope statement and expiry date to the Customer within five Business Days of the Commencement Date and within five Business Days of each renewal.

Put it in a security schedule, not the boilerplate

Cyber Essentials for suppliers sits alongside access control, incident notification, subprocessor terms and data handling. Grouping them in one schedule makes the whole package reviewable, lets you version it as the scheme changes, and means a supplier negotiating one point does not reopen the master agreement. It also stops the requirement being lost in a clause about insurance, which is where it usually ends up.

Handle scheme change up front

Question sets are refreshed periodically and requirement versions change. Say what happens: the supplier maintains certification under the then-current requirements of the scheme, and if the scheme is withdrawn or materially replaced, the parties agree an equivalent successor in good faith. Two sentences now avoids an argument in year three.

Proving Cyber Essentials for Suppliers: Evidence and Verification

cyber essentials for suppliers contract clauses f hourglass plinth

An obligation nobody checks is an obligation nobody keeps. The evidence provisions are where Cyber Essentials for suppliers stops being a drafting exercise and starts being an operational one, and they need to be light enough that you will actually run them.

Ask for the certificate number, not a PDF

A PDF is easy to send and easy to misread. The certificate number, the certifying body and the expiry date let you verify independently, which is the whole point of asking for Cyber Essentials for suppliers in the first place. Make those three fields the contractual deliverable and treat the PDF as a convenience rather than the evidence itself.

Verify against the register, not the email

Certified organisations appear in a searchable directory maintained by IASME as the scheme’s delivery partner, and checking a certificate against it takes under a minute. Do it at onboarding and at each renewal. A surprising proportion of certificates circulated in procurement packs are expired, scoped elsewhere, or belong to a related company that is not your counterparty.

Read the scope statement, every time

The scope line is the most informative sentence on the certificate and the one nobody reads. Look for whole-organisation coverage, or a sub-scope that plainly includes the delivery team, the platform and the cloud tenancy serving you. If the scope names a subsidiary you have never heard of, ask before signing rather than after an incident.

Record expiry where somebody will see it

Lapses in Cyber Essentials for suppliers are a calendar problem, not a security problem. Put the expiry date in the contract register with an owner and a reminder at ninety and thirty days, alongside your other IT governance dates. Organisations that track renewals centrally almost never have a lapse dispute; organisations that rely on the supplier remembering have one most years.

Decide in advance what a mismatch means

If the scope does not cover your service, the certificate is not evidence of compliance with the clause even though it is genuine. Agree the response before it happens: a scope extension at the next assessment, a documented interim control, or a tier downgrade with reduced access. Improvising this under time pressure is how buyers end up accepting evidence they know is wrong.

Flow-Down: Reaching the Subcontractors You Never Signed With

Your contract binds your counterparty and nobody else. If the supplier subcontracts the work, hosts on a third-party platform or uses an offshore development partner, Cyber Essentials for suppliers stops at the first hop unless you write it further down the chain.

Require equivalent obligations downstream

The standard mechanism is a flow-down: the supplier must impose materially equivalent obligations, including Cyber Essentials for suppliers at the same tier, on any subcontractor performing a material part of the services or accessing your data, and remains fully liable for their performance. That last part matters most. Without it, a supplier can point downstream when something fails.

Keep flow-down proportionate

Applying the top tier to every subcontractor makes the clause unworkable and invites a blanket refusal. Limit Cyber Essentials for suppliers at the second hop to those who process your data, access your systems, or perform a material part of the services. A courier delivering hardware is not in scope; the hosting provider running your application plainly is.

Take approval rights over new subcontractors

Cyber Essentials for suppliers is only meaningful if you know who the parties actually are. Require notice of new subcontractors touching your data, with a right to object on reasonable security grounds. This mirrors the subprocessor mechanics you already need under UK data protection law, so it is rarely contentious with a supplier who has data protection terms in place.

Do not let flow-down substitute for direct assurance

A supplier confirming that “all our subcontractors meet our security standards” is a statement, not evidence. For Tier 1 suppliers, ask for the list and the certificate details of the material ones. For everyone else, the flow-down obligation plus liability is a reasonable place to stop. The NCSC’s supply chain security guidance is a sensible reference point for how far to push.

Keeping Cyber Essentials for Suppliers Current: Renewal and Lapse

Certificates last twelve months and contracts last three to five years, so every agreement will see three or four renewal cycles. Most disputes about Cyber Essentials for suppliers are not about whether the supplier is secure; they are about a certificate that expired six weeks ago and a clause that never said what to do about it.

Twelve months is shorter than your contract

Write the renewal into the obligation rather than assuming it. “Hold and maintain” carries it implicitly, but an explicit sentence requiring evidence within five business days of each renewal converts an implication into a diary entry that both sides can plan around. This is the cheapest sentence in any Cyber Essentials for suppliers schedule. Suppliers generally prefer this, because it tells them exactly what is expected and when.

Require notification of lapse or failure

The supplier should notify you promptly — five business days is a common figure — if certification lapses, is withdrawn, if an assessment is failed, or if the scope changes in a way that affects your services. This is the clause that turns an invisible problem into a manageable one, and it is the clause suppliers most often try to soften into “shall use reasonable endeavours to inform”.

Give a workable grace period

A short remediation window, typically thirty to sixty days with a written plan, is more effective than an immediate breach declaration you will never invoke. Certification bodies have queues, assessments get rescheduled, and a supplier working through a genuine reassessment is not the risk your Cyber Essentials for suppliers clause was written for. Grace periods should be defined, finite and non-recurring.

Treat scope change as a notifiable event

A supplier who migrates from on-premises to cloud, opens a delivery centre overseas, or is acquired has changed the thing you assessed. Scope change is the least-drafted and most consequential trigger in Cyber Essentials for suppliers, and adding it to the notification list costs one line.

Remedies That Give the Clause Teeth Without Ending the Relationship

Every remedy you write should be one you would actually use. Termination rights that nobody would exercise against a sole-source supplier are decorative, and both parties know it, which quietly devalues the whole schedule. A graduated ladder is what makes Cyber Essentials for suppliers credible rather than theatrical.

Start with a rectification plan

The first rung is a written plan with dates: what the supplier will do, by when, and what interim controls apply meanwhile. This resolves the overwhelming majority of Cyber Essentials for suppliers failures and preserves the relationship. It also creates the paper trail that makes any later escalation defensible.

Escalate to access restriction

If the plan slips, restrict what the supplier can reach: suspend remote access, revoke standing administrative credentials, move to supervised sessions, or pause new data transfers. This is proportionate, immediately protective, and materially uncomfortable for the supplier without being commercially fatal. It is also the rung most contracts forget to include.

Use withholding sparingly and specifically

Withholding a defined percentage of charges against a defined milestone works. Withholding “payment” in general invites a dispute about set-off and gets negotiated out. If you want financial pressure, tie it to the rectification plan’s dates and cap it.

Reserve termination for persistent failure

Termination for a single expired certificate is disproportionate and unlikely to survive negotiation. Termination for failure to remedy within the grace period, or for repeated lapses within a rolling twelve months, is both reasonable and enforceable, and it is the only rung of Cyber Essentials for suppliers that a supplier will genuinely price into their behaviour. Pair it with the exit assistance provisions from your contract checklist so that leaving is actually possible.

SituationProportionate responseTypical windowEscalate if
Renewal running late, assessment bookedWritten plan, no other action30 daysDate slips twice
Certificate lapsed, no plan offeredFormal notice plus rectification plan30 daysNo plan within 10 days
Assessment failedInterim controls plus access review60 daysFailure repeats
Scope no longer covers your servicesScope extension commitmentNext assessmentRefusal to extend
Lapse concealed until discoveredAccess restriction plus noticeImmediateSecond concealment
Repeated lapses in 12 monthsTermination right engagedContractual noticen/a
Subcontractor uncertifiedSupplier remedies or replaces60 daysNo replacement offered
Refusal to certify at allRetender or accept documented riskAt renewaln/a

Cost, Timescales and Pushback on Cyber Essentials for Suppliers

Suppliers push back for four reasons: cost, time, precedent and pride. Knowing the real numbers lets you answer the first two immediately, which usually dissolves the other two. Requiring Cyber Essentials for suppliers is not an expensive ask by the standards of anything else in a commercial negotiation.

What certification actually costs

Self-assessment certification is priced in tiers by organisation size and, for a micro or small business, sits in the low hundreds of pounds. Cyber Essentials Plus costs materially more because it involves an assessor’s time, and quotes vary widely with the number of sites, devices and cloud services in scope. Published pricing changes periodically, so point suppliers at the scheme rather than quoting a figure in your clause.

The real cost is remediation, not the certificate

Suppliers who fail first time usually fail on unsupported software, missing multi-factor authentication on cloud administrator accounts, or patching that runs slower than the required window. Fixing those is the genuine expense of Cyber Essentials for suppliers, and it is also the entire benefit. A supplier who tells you certification is expensive is often telling you their current security posture has a gap in it.

How long it takes

A prepared small organisation can complete self-assessment in two to four weeks. One that needs remediation should plan for eight to twelve. Cyber Essentials Plus adds scheduling time for the assessor and a testing window. Three to six months is a realistic transition period for Cyber Essentials for suppliers; thirty days is not, and demanding it just produces a refusal.

“We are already ISO 27001 certified”

Sometimes valid, sometimes not. ISO 27001 certifies a management system and its scope may or may not include the specific technical controls at the specific standard the scheme requires. Ask for the scope statement and the Statement of Applicability, then decide. An equivalence provision written in advance saves this conversation happening under deadline.

Who pays

The supplier pays, in almost every case — Cyber Essentials for suppliers is a cost of doing business, it benefits their whole client base, and buyers who offer to pay find the offer becomes an expectation. The exception worth making is a sole-source micro supplier you genuinely cannot replace, where funding the certificate is cheaper than the alternative.

Where a first-time supplier’s certification effort goes (indicative model for a 25-person services business)
Remediation of existing gaps 46%
Asset and cloud service inventory 21%
Completing the question set 16%
Internal review and sign-off 11%
Certification body fee and submission 6%

Rolling Cyber Essentials for Suppliers Across an Existing Supply Base

Writing the clause for new contracts is the easy half. Retrofitting Cyber Essentials for suppliers onto a supply base of two hundred incumbents, most of whom are on evergreen terms nobody has opened since 2019, is the part that needs a plan.

Start with the contracts you are renewing anyway

Every renewal, extension and variation is a free opportunity to introduce the security schedule. Attach it as a matter of course and Cyber Essentials for suppliers propagates across the population over a normal contract cycle at almost no negotiation cost. Suppliers accept new terms at renewal that they would resist mid-term on principle alone.

Segment before you write to anybody

Send the same letter to two hundred suppliers and you will spend six months answering questions from the hundred who never needed Cyber Essentials for suppliers at all. Apply the tiering first, then contact Tier 1 and Tier 2 only. A programme that touches forty suppliers finishes; one that touches two hundred stalls.

Give a transition window and mean it

Three to six months, stated in writing, with a named contact for questions. Suppliers who are already certified reply within a week. Suppliers who are not will tell you whether they intend to be, which is itself the most useful piece of supply chain intelligence the exercise produces.

Track it where the contract lives

Certificate number, level, scope summary, expiry and owner belong in the contract register beside the renewal date, not in a separate security spreadsheet that diverges within a quarter. Organisations with mature outsourcing strategies treat Cyber Essentials for suppliers as contract data, because the register is the only place anyone reliably looks.

Expect a small number of genuine refusals

Some suppliers will decline, and a few of those will be right to — a specialist with no access to your systems and no personal data has a fair argument. Document the decision, record the accepted risk, and move on. A programme that cannot say no to itself will not be trusted to say yes.

How a 200-supplier rollout typically resolves after a six-month window (indicative model)
Out of scope after tiering 58%
Already certified, evidence verified 19%
Certified within the transition window 14%
Still in progress at six months 6%
Refused, risk documented or replaced 3%

Mistakes That Make a Cyber Essentials for Suppliers Clause Unenforceable

Most weak clauses are not badly intentioned. They are the residue of a negotiation in which each individual softening looked reasonable and the combined effect removed every mechanism that would have made Cyber Essentials for suppliers real.

“Where applicable” and “where appropriate”

These two phrases void more security obligations than any other drafting in commercial contracts. Applicable according to whom, judged when? If the requirement genuinely depends on circumstances, define the circumstances. If it does not, delete the qualifier.

No evidence obligation at all

A clause requiring Cyber Essentials for suppliers without requiring proof is unverifiable by construction. You will not discover a lapse, because nothing in the contract creates a moment at which anyone looks. Evidence provisions are the cheapest part of the schedule and the one most often cut for brevity.

Silence on scope

Discussed above and worth repeating, because it is the single most common defect. A certificate scoped to somewhere else satisfies an unscoped clause perfectly. This is not a supplier acting in bad faith; it is a buyer having asked the wrong question.

Demanding the audited level from everyone

An unaffordable requirement applied indiscriminately gets negotiated out entirely, and you end up with less than a proportionate ask would have achieved. Tiering is not a concession — it is what makes the demanding tier survive.

Writing it once and never looking again

The final mistake is operational rather than legal. Perfect Cyber Essentials for suppliers wording with no renewal tracking behaves exactly like no clause at all, and it is worse in one respect: it produces a confident but false belief that the supply base is covered. Diary the expiry dates on the day you sign.

Copying a public sector clause without the context

Central government has required certification in defined circumstances for years through mechanisms such as Procurement Policy Note 09/14, and defence supply chains layer further requirements on top. Those clauses come with an assurance apparatus most private buyers do not have. Borrow the structure, not the enforcement assumptions, and check what the current policy framework says before citing a note by number — they are periodically renumbered and replaced.

Frequently Asked Questions

Can we require Cyber Essentials from a supplier mid-contract?

Only if the contract already provides for it, through a change control mechanism or a security schedule that can be updated. Otherwise the practical route is to ask, offer a transition window, and make it a condition of the next renewal or extension. Introducing Cyber Essentials for suppliers at renewal is far easier than imposing it mid-term.

What if a supplier’s certificate covers only part of their business?

Then it may not evidence compliance with your clause, even though it is a genuine certificate. Read the scope statement, establish whether it covers the team, systems and cloud services delivering your work, and if it does not, agree a scope extension at the next assessment with documented interim controls in the meantime. Scope is the most common reason Cyber Essentials for suppliers fails to deliver what the buyer assumed.

Is Cyber Essentials enough on its own for a critical supplier?

No. Cyber Essentials for suppliers covers five technical controls and nothing else — no incident response, no business continuity, no secure development, no staff vetting. For critical suppliers, treat it as the entry requirement and add the specific terms your risk assessment calls for. The Cyber Security and Resilience Bill is one reason to expect that baseline to keep rising.

Should we pay for a small supplier’s certification?

Generally no, but occasionally yes. For a sole-source micro supplier you cannot replace, funding a few hundred pounds of certification is cheaper than either the risk or a retender. Make it a one-off, document why, and do not let it become a precedent across the supply base.

How do we check a certificate is real?

Use the certificate number and the certifying body to verify against the scheme’s published directory rather than relying on the PDF you were emailed. Check the organisation name matches your actual contracting party, not a parent or sister company, and check the expiry date against today rather than against the date the document was issued. Verifying Cyber Essentials for suppliers this way takes under a minute per certificate.

What level should we require by default?

Standard certification as the baseline for any supplier processing personal data or holding systems access, and the audited Plus level for suppliers with privileged access, bulk personal data, or the ability to change your production environment. Everything below that baseline needs no Cyber Essentials for suppliers requirement at all, and saying so explicitly is what makes the rest of the policy credible.

References