How Cyber Essentials Plus requirements appear in tenders
CE+ is no longer a nice-to-have. NHS Supply Chain, MOD frameworks, and corporate supply chains now name it as a qualifying requirement. Here is how it shows up, and what to do before the deadline bites.
A few years ago, Cyber Essentials was a box you ticked if you had time. Now it is a gating requirement. If you supply into the NHS, the public sector, or a large corporate, the question is no longer whether you will be asked for it, but whether you will have it ready when the tender lands.
NHS Supply Chain and the DSPT deadline
NHS Supply Chain now mandates Cyber Essentials Plus for all in-scope suppliers. Alongside it sits the Data Security and Protection Toolkit, the DSPT, an annual self-assessment with a submission deadline of 30 June. The two work together. The DSPT is your yearly declaration, and CE+ is the independently verified proof behind it.
The trap is timing. Businesses leave CE+ until the DSPT deadline is close, then discover the certification takes several weeks and the independent test cannot be slotted in at the last minute. By the time the gap is found, the deadline has already moved.
Plan backwards from the deadline
If your DSPT submission is due 30 June, your CE+ certificate needs to be in hand weeks before that. Start the gap analysis in spring, not in June.
MOD and public sector supply chain tenders
Manufacturing and engineering businesses hit this one hard. MOD and wider public sector tenders name Cyber Essentials Plus as a qualifying requirement, meaning you cannot even bid without it. It is not scored. It is a threshold. No certificate, no bid, no conversation.
The cost of getting this wrong is not a lower score. It is a tender you were fully capable of winning that you never got to submit. We see businesses lose contracts they had already priced because the certification was not sorted before the qualification stage closed.
Corporate supply chains pushing it downwards
It is not just the public sector. Large corporates are increasingly pushing Cyber Essentials Plus down their own supply chains as a condition of doing business. A client you have worked with for years suddenly sends a supplier assurance questionnaire naming CE+ explicitly, and gives you a short window to provide it.
Legal and financial services firms see this most often. Client confidentiality obligations and insurer requirements increasingly name CE+ in the small print. It is becoming the baseline proof that a supplier takes information security seriously, whether the regulator demands it or the client simply insists.
What to check before the deadline bites
- Read the exact wording. If a tender says Cyber Essentials, confirm whether it means the self-assessment or CE Plus. Most public sector frameworks mean the Plus version specifically.
- Check the scope. CE+ is certified for a defined scope. Make sure the scope on your certificate covers the systems and sites the contract actually relies on.
- Mind the expiry. Certificates last twelve months. A certificate that expires mid-contract is the same as not having one when the client checks.
- Build in renewal time. Independent assessors book up, and the technical test cannot be rushed. Treat renewal as a project with a deadline, not a formality.
Why managed beats one-off for tender work
If you are certifying for a tender, the risk is not just passing once. It is staying certified for the life of the contract. Our Managed CE+ package handles renewal automatically with continuous vulnerability scanning, so the certificate never lapses and the next tender never catches you out.
If the deadline is already close
If a tender deadline is already bearing down on you, do not assume it is too late. A Readiness Assessment gives you a written gap analysis against all five technical controls quickly, so you know exactly what stands between you and a pass before you commit to the full certification. In most cases there is less to fix than you fear, and a clear plan is enough to buy time with the procurement team.
Book a fifteen-minute scoping call and we will tell you honestly whether the timeline is achievable, what it will take, and what it will cost. No forms to fill in first, no hard sell.
Written by
Gary Sinnott
Founder & IT Business Consultant
Freshcyber helps UK regulated SMEs achieve and maintain Cyber Essentials Plus, with a 100% pass rate across every engagement delivered.
Keep reading
Why self-assessment fails the Cyber Essentials Plus test
Cyber Essentials is a self-assessment. Cyber Essentials Plus adds an independent technical test. Here is exactly where self-assessed applications fall apart on audit day, and how to pass first time.
ReadPenetration testing vs vulnerability management: what is the difference?
A one-off penetration test and continuous vulnerability management solve different problems. Here is which one your business actually needs, and why the best programmes use both.
Read