Cyber Essentials for hotels has quietly become a commercial document rather than a technical one. It started life as a government scheme to raise the floor on basic controls, and it now turns up in corporate travel tenders, agency accommodation agreements, conference contracts and insurance renewals. The hotel that can produce a current certificate answers the question in one line. The hotel that cannot spends three weeks writing prose about its firewalls and still loses the account.
The scheme itself is not difficult. What makes Cyber Essentials for hotels awkward is the estate: a property management system somebody else hosts, bar tills nobody patches, a door-lock encoder running an operating system from a previous decade, self-service kiosks in the lobby, a guest network shared with three hundred strangers a night, and a workforce that turns over faster than almost any other sector in Britain.
Those are scoping problems, not security problems, and they are where certification attempts stall. If you have read our guide to Cyber Essentials for property management companies, the shape will be familiar, but a hotel has a payment estate and a guest estate that a lettings business simply does not.
This guide to Cyber Essentials for hotels covers what the scheme certifies, what changed with the Danzell v3.3 requirements in April 2026, how to draw a defensible scope boundary around a hotel, what each of the five controls means at a front desk, what certification actually costs, what a Cyber Essentials Plus assessor tests, who is asking for the certificate, and a ninety-day plan to get it. It assumes you already have IT support for hotels in some form, whether in-house, outsourced or brand-mandated.
Table of contents
- Why Cyber Essentials for Hotels Stopped Being Optional
- What Cyber Essentials Actually Certifies
- What Changed in 2026: Danzell v3.3 and Cyber Essentials for Hotels
- Scoping Cyber Essentials for Hotels: Where the Boundary Falls
- The Hotel Systems That Complicate Cyber Essentials for Hotels
- Guest WiFi, Card Payments and Cyber Essentials for Hotels
- Firewalls and Secure Configuration Across a Property
- Security Update Management on a 14-Day Clock
- User Access Control When Staff Turnover Is High
- Malware Protection From Front Desk to Back Office
- What Cyber Essentials for Hotels Costs in 2026
- Cyber Essentials for Hotels: Moving Up to Cyber Essentials Plus
- Who Actually Asks for Cyber Essentials for Hotels
- Cyber Essentials for Hotels vs PCI DSS and ISO 27001
- A Worked Example: Cyber Essentials for Hotels in a Four-Property Group
- Why Cyber Essentials for Hotels Applications Fail
- A 90-Day Plan to Achieve Cyber Essentials for Hotels
- Cyber Essentials for Hotels: Frequently Asked Questions
- References
Why Cyber Essentials for Hotels Stopped Being Optional
Cyber Essentials for a bakery is a badge. For accommodation providers it has become a filter applied before anyone reads your rate card.
The certificate is now a procurement gate
Public sector buyers set the pattern. Procurement Policy Note 014 came into force on 24 February 2025, replacing PPN 09/14 and PPN 09/23, and it binds central government departments, executive agencies, non-departmental public bodies and NHS bodies. Crucially for this sector, it names travel booking explicitly as a service where a supplier handling the personal information of government employees, ministers and special advisors must meet the technical requirements.
A hotel holding a civil servant’s name, home address, payment details and stay dates sits squarely inside that wording. Evidence is required before contract award and must be renewed annually for the life of the contract. The note also tells buyers not to take a blanket approach and warns them against over-burdening smaller suppliers, which is worth knowing when an ask looks disproportionate. Local authorities and housing associations are not formally in scope, but many apply the same rule anyway.
Corporate travel programmes copied it
Once the public sector normalised the question, corporate travel and procurement teams followed. Hotels bidding for a preferred-supplier agreement now regularly meet a security questionnaire, and Cyber Essentials for hotels is the cheapest possible answer to most of it. That is the practical case for Cyber Essentials for hotels: not that it prevents every attack, but that it converts a fortnight of questionnaire correspondence into a single verifiable line.
The national numbers explain the leverage
The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found 43% of UK businesses had experienced a breach or attack in the preceding twelve months. Exposure climbs with size: 46% of small businesses, 65% of medium and 69% of large.
Only 25% have a formal incident response plan and only 31% have a board member with named responsibility for cyber security. Certification sits at 5% of businesses overall, 12% of small businesses and 35% of large ones, while awareness of the scheme reaches only 17%. That gap is why Cyber Essentials for hotels still reads as a differentiator rather than a baseline.
Insurers ask a version of the same question
Cyber insurance proposal forms have converged on the same five controls: perimeter firewalls, secure configuration, patching, access control and malware protection. A property that can evidence all five through Cyber Essentials for hotels usually gets a faster underwriting decision. Certifying through an IASME-licensed body also carries £25,000 of cyber liability cover for UK businesses turning over under £20 million. That is not a promise about premium reductions, but it removes a category of back-and-forth.
What Cyber Essentials for hotels is really insuring against
The sector’s worst case is already on the record. The ICO fined Marriott International £18.4 million on 30 October 2020 over an attack on Starwood Hotels and Resorts that began in 2014 and went undetected until September 2018, exposing roughly 339 million guest records worldwide, around 30 million in the EEA and 7 million in the UK. The original notice of intent had been £99.2 million. Nothing in the scheme would have guaranteed prevention, but every control it tests is one the ICO went on to examine.
What Cyber Essentials Actually Certifies
Before scoping anything, it helps to be precise about what Cyber Essentials for hotels does and does not certify. Overstating it in a tender response is how hotels end up making claims they cannot support.
Five technical controls, nothing more
The scheme covers firewalls and internet gateways, secure configuration, security update management, user access control and malware protection. That is the whole thing. It does not cover physical security, staff vetting, contractual terms, business continuity or the way you handle a guest complaint about their data.
Self-assessment versus independent testing
Basic certification is a self-assessment questionnaire, answered by someone who can genuinely speak for the estate and signed off at board level, then marked by a certification body. Cyber Essentials Plus keeps the identical technical requirements and adds an independent hands-on audit. The requirements do not get harder at Plus level; the evidence does.
Backups still are not a control
Backups are discussed in the requirements and repositioned in the latest version, but they remain outside the five controls. A hotel can hold a valid Cyber Essentials for hotels certificate with a backup regime that would not survive a ransomware event. Treat certification as a floor, not a strategy.
What Cyber Essentials for hotels deliberately excludes
The scheme also says nothing about your suppliers’ own security, which matters because so much of a hotel estate is somebody else’s software. Verizon’s 2026 Data Breach Investigations Report put third-party involvement at 48% of breaches. Cyber Essentials for hotels covers your own estate and does not touch that, which is why supplier questions belong alongside it, as we set out in Cyber Essentials for suppliers.
| Control | What the assessor asks | Where it bites in a hotel |
|---|---|---|
| Firewalls and internet gateways | No unauthenticated management from the internet, default passwords changed, inbound rules justified | Installer-configured wireless gateways and remote-support rules nobody documented |
| Secure configuration | Unused accounts and software removed, auto-run disabled, device unlock controls in place | Shared front-desk logins and kiosk builds shipped by a vendor |
| Security update management | Supported software only, critical and high updates inside 14 days | EPOS terminals, door-lock encoders and back-office machines on vendor release cycles |
| User access control | Named accounts, approval process, prompt removal, MFA on cloud services | Seasonal staff, agency cover and a shared reception account |
| Malware protection | Anti-malware, allow-listing or sandboxing on every in-scope device | Appliance-like devices where no agent can be installed |
What Changed in 2026: Danzell v3.3 and Cyber Essentials for Hotels
The requirements behind Cyber Essentials for hotels moved on 26 April 2026. If your last certificate predates that, the questionnaire you remember is not the questionnaire you will meet.
The version and the dates
IASME published the version 3.3 question set, named Danzell, on 13 February 2026, replacing version 3.2 Willow, and the requirements document itself carries an April 2026 date. It applies to assessment accounts created from late April 2026. IASME has published both 26 and 27 April as the effective date in different articles, so treat the end of that month as the switchover rather than quoting a single day. Accounts created before it were given six months to finish under the old requirements.
Three answers now fail outright
Three requirements are treated as automatic failures rather than recoverable non-compliances. Multi-factor authentication must be applied to cloud services wherever the service supports it, including where the capability sits behind a higher licence tier. Operating systems and router or firewall firmware must receive critical and high severity updates within 14 days, and so must applications, files and extensions. There is no partial credit on any of the three, and each one ends an attempt at Cyber Essentials for hotels on the spot.
Cloud services cannot be carved out
The requirements now define cloud services formally and state plainly that they cannot be excluded from scope. For a hotel that is the single most consequential change, because the property management system, the channel manager, the booking engine, the payroll platform and the EPOS back office are usually all cloud services operated by third parties. Cyber Essentials for hotels therefore now reaches into systems the property does not host.
The BWH Hotels breach shows why that matters. Attackers held access to a reservation web application from 14 October 2025 until 22 April 2026, roughly six months, exposing guest names, email addresses, phone numbers and reservation details across a group operating more than 4,000 hotels worldwide. Payment data was not stored in that system. It was a cloud reservation application, which is exactly the class of system the requirements now say you cannot leave out.
Smaller changes that still matter
FIDO2 security keys are explicitly recognised as multi-factor authentication. Legal entities must be identified by name, registered address and company number, with per-entity certificates available for a small additional fee, which matters for groups holding properties in separate companies. Any excluded area must be specifically described and justified, and “point in time” is defined as the certificate issue date. The old “web applications” terminology becomes “application development”, now referencing the UK Government Software Security Code of Practice.
| Change in v3.3 Danzell | Previously | Effect on a hotel |
|---|---|---|
| MFA on cloud services is an auto-fail | Major non-compliance | A PMS or channel manager without MFA ends the assessment |
| 14-day patching of OS and firmware is an auto-fail | Major non-compliance | Unmanaged EPOS and kiosk builds become the critical path |
| 14-day patching of applications, files and extensions is an auto-fail | Major non-compliance | Browser extensions on back-office PCs need an owner |
| Cloud services cannot be excluded | Ambiguous in practice | Third-party hosted hotel systems are in scope by default |
| Exclusions must be described and justified | Loosely worded | “Guest network excluded” is no longer a sufficient sentence |
| FIDO2 recognised as MFA | Not named | Security keys are a valid answer for shared terminals |
Scoping Cyber Essentials for Hotels: Where the Boundary Falls
Cyber Essentials for a single independent property and certification across a branded group are the same questionnaire answered about very different estates. Scope for Cyber Essentials for hotels is decided before anything technical happens, and a bad boundary is the most expensive mistake available.
Whole organisation or a defined sub-set
You may certify the whole organisation or a clearly defined sub-set. Whole-organisation scope is simpler to explain to a corporate buyer and harder to achieve. The requirements define a sub-set as part of the organisation whose network is segregated from the rest by a firewall or a VLAN. The scope boundary has to name the business unit managing it, the network boundary and the physical location, and it must be agreed with your certification body before assessment begins. One rule closes off the obvious shortcut: a scope that does not include end-user devices is not acceptable.
The temptation to exclude the messy parts
Every hotel is tempted to scope out the kiosks, the tills and the guest network. Under the current requirements each exclusion must be specifically described and justified, and it has to be genuinely segregated rather than simply inconvenient. An exclusion that survives the questionnaire may still fail the commercial test when a client reads the certificate and asks what was left out.
Where the group structure bites
Many UK hotel groups hold each property in a separate limited company for perfectly ordinary reasons. Because legal entities must now be identified by company number, a group that wants one certificate covering everything has to be honest about which entities that certificate names. Per-entity certificates are available for a small extra fee, and for Cyber Essentials for hotels in a multi-company group that is usually the cleaner answer.
Franchise and brand-managed complications
Where a property operates under a franchise agreement, some systems are mandated and supported by the brand and some are the operator’s own. The certificate belongs to the legal entity being assessed, so brand-supplied systems used by that entity’s staff sit inside its scope even when the operator cannot change them. Accounts your organisation owns stay in scope even when a supplier, contractor or managed service provider is the one using them, and you have to be able to demonstrate that the controls are met on anything externally managed. Document who administers what before you answer a single Cyber Essentials for hotels question.
| Hotel system | Default position | What decides it |
|---|---|---|
| Property management system (cloud) | In scope | Cloud services cannot be excluded; MFA is mandatory |
| Front desk and back office PCs | In scope | Staff devices accessing organisational data |
| EPOS terminals in bar and restaurant | In scope | Connect to the internet and to organisational systems |
| Self check-in kiosks | In scope | Internet-connected devices under your administration |
| Door-lock encoder and server | In scope unless segregated | Whether it is firewalled off and justified in writing |
| Guest WiFi network | Excludable if truly segregated | Segregation you can demonstrate, plus a written justification |
| Guest devices on that network | Out of scope | Not owned or administered by the organisation |
| CCTV, BMS and lift telemetry | Depends | Internet connectivity and who administers the platform |
The Hotel Systems That Complicate Cyber Essentials for Hotels
The five controls are simple. Applying them to hospitality hardware is where Cyber Essentials for hotels actually gets difficult, and it is worth naming the specific offenders before you start.
Property management systems
The PMS holds guest names, addresses, stay history, sometimes passport data and often stored card tokens. Modern deployments are cloud-hosted, so under the current requirements they are in scope automatically and multi-factor authentication is not negotiable. Older on-premise deployments raise a harder question: is the underlying operating system still supported by its vendor?
Read the shared-responsibility split before you call the vendor. For software as a service the provider handles firewalls, security update management and malware protection, secure configuration is shared, and user access control is always your organisation’s job. You are also expected to confirm the provider’s commitments through the contract or documents the contract references.
Point of sale and payment terminals
Bar and restaurant tills are frequently supplied, configured and maintained by a hospitality EPOS vendor on a release cadence that has nothing to do with a 14-day clock. They are internet-connected and used by staff, so they are in scope. The realistic answer is usually a contractual conversation with the vendor rather than a technical one, and it is the most common blocker for Cyber Essentials for hotels.
Electronic door locks and encoders
Almost every property has a workstation that programmes room key cards. It is often ancient, rarely patched, sometimes running an operating system past its support date, and almost never on the asset register. Unsupported software is a straightforward failure, and it is the single most common surprise we see, as covered in our guide to unsupported software under Cyber Essentials and ISO 27001. The Unsaflok research put the scale of that estate in perspective: more than three million dormakaba Saflok locks across over 13,000 properties in 131 countries, with only around 36% updated by the time the findings were published.
Kiosks, signage and business-centre PCs
Self check-in kiosks, digital signage players and any surviving business-centre computer are internet-connected devices under your administration. If a guest can use it and you own it, an assessor will want to know how it is patched, how it is protected from malware and how it is prevented from reaching your back office.
Everything else with an IP address
Casting devices in bedrooms, spa booking terminals, energy management controllers, CCTV recorders and conference room panels all have network addresses. Not all of them are in scope, but every one of them needs a decision recorded against it. Sound device management is what turns that from an annual panic into a register you already maintain.
Guest WiFi, Card Payments and Cyber Essentials for Hotels
Two questions dominate every Cyber Essentials for hotels scoping conversation, and both have clearer answers than most operators expect.
Guest devices are not yours
Devices owned by guests are not administered by the organisation and are therefore out of scope. That is the easy half. The rule runs the other way just as firmly: a device your organisation owns is in scope even when a customer is the one using it, so a lobby iPad, a surviving business-centre PC or a self check-in kiosk counts, and so does a hotel-owned laptop loaned to a contractor.
The infrastructure that serves those guests is a different matter: the access points, controller and captive portal gateway are your equipment, bought by you and administered on your behalf. Wireless devices are in scope where they can communicate with other devices over the internet, and out of scope only where an attacker would have to be within signal range to reach them.
The guest network can be excluded, but only properly
IASME’s scoping guidance names this sector directly. A segregated guest network that does not interact with other organisational data or services, and simply lets people outside the organisation reach the internet, can be excluded, and the published example is a hotel with a guest network. Note where that concession lives: it is IASME guidance rather than a line in the requirements document, which never mentions hotels at all, so an assessor applies it on the evidence you provide.
“Guests are on a separate SSID” is not segregation. The design that actually holds up is the one we set out in hotel guest WiFi VLAN segmentation, and the wider posture in hotel WiFi security.
Why the gateway still deserves attention
Even where the guest network is excluded, the gateway is a device you own with a management interface. The CaptiveCrunch campaign disclosed in mid-2026 showed exactly what happens when those appliances are reachable from the internet with installer credentials, and we broke down the chain in captive portal attacks on hotel WiFi. An excluded network is not an unmanaged one, and Cyber Essentials for hotels still asks about the equipment you own.
Card payments run on a parallel track
PCI DSS is a separate obligation with its own scope, and Cyber Essentials for hotels does not satisfy it. Version 4.0.1 landed in June 2024 and its 51 future-dated requirements became effective on 31 March 2025, so no grace period is left to lean on. The two overlap usefully: segmentation reduces payment scope, and PCI DSS requires quarterly detection of rogue wireless access points even where wireless is prohibited in the payment environment. Do the segmentation once and let both regimes benefit.
Firewalls and Secure Configuration Across a Property
The first two controls are where Cyber Essentials for hotels usually scores well on paper and badly in practice, because the estate was configured by an installer years ago.
Boundary firewalls at every site
Each property needs a firewall or equivalent boundary device between its network and the internet, with default administrative passwords changed and no unauthenticated management interface reachable from outside. Multi-property groups often discover that one site was built differently because a different contractor did the install, which is exactly the inconsistency Cyber Essentials for hotels exposes.
What a hospitality scan actually finds
Trustwave scanned the sector in April 2025 and reported 95,040 vulnerabilities across hospitality organisations, drawn from 3,884 unique CVEs, of which 14,318 were rated critical and 1,521 appeared on the CISA known-exploited list. It also found that 61.5% of observed initial access attempts targeted publicly exposed services. The most exposed protocol by a wide margin was SNMP, which in a hotel means building management, HVAC, lighting and IP cameras.
Remote support rules nobody remembers
Hospitality estates accumulate inbound rules: the EPOS vendor needed access, the door-lock supplier needed access, the building management contractor needed access. Every one of those needs a documented business justification and an owner. Rules that no longer have either are the fastest scope reduction available.
Secure configuration in a shared environment
Secure configuration means removing unused software and accounts, disabling auto-run, and controlling how devices are unlocked. In a hotel that runs straight into shared front-desk workstations, kiosk images supplied by a vendor and machines that were never rebuilt after the last refurbishment. Consistent IT governance is what keeps a fixed build from drifting between properties.
Wireless infrastructure counts as configuration
Access points and controllers are configurable devices with administrative credentials. Default community strings, unchanged admin passwords and management interfaces on the guest VLAN are all secure configuration failures, whatever the guest network’s scope status. Getting the network design right once removes an entire class of Cyber Essentials for hotels finding.
Security Update Management on a 14-Day Clock
This is the control that fails hotels, and the 2026 requirements made Cyber Essentials for hotels unforgiving about it.
What the rule actually says
Software must be licensed and supported, and updates rated critical or high by the vendor must be applied within 14 days of release. That applies to operating systems, to router and firewall firmware, and to applications, files and extensions. All three are now automatic failures rather than recoverable findings.
Why hospitality estates struggle
A front-office PC is easy. A till behind a bar during a wedding is not. Kiosks reboot at inconvenient times, encoders are treated as appliances, and nobody wants to patch a system that takes payments on a Saturday night. The result is a small number of devices sitting permanently outside the window, which is enough to end an attempt at Cyber Essentials for hotels.
The exploitation trend behind the rule
Verizon’s 2026 Data Breach Investigations Report found exploitation of software flaws had become the leading initial access route at 31%, overtaking stolen credentials. That is precisely the gap a 14-day clock is designed to close, and it explains why the scheme stopped treating late patching as a negotiable finding.
Making Cyber Essentials for hotels survivable
The practical answer for Cyber Essentials for hotels is a maintenance window that management actually protects, automatic updates wherever the vendor supports them, and a written escalation path for any device the window cannot reach. Continuous monitoring turns “we think everything is patched” into a report you can hand an assessor.
User Access Control When Staff Turnover Is High
Hospitality has some of the highest workforce churn in the UK economy, and the access control requirement behind Cyber Essentials for hotels was written as though it does not. A 2025 benchmark covering more than 35,000 hospitality employees put annual staff turnover at 67%, down from 75% the year before. Two thirds of your account list changes in a year.
Named accounts, not shared ones
Every user needs their own account, created through an approval process, with administrative access granted separately and only where justified. A single reception login shared across a shift is the most common failure in the sector and the least defensible one, because it also destroys any hope of knowing who did what.
Leavers are the real risk
Accounts must be removed promptly when someone leaves. In a hotel that means agency cover, seasonal contracts, transfers between properties and staff who left mid-shift six months ago. The starters and leavers process needs to be owned by whoever runs the rota, not only by whoever runs IT, because leaver accounts are the finding that most often delays Cyber Essentials for hotels.
Personal phones are mostly in scope
User-owned devices that access organisational data or services are in scope. The carve-out is narrow: a phone used only for native calls, native texts or an authenticator app stays out, but the moment it opens the rota system, the booking platform or work email it is in. That catches a great many agency and seasonal staff who were never issued a device.
MFA is now non-negotiable
Multi-factor authentication must be applied to cloud services wherever it is available, including where the capability is only offered on a higher licence tier. FIDO2 security keys are explicitly recognised, which is genuinely useful at a shared terminal where phone-based authentication is impractical. This is one of the three automatic failures, so partial rollout is the same as none.
Administrative accounts in a small team
Small properties often give the general manager local administrator rights because it is convenient. Separate the day-to-day account from the administrative one, keep a list of who holds administrative access, and review it when people move. Doing this well is the substance of the wider security posture that Cyber Essentials for hotels is supposed to reflect.
Malware Protection From Front Desk to Back Office
The fifth control is usually the easiest part of Cyber Essentials for hotels to satisfy and the easiest to leave with a hole in it.
Three acceptable approaches
You may use anti-malware software, application allow-listing, or execution in a sandboxed environment. Most hotels will use anti-malware on Windows devices and allow-listing on kiosks, which is a perfectly good answer for Cyber Essentials for hotels provided it is applied consistently rather than to the machines that happened to have it already.
The devices that resist agents
Appliance-like devices are the awkward ones: some EPOS terminals, some kiosks and some encoders will not accept a third-party agent. Where that is the case, allow-listing or a documented segregation argument is the route, and the vendor needs to be part of the conversation.
Phishing is still the entry route
The 2025/2026 survey put phishing at 38% of businesses experiencing it and identified it as the most disruptive breach type for 69% of those affected. Malware protection on the endpoint is the last line, not the first, and Cyber Essentials for hotels only ever tests the last line. Reservations inboxes handling attachments from unknown senders all day are the highest-risk mailboxes in the building.
Testing rather than assuming
At Plus level an assessor will actually send test files. Before certification, confirm that protection is enabled, updating and reporting centrally on every in-scope device, including the ones in locations nobody visits. A quiet failure on a single back-office machine is enough to fail the audit.
What Cyber Essentials for Hotels Costs in 2026
Cost is the question every general manager asks about Cyber Essentials for hotels first, and the published fees are only part of the answer.
The published assessment fees
IASME’s assessment fees are banded by organisation size, excluding VAT: £320 for micro organisations of 1 to 9 people, £440 for small organisations of 10 to 49, £500 for medium organisations of 50 to 249, and £600 for large organisations of 250 or more. The certificate lasts 12 months. Most single properties fall in the small or medium band; a group with several hotels will usually be medium or large.
What Plus adds
Cyber Essentials Plus is priced by the certification body rather than centrally, and typically lands somewhere between roughly £1,400 and £5,000 or more depending on estate size and the number of sites sampled. It must be completed within three months of the underlying certificate.
The costs that are not on the invoice
The real spend for Cyber Essentials for hotels is usually remediation: replacing an unsupported encoder workstation, buying licences that unlock multi-factor authentication, rebuilding a kiosk image, or paying an EPOS vendor to move to a supported release. Budget for those before you book the assessment, not after the questionnaire tells you about them.
Where the money is recovered
A single corporate account won on the back of a clean security answer usually covers the whole exercise. That is the honest commercial case: Cyber Essentials for hotels is cheap relative to a tender you cannot answer, and it is dramatically cheaper than the first day of an incident.
Cyber Essentials for Hotels: Moving Up to Cyber Essentials Plus
Plus is where the paperwork behind Cyber Essentials for hotels meets reality, and the 2026 requirements sharpened the consequences of getting it wrong.
What the assessor actually does
The current test specification is version 3.2, published in April 2025, and it sets five test cases: a remote vulnerability assessment of every IP address in use, an authenticated scan of sampled devices, malware protection tested by email and by browser download, multi-factor authentication tested on all cloud services, and account separation tested on every sampled device.
The patch threshold is explicit. Anything the vendor rates critical or high, or scoring 7 or above on CVSS version 3, with a fix available for more than 14 days, is a fail, and virtual patching is not accepted as a long-term answer for unsupported operating systems. A single fail means the assessment fails.
Sampling across a distributed estate
Sampling is harder in hospitality because the devices are spread across properties, shifts and back-of-house rooms. Shared front-desk machines, kiosks in public areas and tills that cannot be taken offline during service all complicate scheduling. Sample size follows variation rather than headcount: a group running one standard image needs few representative devices, while a group whose front desks were each built by a different contractor over fifteen years needs many. Every cloud service must also be tested with at least one ordinary and one administrative account.
Before any of that, the assessor has to verify by technical means that the scope matches the systems in front of them and that any sub-set segregation genuinely holds. That is the moment a declared guest-network exclusion stops being a sentence and starts being a test. Plan the audit around the operation rather than expecting the operation to pause.
The retest rules changed
A retest now covers the original sample plus a fresh random sample, and a second failure revokes the certificate rather than simply delaying it. Verified self-assessment answers also lock once Plus testing begins, so you cannot quietly correct the questionnaire once the assessor has started.
Do you need Plus at all
Basic Cyber Essentials for hotels answers most corporate travel questionnaires. Plus is worth it when a specific client demands it, when you are bidding for public sector accommodation work, or when you want the assurance for yourself. If you are weighing it against a management system, our comparison of Cyber Essentials Plus and ISO 27001 sets out where each one earns its place.
Who Actually Asks for Cyber Essentials for Hotels
Knowing where demand for Cyber Essentials for hotels comes from tells you when to certify and what to say once you have.
Public sector accommodation buyers
Government departments, agencies and NHS bodies book a great deal of accommodation, and PPN 014 puts travel booking on the list of services where the requirement applies. The live agreement is RM6342 Travel, Transport, Accommodation and Venue Solutions, running to 30 September 2027 and now administered by the Government Commercial Agency, which is what Crown Commercial Service became on 1 April 2026.
Be precise when you quote this to a client: the framework page does not itself mandate certification. The obligation reaches a hotel through PPN 014 and through the travel management company’s own supplier terms.
NHS buyers often want Plus
NHS Supply Chain expects suppliers handling its personal data to demonstrate Cyber Essentials Plus, accepting basic certification only where the supplier can provide evidence that replaces an external audit requirement. If your group takes NHS accommodation business, assume the higher bar and plan Cyber Essentials for hotels with Plus in view from the start.
Corporate travel programmes and TMCs
Companies with negotiated rate programmes increasingly route hotels through a supplier security review. The questions are rarely sophisticated; they are usually a checklist that maps neatly onto the five controls. Cyber Essentials for hotels answers most of it before the conversation starts. The direction of travel is clear enough: the NCSC published a Cyber Essentials Supply Chain Playbook in December 2025 telling large buyers to require certification of their suppliers rather than merely encourage it, alongside a tool that bulk-checks supplier certification status.
Conference, event and group bookings
Event clients handing over delegate lists are handing over personal data, and their own compliance teams have started asking how it will be held. A certificate plus a clear statement of what is in scope resolves that quickly.
Brands, insurers and lenders
Franchisors set technology standards, insurers ask about the same controls, and lenders financing a refurbishment increasingly ask about operational resilience. None of these strictly require Cyber Essentials for hotels, but all of them are easier conversations with a certificate in hand. Systematic vendor management is the other half of that answer.
| Who asks | What they want | What satisfies them |
|---|---|---|
| Central government and NHS buyers | Stated requirement in the tender notice | Current certificate, or an accepted equivalent |
| Corporate travel programmes | Supplier security questionnaire | Certificate plus a one-page scope statement |
| Conference and event clients | Assurance over delegate data | Certificate, retention policy, named contact |
| Cyber insurers | Evidence of basic controls | Certificate plus MFA and patching evidence |
| Franchisors and brands | Compliance with brand IT standards | Certificate mapped to the brand checklist |
Cyber Essentials for Hotels vs PCI DSS and ISO 27001
Operators are frequently asked about all three in the same week and treat them as rivals to Cyber Essentials for hotels. They are not.
Different questions entirely
Cyber Essentials asks whether five technical controls are in place across a defined estate. PCI DSS asks how you protect cardholder data specifically. ISO 27001 asks whether you run a management system that identifies and treats information risk over time. One is a floor, one is payment-specific, one is a discipline.
Where they overlap usefully
Network segmentation reduces PCI scope and supports a clean Cyber Essentials boundary at the same time. Patching and access control evidence serves all three. An asset register built for certification is the same register an ISO 27001 auditor will ask for, which is why our ISO 27001 readiness assessment starts in the same place.
Sequencing them sensibly
For most independent hotels and small groups the order is straightforward: complete Cyber Essentials for hotels first, keep PCI DSS obligations current with your acquirer, and consider ISO 27001 only if a major client or a lender genuinely requires it. Doing them in that order means each stage reuses the previous stage’s evidence.
| Dimension | Cyber Essentials | Cyber Essentials Plus | PCI DSS | ISO 27001 |
|---|---|---|---|---|
| What it covers | Five technical controls | Same, independently tested | Cardholder data environment | Whole management system |
| Evidence | Self-assessment, marked | Hands-on audit and sampling | SAQ or QSA assessment | External certification audit |
| Typical cost | £320 to £600 plus VAT | Roughly £1,400 to £5,000+ | Varies by acquirer and channel | Substantially higher |
| Renewal | Annual | Annual, within 3 months of base | Annual validation | 3-year cycle with surveillance |
| Best used for | Tenders and questionnaires | Clients who demand testing | Card acceptance obligations | Enterprise and lender assurance |
A Worked Example: Cyber Essentials for Hotels in a Four-Property Group
Abstract requirements are easy to nod along to. Here is what the scope for Cyber Essentials for hotels actually looks like in a modest UK group, using round numbers you can substitute your own figures into.
The estate
Four properties of 120, 90, 75 and 60 bedrooms, so 345 bedrooms in total, plus a small head office. Employment across the group is roughly 45 people per property and 12 at head office, which is 4 × 45 + 12 = 192 people. That places the group in the medium band of 50 to 249, so the assessment fee is £500 excluding VAT.
Counting the devices
Per property there are 4 front-desk PCs, 6 back-office PCs, 5 EPOS terminals, 2 self check-in kiosks, 1 door-lock encoder workstation and 3 duty-manager mobile devices. Across four properties that is 16, 24, 20, 8, 4 and 12 respectively, and head office adds 14 laptops. The total in-scope device count is 16 + 24 + 20 + 8 + 4 + 12 + 14 = 98.
Where the effort concentrates
Of those 98 devices, the 24 back-office PCs and 16 front-desk PCs are ordinary managed Windows machines. The 20 EPOS terminals, 8 kiosks and 4 encoders — 32 devices, just under a third of the estate — are the ones a hotel does not fully control, and they will consume most of the remediation effort.
The cloud side of the same scope
The group also runs seven cloud services: Microsoft 365, the PMS, a channel manager, the booking engine, payroll, the EPOS back office and a cloud CCTV platform. Every one of them needs multi-factor authentication enabled, because cloud services cannot be excluded and MFA is an automatic failure. Seven services and 98 devices is the entire Cyber Essentials for hotels scope statement, and it fits on one page.
What this group should expect to spend
The £500 assessment fee is trivial next to the remediation. Realistically this group replaces one or two encoder workstations, buys licences that unlock MFA on at least one platform, and negotiates a supported release with its EPOS vendor. A single managed IT services arrangement covering all four properties usually costs less than running four different local arrangements badly.
Why Cyber Essentials for Hotels Applications Fail
Failures cluster around a small number of causes, and every one of them is discoverable before you submit.
Unsupported software nobody owned
An encoder, a back-office machine or a kiosk running software past its vendor support date is a straightforward failure. Find it during the asset inventory, not during the assessment. This is the single most common cause across every sector, and hospitality has more hidden candidates than most.
Partial multi-factor authentication
MFA on Microsoft 365 but not on the PMS is a fail, because the requirement applies to every cloud service that supports it. Licence-tier excuses were closed off explicitly in the current requirements. List every cloud service first, then check each one against the Cyber Essentials for hotels requirement.
Scope written to be convenient
An exclusion that is not genuinely segregated, or is described in one vague sentence, invites rejection. Write the boundary as though a sceptical assessor will read it, because one will. The other failure patterns are catalogued in our guide to Cyber Essentials failure reasons.
Answering from memory
The questionnaire is answered by a person who signs for the whole organisation. Answers based on what the estate looked like two years ago fail at Plus and mislead clients in the meantime. Verify each answer against something you can show, whether that is a management console export or a photograph of a device screen.
No owner after certification
A Cyber Essentials for hotels certificate is a point-in-time statement, defined as the certificate issue date, and it lasts twelve months. Without a named owner, the estate drifts and the next renewal becomes a fresh project. Good cybersecurity practice in hospitality is a maintained register plus a monthly review, not an annual scramble.
A 90-Day Plan to Achieve Cyber Essentials for Hotels
This plan takes a property from nothing to Cyber Essentials for hotels in one quarter. It assumes one competent supplier, no new capital budget and a few hours of management attention each week.
Days 1 to 21: inventory and scope
List every device with an IP address across every property, every cloud service in use including the ones marketing signed up for, and every user account. Decide the scope boundary and write it down. Confirm which legal entities the certificate must name, with company numbers.
Days 22 to 45: close the automatic failures
Enable multi-factor authentication on every cloud service that supports it, including behind licence tiers. Establish a patching regime that meets the 14-day rule for operating systems, firmware and applications, and identify the devices that cannot meet it. These three items are the ones that end assessments outright.
Days 46 to 70: fix the awkward estate
Deal with unsupported software, agree a supported release path with the EPOS and door-lock vendors, rebuild kiosk images with allow-listing, remove stale accounts and eliminate shared logins at reception. Where segregation is part of your scope argument, prove it with a test rather than a diagram.
Days 71 to 90: assess and evidence
Complete the self-assessment with evidence beside each answer, submit, and remediate anything the marker raises. Then write the one-page scope statement that goes to clients alongside the certificate. Properties without in-house expertise can lean on a local IT support team in Chester to run the fortnightly milestones.
Keeping it after you have it
Add the Cyber Essentials for hotels renewal to the same calendar as your fire and food safety obligations, review administrative accounts quarterly, and keep the asset register current as devices are replaced during refurbishment. Pair it with a tested incident response plan, because certification tells a client what you prevent, not what you do when prevention fails.
Cyber Essentials for Hotels: Frequently Asked Questions
Does the guest WiFi have to be in scope?
Not necessarily. Guest devices are never in scope for Cyber Essentials for hotels because you do not administer them, and the guest network itself can be excluded where it is genuinely segregated from organisational systems and the exclusion is specifically described and justified. The infrastructure you own still needs secure configuration regardless.
Can a hotel group certify all its properties on one certificate?
Yes, if they sit within the scope you define and the legal entity position is clear. Because entities must now be named with their company number, groups holding each property in a separate company often find per-entity certificates cleaner, and those are available for a small additional fee.
Is Cyber Essentials enough for PCI DSS?
No. They are separate regimes with separate scopes. Cyber Essentials for hotels demonstrates five basic technical controls; PCI DSS governs how cardholder data is protected. The overlap is real but partial, and segmentation work benefits both.
What happens if our door-lock system runs unsupported software?
It fails the security update management control if it is in scope. The requirements give three routes: upgrade it, remove the unsupported software from the device, or place it in a defined sub-set that prevents all traffic to and from the internet. That third route is legitimate but it means genuinely cutting the device off, not simply labelling it as excluded.
How long does certification take for a single hotel?
For a well-run single property with managed devices and MFA already enabled, a few weeks. For a property discovering its estate for the first time, ninety days is realistic. The variable is remediation, not the questionnaire.
Do we need Cyber Essentials Plus to win corporate accounts?
Usually not. Basic Cyber Essentials for hotels answers most corporate travel and event questionnaires. Plus becomes relevant when a specific client demands independent testing or when you are bidding for public sector accommodation contracts where the buyer has set that bar.
References
Cyber Essentials: Requirements for IT Infrastructure v3.3
Cyber Essentials Plus Test Specification v3.2
NCSC: Cyber Essentials Supply Chain Playbook
Procurement Policy Note 014: Cyber Essentials Scheme
IASME: Important Update, Changes to Cyber Essentials for April 2026
IASME: Cyber Essentials and Cyber Essentials Plus, What Is the Difference?
Cyber Security Breaches Survey 2025/2026
Travel, Transport, Accommodation and Venue Solutions
Government Commercial Agency: Cyber Essentials Certification Guidance for SMEs
NHS Supply Chain: Cyber Security Expectations of Suppliers
PCI Security Standards Council: Adopting the Future-Dated Requirements of PCI DSS v4.x
2025 Trustwave Risk Radar Report: Hospitality Sector
SecurityWeek: BWH Hotels Says Hackers Had Access to Reservation Data for 6 Months
SecurityWeek: Saflok Lock Vulnerability Can Be Exploited to Open Millions of Doors
Infosecurity Magazine: Data on Half a Million Hotel Guests Exposed After Otelier Breach
Infosecurity Magazine: NCSC Playbook Embeds Cyber Essentials in Supply Chains
Malwarebytes: Travelers Targeted When Logging Into Hotel Wi-Fi Networks
UKHospitality: Facts and Stats
UKHospitality: Cyber Security Isn’t Just an IT Problem Any More
UKHospitality: Cyberthreats and the DarkHotel, Protecting Hospitality Businesses
The Hotel Magazine: Hospitality Staff Turnover Drops by Close to 10%
Hotel Tech Report: Top 10 Best Hotel Property Management Systems 2026
IBISWorld: Hotels in the UK, Number of Businesses
Armstrong Watson: Cyber Threats in the Hospitality, Leisure and Tourism Sector
Claranet: 2026 Changes to Cyber Essentials and Cyber Essentials Plus