All systems operational · Ormskirk, North West England

Cyber Essentials Is Becoming a Condition of Contract in the North West

If you supply services to manufacturers, legal firms or public sector organisations in the North West, there is a reasonable chance that Cyber Essentials certification will appear in your next contract renewal. Not as a recommendation. As a requirement.

The shift has been gradual but it is now visible. Larger businesses in the region, particularly those in engineering and manufacturing who hold their own government contracts, are passing the requirement down the supply chain. If you cannot demonstrate that your business meets the Cyber Essentials standard, you may not be asked back.

What Cyber Essentials Actually Is

Cyber Essentials is a UK government-backed certification scheme. It sets out five technical controls that, if properly implemented, protect a business against the most common forms of cyber attack – phishing emails, malware, and unauthorised access to systems.

The five controls are: firewalls, secure configuration, user access control, malware protection, and patch management. None of them are exotic. Most businesses have some version of them already. The certification process establishes whether they are actually working.

There are two levels. Cyber Essentials is a self-assessment, verified externally. Cyber Essentials Plus involves hands-on technical testing by an accredited organisation. The Plus certification carries more weight with larger clients and in regulated sectors.

Why It Is Spreading Through the Supply Chain

The UK government has required Cyber Essentials for all suppliers handling personal data or providing technical products since 2014. Defence contractors have required it for longer. What has changed is the speed at which that requirement is moving into the private sector.

Insurance is part of it. Cyber liability insurers are increasingly asking about certification at renewal, and in some cases adjusting premiums accordingly. Businesses that have been through a claim, or know someone who has, are tightening their supplier requirements as a result.

The other driver is visibility. A data breach at a supplier is a data breach at the client. Businesses that hold sensitive client data – legal firms, financial services, healthcare – cannot afford to find that out the hard way.

What It Costs and How Long It Takes

The self-assessment certification costs from £300 depending on the certifying body. Cyber Essentials Plus typically runs from £1,500 upwards depending on the size of the organisation and the complexity of the infrastructure.

For most small and medium businesses, the process takes between two and six weeks from starting the gap analysis to receiving the certificate. The timeline depends largely on how much remediation work is needed before the assessment.

Blowfish Technology holds both Cyber Essentials and ISO 27001 certification. If you want to understand what a certification process would involve for your business, talk to our team.

B
Blowfish Technology

The Blowfish Technology team. Managed IT, cloud services, software development and connectivity for North West businesses since 1999.