Cyber Essentials for hotels has quietly become a commercial document rather than a technical one. It started life as a government scheme to raise the floor on basic controls, and it now turns up in corporate travel tenders, agency accommodation agreements, conference contracts and insurance renewals. The hotel that can produce a current certificate answers the question in one line. The hotel that cannot spends three weeks writing prose about its firewalls and still loses the account.

The scheme itself is not difficult. What makes Cyber Essentials for hotels awkward is the estate: a property management system somebody else hosts, bar tills nobody patches, a door-lock encoder running an operating system from a previous decade, self-service kiosks in the lobby, a guest network shared with three hundred strangers a night, and a workforce that turns over faster than almost any other sector in Britain.

Those are scoping problems, not security problems, and they are where certification attempts stall. If you have read our guide to Cyber Essentials for property management companies, the shape will be familiar, but a hotel has a payment estate and a guest estate that a lettings business simply does not.

This guide to Cyber Essentials for hotels covers what the scheme certifies, what changed with the Danzell v3.3 requirements in April 2026, how to draw a defensible scope boundary around a hotel, what each of the five controls means at a front desk, what certification actually costs, what a Cyber Essentials Plus assessor tests, who is asking for the certificate, and a ninety-day plan to get it. It assumes you already have IT support for hotels in some form, whether in-house, outsourced or brand-mandated.

Why Cyber Essentials for Hotels Stopped Being Optional

cyber essentials for hotels 2026 certification guide b open document wallet

Cyber Essentials for a bakery is a badge. For accommodation providers it has become a filter applied before anyone reads your rate card.

The certificate is now a procurement gate

Public sector buyers set the pattern. Procurement Policy Note 014 came into force on 24 February 2025, replacing PPN 09/14 and PPN 09/23, and it binds central government departments, executive agencies, non-departmental public bodies and NHS bodies. Crucially for this sector, it names travel booking explicitly as a service where a supplier handling the personal information of government employees, ministers and special advisors must meet the technical requirements.

A hotel holding a civil servant’s name, home address, payment details and stay dates sits squarely inside that wording. Evidence is required before contract award and must be renewed annually for the life of the contract. The note also tells buyers not to take a blanket approach and warns them against over-burdening smaller suppliers, which is worth knowing when an ask looks disproportionate. Local authorities and housing associations are not formally in scope, but many apply the same rule anyway.

Corporate travel programmes copied it

Once the public sector normalised the question, corporate travel and procurement teams followed. Hotels bidding for a preferred-supplier agreement now regularly meet a security questionnaire, and Cyber Essentials for hotels is the cheapest possible answer to most of it. That is the practical case for Cyber Essentials for hotels: not that it prevents every attack, but that it converts a fortnight of questionnaire correspondence into a single verifiable line.

The national numbers explain the leverage

The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found 43% of UK businesses had experienced a breach or attack in the preceding twelve months. Exposure climbs with size: 46% of small businesses, 65% of medium and 69% of large.

Only 25% have a formal incident response plan and only 31% have a board member with named responsibility for cyber security. Certification sits at 5% of businesses overall, 12% of small businesses and 35% of large ones, while awareness of the scheme reaches only 17%. That gap is why Cyber Essentials for hotels still reads as a differentiator rather than a baseline.

UK businesses: breach exposure against basic preparedness (2025/2026 survey)
Experienced a breach or attack 43%
Named board member for cyber security 31%
Formal incident response plan 25%
Certified to Cyber Essentials 5%

Insurers ask a version of the same question

Cyber insurance proposal forms have converged on the same five controls: perimeter firewalls, secure configuration, patching, access control and malware protection. A property that can evidence all five through Cyber Essentials for hotels usually gets a faster underwriting decision. Certifying through an IASME-licensed body also carries £25,000 of cyber liability cover for UK businesses turning over under £20 million. That is not a promise about premium reductions, but it removes a category of back-and-forth.

What Cyber Essentials for hotels is really insuring against

The sector’s worst case is already on the record. The ICO fined Marriott International £18.4 million on 30 October 2020 over an attack on Starwood Hotels and Resorts that began in 2014 and went undetected until September 2018, exposing roughly 339 million guest records worldwide, around 30 million in the EEA and 7 million in the UK. The original notice of intent had been £99.2 million. Nothing in the scheme would have guaranteed prevention, but every control it tests is one the ICO went on to examine.

What Cyber Essentials Actually Certifies

cyber essentials for hotels 2026 certification guide c kiosk pillar panel

Before scoping anything, it helps to be precise about what Cyber Essentials for hotels does and does not certify. Overstating it in a tender response is how hotels end up making claims they cannot support.

Five technical controls, nothing more

The scheme covers firewalls and internet gateways, secure configuration, security update management, user access control and malware protection. That is the whole thing. It does not cover physical security, staff vetting, contractual terms, business continuity or the way you handle a guest complaint about their data.

Self-assessment versus independent testing

Basic certification is a self-assessment questionnaire, answered by someone who can genuinely speak for the estate and signed off at board level, then marked by a certification body. Cyber Essentials Plus keeps the identical technical requirements and adds an independent hands-on audit. The requirements do not get harder at Plus level; the evidence does.

Backups still are not a control

Backups are discussed in the requirements and repositioned in the latest version, but they remain outside the five controls. A hotel can hold a valid Cyber Essentials for hotels certificate with a backup regime that would not survive a ransomware event. Treat certification as a floor, not a strategy.

What Cyber Essentials for hotels deliberately excludes

The scheme also says nothing about your suppliers’ own security, which matters because so much of a hotel estate is somebody else’s software. Verizon’s 2026 Data Breach Investigations Report put third-party involvement at 48% of breaches. Cyber Essentials for hotels covers your own estate and does not touch that, which is why supplier questions belong alongside it, as we set out in Cyber Essentials for suppliers.

ControlWhat the assessor asksWhere it bites in a hotel
Firewalls and internet gatewaysNo unauthenticated management from the internet, default passwords changed, inbound rules justifiedInstaller-configured wireless gateways and remote-support rules nobody documented
Secure configurationUnused accounts and software removed, auto-run disabled, device unlock controls in placeShared front-desk logins and kiosk builds shipped by a vendor
Security update managementSupported software only, critical and high updates inside 14 daysEPOS terminals, door-lock encoders and back-office machines on vendor release cycles
User access controlNamed accounts, approval process, prompt removal, MFA on cloud servicesSeasonal staff, agency cover and a shared reception account
Malware protectionAnti-malware, allow-listing or sandboxing on every in-scope deviceAppliance-like devices where no agent can be installed

What Changed in 2026: Danzell v3.3 and Cyber Essentials for Hotels

cyber essentials for hotels 2026 certification guide d three key cards

The requirements behind Cyber Essentials for hotels moved on 26 April 2026. If your last certificate predates that, the questionnaire you remember is not the questionnaire you will meet.

The version and the dates

IASME published the version 3.3 question set, named Danzell, on 13 February 2026, replacing version 3.2 Willow, and the requirements document itself carries an April 2026 date. It applies to assessment accounts created from late April 2026. IASME has published both 26 and 27 April as the effective date in different articles, so treat the end of that month as the switchover rather than quoting a single day. Accounts created before it were given six months to finish under the old requirements.

Three answers now fail outright

Three requirements are treated as automatic failures rather than recoverable non-compliances. Multi-factor authentication must be applied to cloud services wherever the service supports it, including where the capability sits behind a higher licence tier. Operating systems and router or firewall firmware must receive critical and high severity updates within 14 days, and so must applications, files and extensions. There is no partial credit on any of the three, and each one ends an attempt at Cyber Essentials for hotels on the spot.

Cloud services cannot be carved out

The requirements now define cloud services formally and state plainly that they cannot be excluded from scope. For a hotel that is the single most consequential change, because the property management system, the channel manager, the booking engine, the payroll platform and the EPOS back office are usually all cloud services operated by third parties. Cyber Essentials for hotels therefore now reaches into systems the property does not host.

The BWH Hotels breach shows why that matters. Attackers held access to a reservation web application from 14 October 2025 until 22 April 2026, roughly six months, exposing guest names, email addresses, phone numbers and reservation details across a group operating more than 4,000 hotels worldwide. Payment data was not stored in that system. It was a cloud reservation application, which is exactly the class of system the requirements now say you cannot leave out.

Smaller changes that still matter

FIDO2 security keys are explicitly recognised as multi-factor authentication. Legal entities must be identified by name, registered address and company number, with per-entity certificates available for a small additional fee, which matters for groups holding properties in separate companies. Any excluded area must be specifically described and justified, and “point in time” is defined as the certificate issue date. The old “web applications” terminology becomes “application development”, now referencing the UK Government Software Security Code of Practice.

Change in v3.3 DanzellPreviouslyEffect on a hotel
MFA on cloud services is an auto-failMajor non-complianceA PMS or channel manager without MFA ends the assessment
14-day patching of OS and firmware is an auto-failMajor non-complianceUnmanaged EPOS and kiosk builds become the critical path
14-day patching of applications, files and extensions is an auto-failMajor non-complianceBrowser extensions on back-office PCs need an owner
Cloud services cannot be excludedAmbiguous in practiceThird-party hosted hotel systems are in scope by default
Exclusions must be described and justifiedLoosely worded“Guest network excluded” is no longer a sufficient sentence
FIDO2 recognised as MFANot namedSecurity keys are a valid answer for shared terminals

Scoping Cyber Essentials for Hotels: Where the Boundary Falls

cyber essentials for hotels 2026 certification guide e folded wallet

Cyber Essentials for a single independent property and certification across a branded group are the same questionnaire answered about very different estates. Scope for Cyber Essentials for hotels is decided before anything technical happens, and a bad boundary is the most expensive mistake available.

Whole organisation or a defined sub-set

You may certify the whole organisation or a clearly defined sub-set. Whole-organisation scope is simpler to explain to a corporate buyer and harder to achieve. The requirements define a sub-set as part of the organisation whose network is segregated from the rest by a firewall or a VLAN. The scope boundary has to name the business unit managing it, the network boundary and the physical location, and it must be agreed with your certification body before assessment begins. One rule closes off the obvious shortcut: a scope that does not include end-user devices is not acceptable.

The temptation to exclude the messy parts

Every hotel is tempted to scope out the kiosks, the tills and the guest network. Under the current requirements each exclusion must be specifically described and justified, and it has to be genuinely segregated rather than simply inconvenient. An exclusion that survives the questionnaire may still fail the commercial test when a client reads the certificate and asks what was left out.

Where the group structure bites

Many UK hotel groups hold each property in a separate limited company for perfectly ordinary reasons. Because legal entities must now be identified by company number, a group that wants one certificate covering everything has to be honest about which entities that certificate names. Per-entity certificates are available for a small extra fee, and for Cyber Essentials for hotels in a multi-company group that is usually the cleaner answer.

Franchise and brand-managed complications

Where a property operates under a franchise agreement, some systems are mandated and supported by the brand and some are the operator’s own. The certificate belongs to the legal entity being assessed, so brand-supplied systems used by that entity’s staff sit inside its scope even when the operator cannot change them. Accounts your organisation owns stay in scope even when a supplier, contractor or managed service provider is the one using them, and you have to be able to demonstrate that the controls are met on anything externally managed. Document who administers what before you answer a single Cyber Essentials for hotels question.

Hotel systemDefault positionWhat decides it
Property management system (cloud)In scopeCloud services cannot be excluded; MFA is mandatory
Front desk and back office PCsIn scopeStaff devices accessing organisational data
EPOS terminals in bar and restaurantIn scopeConnect to the internet and to organisational systems
Self check-in kiosksIn scopeInternet-connected devices under your administration
Door-lock encoder and serverIn scope unless segregatedWhether it is firewalled off and justified in writing
Guest WiFi networkExcludable if truly segregatedSegregation you can demonstrate, plus a written justification
Guest devices on that networkOut of scopeNot owned or administered by the organisation
CCTV, BMS and lift telemetryDependsInternet connectivity and who administers the platform

The Hotel Systems That Complicate Cyber Essentials for Hotels

cyber essentials for hotels 2026 certification guide f certificate frame

The five controls are simple. Applying them to hospitality hardware is where Cyber Essentials for hotels actually gets difficult, and it is worth naming the specific offenders before you start.

Property management systems

The PMS holds guest names, addresses, stay history, sometimes passport data and often stored card tokens. Modern deployments are cloud-hosted, so under the current requirements they are in scope automatically and multi-factor authentication is not negotiable. Older on-premise deployments raise a harder question: is the underlying operating system still supported by its vendor?

Read the shared-responsibility split before you call the vendor. For software as a service the provider handles firewalls, security update management and malware protection, secure configuration is shared, and user access control is always your organisation’s job. You are also expected to confirm the provider’s commitments through the contract or documents the contract references.

Point of sale and payment terminals

Bar and restaurant tills are frequently supplied, configured and maintained by a hospitality EPOS vendor on a release cadence that has nothing to do with a 14-day clock. They are internet-connected and used by staff, so they are in scope. The realistic answer is usually a contractual conversation with the vendor rather than a technical one, and it is the most common blocker for Cyber Essentials for hotels.

Electronic door locks and encoders

Almost every property has a workstation that programmes room key cards. It is often ancient, rarely patched, sometimes running an operating system past its support date, and almost never on the asset register. Unsupported software is a straightforward failure, and it is the single most common surprise we see, as covered in our guide to unsupported software under Cyber Essentials and ISO 27001. The Unsaflok research put the scale of that estate in perspective: more than three million dormakaba Saflok locks across over 13,000 properties in 131 countries, with only around 36% updated by the time the findings were published.

Kiosks, signage and business-centre PCs

Self check-in kiosks, digital signage players and any surviving business-centre computer are internet-connected devices under your administration. If a guest can use it and you own it, an assessor will want to know how it is patched, how it is protected from malware and how it is prevented from reaching your back office.

Everything else with an IP address

Casting devices in bedrooms, spa booking terminals, energy management controllers, CCTV recorders and conference room panels all have network addresses. Not all of them are in scope, but every one of them needs a decision recorded against it. Sound device management is what turns that from an annual panic into a register you already maintain.

Guest WiFi, Card Payments and Cyber Essentials for Hotels

Two questions dominate every Cyber Essentials for hotels scoping conversation, and both have clearer answers than most operators expect.

Guest devices are not yours

Devices owned by guests are not administered by the organisation and are therefore out of scope. That is the easy half. The rule runs the other way just as firmly: a device your organisation owns is in scope even when a customer is the one using it, so a lobby iPad, a surviving business-centre PC or a self check-in kiosk counts, and so does a hotel-owned laptop loaned to a contractor.

The infrastructure that serves those guests is a different matter: the access points, controller and captive portal gateway are your equipment, bought by you and administered on your behalf. Wireless devices are in scope where they can communicate with other devices over the internet, and out of scope only where an attacker would have to be within signal range to reach them.

The guest network can be excluded, but only properly

IASME’s scoping guidance names this sector directly. A segregated guest network that does not interact with other organisational data or services, and simply lets people outside the organisation reach the internet, can be excluded, and the published example is a hotel with a guest network. Note where that concession lives: it is IASME guidance rather than a line in the requirements document, which never mentions hotels at all, so an assessor applies it on the evidence you provide.

“Guests are on a separate SSID” is not segregation. The design that actually holds up is the one we set out in hotel guest WiFi VLAN segmentation, and the wider posture in hotel WiFi security.

Why the gateway still deserves attention

Even where the guest network is excluded, the gateway is a device you own with a management interface. The CaptiveCrunch campaign disclosed in mid-2026 showed exactly what happens when those appliances are reachable from the internet with installer credentials, and we broke down the chain in captive portal attacks on hotel WiFi. An excluded network is not an unmanaged one, and Cyber Essentials for hotels still asks about the equipment you own.

Card payments run on a parallel track

PCI DSS is a separate obligation with its own scope, and Cyber Essentials for hotels does not satisfy it. Version 4.0.1 landed in June 2024 and its 51 future-dated requirements became effective on 31 March 2025, so no grace period is left to lean on. The two overlap usefully: segmentation reduces payment scope, and PCI DSS requires quarterly detection of rogue wireless access points even where wireless is prohibited in the payment environment. Do the segmentation once and let both regimes benefit.

Firewalls and Secure Configuration Across a Property

The first two controls are where Cyber Essentials for hotels usually scores well on paper and badly in practice, because the estate was configured by an installer years ago.

Boundary firewalls at every site

Each property needs a firewall or equivalent boundary device between its network and the internet, with default administrative passwords changed and no unauthenticated management interface reachable from outside. Multi-property groups often discover that one site was built differently because a different contractor did the install, which is exactly the inconsistency Cyber Essentials for hotels exposes.

What a hospitality scan actually finds

Trustwave scanned the sector in April 2025 and reported 95,040 vulnerabilities across hospitality organisations, drawn from 3,884 unique CVEs, of which 14,318 were rated critical and 1,521 appeared on the CISA known-exploited list. It also found that 61.5% of observed initial access attempts targeted publicly exposed services. The most exposed protocol by a wide margin was SNMP, which in a hotel means building management, HVAC, lighting and IP cameras.

Internet-exposed services found across hospitality organisations (Trustwave, April 2025)
SNMP, port 161 9,627
HTTPS, ports 443 and 8443 6,438
NTP, port 123 5,525
HTTP, port 80 4,372

Remote support rules nobody remembers

Hospitality estates accumulate inbound rules: the EPOS vendor needed access, the door-lock supplier needed access, the building management contractor needed access. Every one of those needs a documented business justification and an owner. Rules that no longer have either are the fastest scope reduction available.

Secure configuration in a shared environment

Secure configuration means removing unused software and accounts, disabling auto-run, and controlling how devices are unlocked. In a hotel that runs straight into shared front-desk workstations, kiosk images supplied by a vendor and machines that were never rebuilt after the last refurbishment. Consistent IT governance is what keeps a fixed build from drifting between properties.

Wireless infrastructure counts as configuration

Access points and controllers are configurable devices with administrative credentials. Default community strings, unchanged admin passwords and management interfaces on the guest VLAN are all secure configuration failures, whatever the guest network’s scope status. Getting the network design right once removes an entire class of Cyber Essentials for hotels finding.

Security Update Management on a 14-Day Clock

This is the control that fails hotels, and the 2026 requirements made Cyber Essentials for hotels unforgiving about it.

What the rule actually says

Software must be licensed and supported, and updates rated critical or high by the vendor must be applied within 14 days of release. That applies to operating systems, to router and firewall firmware, and to applications, files and extensions. All three are now automatic failures rather than recoverable findings.

Why hospitality estates struggle

A front-office PC is easy. A till behind a bar during a wedding is not. Kiosks reboot at inconvenient times, encoders are treated as appliances, and nobody wants to patch a system that takes payments on a Saturday night. The result is a small number of devices sitting permanently outside the window, which is enough to end an attempt at Cyber Essentials for hotels.

The exploitation trend behind the rule

Verizon’s 2026 Data Breach Investigations Report found exploitation of software flaws had become the leading initial access route at 31%, overtaking stolen credentials. That is precisely the gap a 14-day clock is designed to close, and it explains why the scheme stopped treating late patching as a negotiable finding.

Making Cyber Essentials for hotels survivable

The practical answer for Cyber Essentials for hotels is a maintenance window that management actually protects, automatic updates wherever the vendor supports them, and a written escalation path for any device the window cannot reach. Continuous monitoring turns “we think everything is patched” into a report you can hand an assessor.

User Access Control When Staff Turnover Is High

Hospitality has some of the highest workforce churn in the UK economy, and the access control requirement behind Cyber Essentials for hotels was written as though it does not. A 2025 benchmark covering more than 35,000 hospitality employees put annual staff turnover at 67%, down from 75% the year before. Two thirds of your account list changes in a year.

Named accounts, not shared ones

Every user needs their own account, created through an approval process, with administrative access granted separately and only where justified. A single reception login shared across a shift is the most common failure in the sector and the least defensible one, because it also destroys any hope of knowing who did what.

Leavers are the real risk

Accounts must be removed promptly when someone leaves. In a hotel that means agency cover, seasonal contracts, transfers between properties and staff who left mid-shift six months ago. The starters and leavers process needs to be owned by whoever runs the rota, not only by whoever runs IT, because leaver accounts are the finding that most often delays Cyber Essentials for hotels.

Personal phones are mostly in scope

User-owned devices that access organisational data or services are in scope. The carve-out is narrow: a phone used only for native calls, native texts or an authenticator app stays out, but the moment it opens the rota system, the booking platform or work email it is in. That catches a great many agency and seasonal staff who were never issued a device.

MFA is now non-negotiable

Multi-factor authentication must be applied to cloud services wherever it is available, including where the capability is only offered on a higher licence tier. FIDO2 security keys are explicitly recognised, which is genuinely useful at a shared terminal where phone-based authentication is impractical. This is one of the three automatic failures, so partial rollout is the same as none.

Administrative accounts in a small team

Small properties often give the general manager local administrator rights because it is convenient. Separate the day-to-day account from the administrative one, keep a list of who holds administrative access, and review it when people move. Doing this well is the substance of the wider security posture that Cyber Essentials for hotels is supposed to reflect.

Malware Protection From Front Desk to Back Office

The fifth control is usually the easiest part of Cyber Essentials for hotels to satisfy and the easiest to leave with a hole in it.

Three acceptable approaches

You may use anti-malware software, application allow-listing, or execution in a sandboxed environment. Most hotels will use anti-malware on Windows devices and allow-listing on kiosks, which is a perfectly good answer for Cyber Essentials for hotels provided it is applied consistently rather than to the machines that happened to have it already.

The devices that resist agents

Appliance-like devices are the awkward ones: some EPOS terminals, some kiosks and some encoders will not accept a third-party agent. Where that is the case, allow-listing or a documented segregation argument is the route, and the vendor needs to be part of the conversation.

Phishing is still the entry route

The 2025/2026 survey put phishing at 38% of businesses experiencing it and identified it as the most disruptive breach type for 69% of those affected. Malware protection on the endpoint is the last line, not the first, and Cyber Essentials for hotels only ever tests the last line. Reservations inboxes handling attachments from unknown senders all day are the highest-risk mailboxes in the building.

Testing rather than assuming

At Plus level an assessor will actually send test files. Before certification, confirm that protection is enabled, updating and reporting centrally on every in-scope device, including the ones in locations nobody visits. A quiet failure on a single back-office machine is enough to fail the audit.

What Cyber Essentials for Hotels Costs in 2026

Cost is the question every general manager asks about Cyber Essentials for hotels first, and the published fees are only part of the answer.

The published assessment fees

IASME’s assessment fees are banded by organisation size, excluding VAT: £320 for micro organisations of 1 to 9 people, £440 for small organisations of 10 to 49, £500 for medium organisations of 50 to 249, and £600 for large organisations of 250 or more. The certificate lasts 12 months. Most single properties fall in the small or medium band; a group with several hotels will usually be medium or large.

IASME assessment fee by organisation size, excluding VAT
Micro, 1 to 9 people £320
Small, 10 to 49 people £440
Medium, 50 to 249 people £500
Large, 250 or more people £600

What Plus adds

Cyber Essentials Plus is priced by the certification body rather than centrally, and typically lands somewhere between roughly £1,400 and £5,000 or more depending on estate size and the number of sites sampled. It must be completed within three months of the underlying certificate.

The costs that are not on the invoice

The real spend for Cyber Essentials for hotels is usually remediation: replacing an unsupported encoder workstation, buying licences that unlock multi-factor authentication, rebuilding a kiosk image, or paying an EPOS vendor to move to a supported release. Budget for those before you book the assessment, not after the questionnaire tells you about them.

Where the money is recovered

A single corporate account won on the back of a clean security answer usually covers the whole exercise. That is the honest commercial case: Cyber Essentials for hotels is cheap relative to a tender you cannot answer, and it is dramatically cheaper than the first day of an incident.

Cyber Essentials for Hotels: Moving Up to Cyber Essentials Plus

Plus is where the paperwork behind Cyber Essentials for hotels meets reality, and the 2026 requirements sharpened the consequences of getting it wrong.

What the assessor actually does

The current test specification is version 3.2, published in April 2025, and it sets five test cases: a remote vulnerability assessment of every IP address in use, an authenticated scan of sampled devices, malware protection tested by email and by browser download, multi-factor authentication tested on all cloud services, and account separation tested on every sampled device.

The patch threshold is explicit. Anything the vendor rates critical or high, or scoring 7 or above on CVSS version 3, with a fix available for more than 14 days, is a fail, and virtual patching is not accepted as a long-term answer for unsupported operating systems. A single fail means the assessment fails.

Sampling across a distributed estate

Sampling is harder in hospitality because the devices are spread across properties, shifts and back-of-house rooms. Shared front-desk machines, kiosks in public areas and tills that cannot be taken offline during service all complicate scheduling. Sample size follows variation rather than headcount: a group running one standard image needs few representative devices, while a group whose front desks were each built by a different contractor over fifteen years needs many. Every cloud service must also be tested with at least one ordinary and one administrative account.

Before any of that, the assessor has to verify by technical means that the scope matches the systems in front of them and that any sub-set segregation genuinely holds. That is the moment a declared guest-network exclusion stops being a sentence and starts being a test. Plan the audit around the operation rather than expecting the operation to pause.

The retest rules changed

A retest now covers the original sample plus a fresh random sample, and a second failure revokes the certificate rather than simply delaying it. Verified self-assessment answers also lock once Plus testing begins, so you cannot quietly correct the questionnaire once the assessor has started.

Do you need Plus at all

Basic Cyber Essentials for hotels answers most corporate travel questionnaires. Plus is worth it when a specific client demands it, when you are bidding for public sector accommodation work, or when you want the assurance for yourself. If you are weighing it against a management system, our comparison of Cyber Essentials Plus and ISO 27001 sets out where each one earns its place.

Who Actually Asks for Cyber Essentials for Hotels

Knowing where demand for Cyber Essentials for hotels comes from tells you when to certify and what to say once you have.

Public sector accommodation buyers

Government departments, agencies and NHS bodies book a great deal of accommodation, and PPN 014 puts travel booking on the list of services where the requirement applies. The live agreement is RM6342 Travel, Transport, Accommodation and Venue Solutions, running to 30 September 2027 and now administered by the Government Commercial Agency, which is what Crown Commercial Service became on 1 April 2026.

Be precise when you quote this to a client: the framework page does not itself mandate certification. The obligation reaches a hotel through PPN 014 and through the travel management company’s own supplier terms.

NHS buyers often want Plus

NHS Supply Chain expects suppliers handling its personal data to demonstrate Cyber Essentials Plus, accepting basic certification only where the supplier can provide evidence that replaces an external audit requirement. If your group takes NHS accommodation business, assume the higher bar and plan Cyber Essentials for hotels with Plus in view from the start.

Corporate travel programmes and TMCs

Companies with negotiated rate programmes increasingly route hotels through a supplier security review. The questions are rarely sophisticated; they are usually a checklist that maps neatly onto the five controls. Cyber Essentials for hotels answers most of it before the conversation starts. The direction of travel is clear enough: the NCSC published a Cyber Essentials Supply Chain Playbook in December 2025 telling large buyers to require certification of their suppliers rather than merely encourage it, alongside a tool that bulk-checks supplier certification status.

Conference, event and group bookings

Event clients handing over delegate lists are handing over personal data, and their own compliance teams have started asking how it will be held. A certificate plus a clear statement of what is in scope resolves that quickly.

Brands, insurers and lenders

Franchisors set technology standards, insurers ask about the same controls, and lenders financing a refurbishment increasingly ask about operational resilience. None of these strictly require Cyber Essentials for hotels, but all of them are easier conversations with a certificate in hand. Systematic vendor management is the other half of that answer.

Who asksWhat they wantWhat satisfies them
Central government and NHS buyersStated requirement in the tender noticeCurrent certificate, or an accepted equivalent
Corporate travel programmesSupplier security questionnaireCertificate plus a one-page scope statement
Conference and event clientsAssurance over delegate dataCertificate, retention policy, named contact
Cyber insurersEvidence of basic controlsCertificate plus MFA and patching evidence
Franchisors and brandsCompliance with brand IT standardsCertificate mapped to the brand checklist

Cyber Essentials for Hotels vs PCI DSS and ISO 27001

Operators are frequently asked about all three in the same week and treat them as rivals to Cyber Essentials for hotels. They are not.

Different questions entirely

Cyber Essentials asks whether five technical controls are in place across a defined estate. PCI DSS asks how you protect cardholder data specifically. ISO 27001 asks whether you run a management system that identifies and treats information risk over time. One is a floor, one is payment-specific, one is a discipline.

Where they overlap usefully

Network segmentation reduces PCI scope and supports a clean Cyber Essentials boundary at the same time. Patching and access control evidence serves all three. An asset register built for certification is the same register an ISO 27001 auditor will ask for, which is why our ISO 27001 readiness assessment starts in the same place.

Sequencing them sensibly

For most independent hotels and small groups the order is straightforward: complete Cyber Essentials for hotels first, keep PCI DSS obligations current with your acquirer, and consider ISO 27001 only if a major client or a lender genuinely requires it. Doing them in that order means each stage reuses the previous stage’s evidence.

DimensionCyber EssentialsCyber Essentials PlusPCI DSSISO 27001
What it coversFive technical controlsSame, independently testedCardholder data environmentWhole management system
EvidenceSelf-assessment, markedHands-on audit and samplingSAQ or QSA assessmentExternal certification audit
Typical cost£320 to £600 plus VATRoughly £1,400 to £5,000+Varies by acquirer and channelSubstantially higher
RenewalAnnualAnnual, within 3 months of baseAnnual validation3-year cycle with surveillance
Best used forTenders and questionnairesClients who demand testingCard acceptance obligationsEnterprise and lender assurance

A Worked Example: Cyber Essentials for Hotels in a Four-Property Group

Abstract requirements are easy to nod along to. Here is what the scope for Cyber Essentials for hotels actually looks like in a modest UK group, using round numbers you can substitute your own figures into.

The estate

Four properties of 120, 90, 75 and 60 bedrooms, so 345 bedrooms in total, plus a small head office. Employment across the group is roughly 45 people per property and 12 at head office, which is 4 × 45 + 12 = 192 people. That places the group in the medium band of 50 to 249, so the assessment fee is £500 excluding VAT.

Counting the devices

Per property there are 4 front-desk PCs, 6 back-office PCs, 5 EPOS terminals, 2 self check-in kiosks, 1 door-lock encoder workstation and 3 duty-manager mobile devices. Across four properties that is 16, 24, 20, 8, 4 and 12 respectively, and head office adds 14 laptops. The total in-scope device count is 16 + 24 + 20 + 8 + 4 + 12 + 14 = 98.

Where the effort concentrates

Of those 98 devices, the 24 back-office PCs and 16 front-desk PCs are ordinary managed Windows machines. The 20 EPOS terminals, 8 kiosks and 4 encoders — 32 devices, just under a third of the estate — are the ones a hotel does not fully control, and they will consume most of the remediation effort.

Worked example: 98 in-scope devices across a four-property group
Back-office PCs 24
EPOS terminals 20
Front-desk PCs 16
Head office laptops 14
Duty-manager mobiles 12
Kiosks and encoders 12

The cloud side of the same scope

The group also runs seven cloud services: Microsoft 365, the PMS, a channel manager, the booking engine, payroll, the EPOS back office and a cloud CCTV platform. Every one of them needs multi-factor authentication enabled, because cloud services cannot be excluded and MFA is an automatic failure. Seven services and 98 devices is the entire Cyber Essentials for hotels scope statement, and it fits on one page.

What this group should expect to spend

The £500 assessment fee is trivial next to the remediation. Realistically this group replaces one or two encoder workstations, buys licences that unlock MFA on at least one platform, and negotiates a supported release with its EPOS vendor. A single managed IT services arrangement covering all four properties usually costs less than running four different local arrangements badly.

Why Cyber Essentials for Hotels Applications Fail

Failures cluster around a small number of causes, and every one of them is discoverable before you submit.

Unsupported software nobody owned

An encoder, a back-office machine or a kiosk running software past its vendor support date is a straightforward failure. Find it during the asset inventory, not during the assessment. This is the single most common cause across every sector, and hospitality has more hidden candidates than most.

Partial multi-factor authentication

MFA on Microsoft 365 but not on the PMS is a fail, because the requirement applies to every cloud service that supports it. Licence-tier excuses were closed off explicitly in the current requirements. List every cloud service first, then check each one against the Cyber Essentials for hotels requirement.

Scope written to be convenient

An exclusion that is not genuinely segregated, or is described in one vague sentence, invites rejection. Write the boundary as though a sceptical assessor will read it, because one will. The other failure patterns are catalogued in our guide to Cyber Essentials failure reasons.

Answering from memory

The questionnaire is answered by a person who signs for the whole organisation. Answers based on what the estate looked like two years ago fail at Plus and mislead clients in the meantime. Verify each answer against something you can show, whether that is a management console export or a photograph of a device screen.

No owner after certification

A Cyber Essentials for hotels certificate is a point-in-time statement, defined as the certificate issue date, and it lasts twelve months. Without a named owner, the estate drifts and the next renewal becomes a fresh project. Good cybersecurity practice in hospitality is a maintained register plus a monthly review, not an annual scramble.

A 90-Day Plan to Achieve Cyber Essentials for Hotels

This plan takes a property from nothing to Cyber Essentials for hotels in one quarter. It assumes one competent supplier, no new capital budget and a few hours of management attention each week.

Days 1 to 21: inventory and scope

List every device with an IP address across every property, every cloud service in use including the ones marketing signed up for, and every user account. Decide the scope boundary and write it down. Confirm which legal entities the certificate must name, with company numbers.

Days 22 to 45: close the automatic failures

Enable multi-factor authentication on every cloud service that supports it, including behind licence tiers. Establish a patching regime that meets the 14-day rule for operating systems, firmware and applications, and identify the devices that cannot meet it. These three items are the ones that end assessments outright.

Days 46 to 70: fix the awkward estate

Deal with unsupported software, agree a supported release path with the EPOS and door-lock vendors, rebuild kiosk images with allow-listing, remove stale accounts and eliminate shared logins at reception. Where segregation is part of your scope argument, prove it with a test rather than a diagram.

Days 71 to 90: assess and evidence

Complete the self-assessment with evidence beside each answer, submit, and remediate anything the marker raises. Then write the one-page scope statement that goes to clients alongside the certificate. Properties without in-house expertise can lean on a local IT support team in Chester to run the fortnightly milestones.

Keeping it after you have it

Add the Cyber Essentials for hotels renewal to the same calendar as your fire and food safety obligations, review administrative accounts quarterly, and keep the asset register current as devices are replaced during refurbishment. Pair it with a tested incident response plan, because certification tells a client what you prevent, not what you do when prevention fails.

Cyber Essentials for Hotels: Frequently Asked Questions

Does the guest WiFi have to be in scope?

Not necessarily. Guest devices are never in scope for Cyber Essentials for hotels because you do not administer them, and the guest network itself can be excluded where it is genuinely segregated from organisational systems and the exclusion is specifically described and justified. The infrastructure you own still needs secure configuration regardless.

Can a hotel group certify all its properties on one certificate?

Yes, if they sit within the scope you define and the legal entity position is clear. Because entities must now be named with their company number, groups holding each property in a separate company often find per-entity certificates cleaner, and those are available for a small additional fee.

Is Cyber Essentials enough for PCI DSS?

No. They are separate regimes with separate scopes. Cyber Essentials for hotels demonstrates five basic technical controls; PCI DSS governs how cardholder data is protected. The overlap is real but partial, and segmentation work benefits both.

What happens if our door-lock system runs unsupported software?

It fails the security update management control if it is in scope. The requirements give three routes: upgrade it, remove the unsupported software from the device, or place it in a defined sub-set that prevents all traffic to and from the internet. That third route is legitimate but it means genuinely cutting the device off, not simply labelling it as excluded.

How long does certification take for a single hotel?

For a well-run single property with managed devices and MFA already enabled, a few weeks. For a property discovering its estate for the first time, ninety days is realistic. The variable is remediation, not the questionnaire.

Do we need Cyber Essentials Plus to win corporate accounts?

Usually not. Basic Cyber Essentials for hotels answers most corporate travel and event questionnaires. Plus becomes relevant when a specific client demands independent testing or when you are bidding for public sector accommodation contracts where the buyer has set that bar.

References

NCSC: Cyber Essentials

Cyber Essentials: Requirements for IT Infrastructure v3.3

Cyber Essentials Plus Test Specification v3.2

NCSC: Cyber Essentials Supply Chain Playbook

Procurement Policy Note 014: Cyber Essentials Scheme

IASME: Scope

IASME: Important Update, Changes to Cyber Essentials for April 2026

IASME: Cyber Essentials and Cyber Essentials Plus, What Is the Difference?

Cyber Security Breaches Survey 2025/2026

Travel, Transport, Accommodation and Venue Solutions

Government Commercial Agency: Cyber Essentials Certification Guidance for SMEs

NHS Supply Chain: Cyber Security Expectations of Suppliers

PCI Security Standards Council: Adopting the Future-Dated Requirements of PCI DSS v4.x

2025 Trustwave Risk Radar Report: Hospitality Sector

SecurityWeek: BWH Hotels Says Hackers Had Access to Reservation Data for 6 Months

SecurityWeek: Saflok Lock Vulnerability Can Be Exploited to Open Millions of Doors

Unsaflok

Infosecurity Magazine: Data on Half a Million Hotel Guests Exposed After Otelier Breach

Infosecurity Magazine: NCSC Playbook Embeds Cyber Essentials in Supply Chains

Malwarebytes: Travelers Targeted When Logging Into Hotel Wi-Fi Networks

UKHospitality: Facts and Stats

UKHospitality: Cyber Security Isn’t Just an IT Problem Any More

UKHospitality: Cyberthreats and the DarkHotel, Protecting Hospitality Businesses

The Hotel Magazine: Hospitality Staff Turnover Drops by Close to 10%

Hotel Tech Report: Top 10 Best Hotel Property Management Systems 2026

IBISWorld: Hotels in the UK, Number of Businesses

Armstrong Watson: Cyber Threats in the Hospitality, Leisure and Tourism Sector

Claranet: 2026 Changes to Cyber Essentials and Cyber Essentials Plus

Verizon Data Breach Investigations Report

ICO: Report a Breach