ISO 27001 consultants for public sector suppliers
If you are bidding for central government work, the certificate the policy names is Cyber Essentials, not ISO 27001. That is worth knowing before you spend anything, and it is the first thing a consultancy should tell you.
What the procurement policy actually says
The Cabinet Office procurement policy note on the Cyber Essentials scheme is binding policy rather than guidance, and it replaced the two earlier notes on the same subject. The government has required suppliers bidding for certain public contracts to hold Cyber Essentials or Cyber Essentials Plus, or demonstrate equivalent controls, since 2014.
The operative requirement is that evidence of holding a Cyber Essentials certificate, basic or Plus, or equivalent, is required before contract award for in-scope contracts. Not during delivery, and not at some later assurance stage. Before award.
It is not a blanket rule covering every public contract. It applies where the tender or the framework specifies it, which in practice is most central government procurement and a great deal of wider public-sector procurement involving data or ICT services.
The two words that decide whether your certificate counts
“Or equivalent” is the phrase everything turns on, and it is not your decision. The contracting authority decides what it will accept.
Some authorities will treat a current ISO 27001 certificate with an appropriate scope as demonstrating equivalent controls. Others will not, and some buying organisations state in terms that ISO 27001 is not an acceptable substitute for Cyber Essentials Plus. Both positions are available to them, which means the same certificate can satisfy one bid and fail the next.
The practical consequence is unglamorous and saves a great deal of money: read the requirement in the tender you are actually bidding for, and if it is ambiguous, ask a clarifying question. Procurement processes have a formal route for exactly that. It costs nothing and it is the only way to get an answer that binds.
Why ISO 27001 is still frequently worth doing
None of the above means the standard is a waste of money for a public-sector supplier. It means it is not a shortcut around a named requirement.
Where it earns its place: framework applications and larger contracts routinely ask security-assurance questions that go well past the five technical control areas Cyber Essentials covers — governance, risk management, supplier management, business continuity, incident response. A management system answers those, and answering them from an existing ISMS is a different exercise from assembling them per bid.
It also travels. A supplier selling to government, to enterprise and possibly abroad needs one security story, and ISO 27001 is the one that is recognised across all three. Cyber Essentials is a UK scheme and does not carry the same weight outside the UK.
The honest summary: Cyber Essentials to be eligible, ISO 27001 to be competitive and to answer the questions Cyber Essentials does not reach.
Scope, subcontractors, and the question that comes after award
Two things trip suppliers up after the certificate exists.
The scope on the certificate has to cover the work. A certificate scoped to one product line does not evidence controls over a different service you have just bid to deliver. Assurance reviewers read the schedule, and in public procurement they are frequently obliged to.
Your own supply chain is part of the answer. The policy exists because of supply chain risk, so expect to be asked what you require of your subcontractors. Annex A supplier controls are exactly this, and if you are certified you should be able to answer from evidence rather than from memory. A folder of supplier certificates that nobody has checked for currency or scope is a common and avoidable finding — and certificates issued against the withdrawn 2013 edition of the standard stopped being valid in October 2025.
Bid timelines and certification timelines do not fit together
The requirement is evidence before contract award. Set that against how long certification actually takes and the problem is obvious: for most suppliers, a tender that lands with a certification requirement has already landed too late.
ISO 27001 has a floor that money does not move. Clause 9.2 requires an internal audit and clause 9.3 a management review, and both need the management system to have been running long enough to produce something worth examining. On top of that, Stage 1 and Stage 2 are separate visits booked around your certification body’s availability, and the certificate itself follows some weeks after the last audit day once the body completes its own review.
Cyber Essentials is much faster, which is another reason it is the sensible first move for a supplier starting cold. The basic level is a verified self-assessment and turns around quickly. Cyber Essentials Plus adds a hands-on technical audit by the assessment body and has to be scheduled, so it is the one most likely to miss a deadline that felt comfortable when the tender arrived.
Which makes this a pipeline question rather than a compliance one. If public sector work is part of your plan, the certification you will need is decided by the framework you intend to bid into, and that is knowable months before a specific opportunity appears. Read the framework’s requirements now. Suppliers who treat certification as something to arrange once a tender is in front of them are the ones who end up asking whether ISO 27001 can be substituted for something they should already have had.
What this does not change
Whatever sits on top, the arithmetic underneath is the same for every sector. Audit days come from ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) and are a function of the people inside your scope, your sites and your complexity. Surveillance is one third of the initial audit every year and recertification is two thirds in year three. Your certification body cannot be your consultant, and cannot do the internal audit clause 9.2 requires.
Work out the cost for your headcount, or see the full audit-day table.
Common questions
Does ISO 27001 satisfy PPN 014?
Sometimes, and it is the contracting authority's call rather than yours. The policy requires Cyber Essentials or Cyber Essentials Plus, or equivalent, before contract award for in-scope contracts. Whether your ISO 27001 certificate counts as equivalent is decided by the buyer, and some buying organisations say explicitly that it does not. Read the specific requirement and, if it is ambiguous, submit a formal clarification question.
Which contracts is it actually mandatory for?
It is not a blanket rule for every public contract. It applies where the tender or framework specifies it, which covers most central government procurement and a great deal of wider public-sector procurement involving personal data or ICT services. The requirement will be stated in the tender documents; that is the authoritative source for your bid, not any general summary.
We have ISO 27001 but not Cyber Essentials. What is the quickest fix?
Cyber Essentials is a verified self-assessment against five technical control areas, with a published fee by organisation size and a short turnaround. If you hold ISO 27001 you will already satisfy most of what it asks, so it is usually a matter of evidencing rather than implementing. Cyber Essentials Plus adds a technical audit and takes longer, so if the contract requires Plus, start earlier than you think you need to.
Do our subcontractors need it too?
Frequently, and the tender will say. The whole point of the policy is supply chain risk, so expect flow-down requirements and expect to be asked how you assure them. If you are certified to ISO 27001, the Annex A supplier controls are where that evidence lives, and it needs to be current rather than a folder assembled once.
Is Cyber Essentials Plus much harder than the basic level?
It is the same five control areas, assessed differently. The basic level is a verified self-assessment; Plus adds a hands-on technical audit by the assessment body, including testing of a sample of devices. Organisations that genuinely operate the controls usually find Plus to be scheduling and evidence work rather than new implementation. Organisations that answered the self-assessment optimistically find out at that point.
Sources cited on this page
- PPN 014: Cyber Essentials Scheme (Cabinet Office procurement policy note)
- IASME, Cyber Essentials certification fees
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Get a costed answer, not a call-back to discuss pricing
Five questions, all of them click-only. Your details are the last step, never the first.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.