Notes 8 August 2026 · 5 min read

The tender wants a cyber certificate. Nobody can list what your firm runs on.

The invitation to tender lands, and somewhere in the questionnaire — between the insurance certificates and the environmental policy — sits a single line. Does your organisation hold Cyber Essentials? It gets forwarded to the chap who fixes the printers. He says yes, no bother, it’s a form.

He’s right. It is a form. Then it asks the firm to list every cloud service holding its data, and everything stops.

Because nobody knows.

What the certificate actually is

Cyber Essentials is the government’s minimum standard for cyber security, designed by the National Cyber Security Centre — the government body that deals with this sort of thing — and run day to day by a company called IASME. It covers five things, none of them exotic: a firewall between your network and the internet, computers set up sensibly rather than left on factory settings, software kept up to date, control over who can get at what, and something on the machines that catches malicious software. Locks on the doors. Not a vault.

You answer questions about your own systems, an assessor marks them, and a director signs them off. Pricing starts at £320 plus VAT and rises with the size of the business. The certificate runs twelve months, then you do it again.

It matters commercially because for some work it isn’t optional. A rule called PPN 014 — a procurement policy note, which is how government tells public buyers how they must buy things — requires departments and their agencies to see a valid certificate, or evidence of equivalent controls, before awarding contracts that involve people’s personal data, government staff data, or IT systems at official classification. It has to be spelled out in the tender notice, so you get warning. Main contractors have picked the habit up too, and it turns up in their pre-qualification questionnaires — the form a client uses to check you’re a real, solvent business before anyone reads your price.

The bit that catches firms out

The scheme is revised every year. April’s revision, applying to applications registered after the 26th, tightened three things that land squarely on a firm like yours.

Cloud services can no longer be left out. The scheme now defines one plainly: anything you reach over the internet using an account, that stores or processes your data. Dropbox. A shared mailbox. The takeoff software someone trialled. The app the site photos go into. If it holds your data it’s in scope, and you have to describe anything you’ve deliberately excluded and how it’s kept separate.

Multi-factor authentication is compulsory. That’s the one where, as well as your password, a code or a prompt goes to your phone. If a cloud service offers it — free, bundled or paid — and you haven’t switched it on, you fail. Not lose marks. Fail.

Critical security updates have to be on inside fourteen days. Operating systems, router and firewall firmware, applications, across everything in scope. Miss it and, again, automatic fail, however well you did elsewhere.

The certificate isn’t the hard part

A decent IT provider can walk a tidy firm through the whole thing in a fortnight. The difficulty sits upstream of the questions. Before you answer anything, you have to be able to say what your business runs on. In most mid-market construction firms no such list exists, and the reason it doesn’t is instructive.

The delivery tickets are photographed into a WhatsApp group on a site manager’s own phone. Six years of priced bills sit in an estimator’s personal Dropbox, because that’s where he put them when the office server filled up. A scheduling tool was signed up to on a free trial with somebody’s own email address and is still in daily use two years later, billed to a personal card and reclaimed on expenses. There’s a file server in the cupboard nobody has touched since the man who set it up moved to Spain. And if you’ve bought a business, you’ve two of everything.

The trade term for this is shadow IT: software the business depends on that the business never bought, never approved and doesn’t hold the password to. It isn’t carelessness. It’s what people do when the official system doesn’t handle the job in front of them. They route around it, and the workaround quietly becomes the process.

Cyber Essentials doesn’t create that problem. It makes you write it down. And the declaration a director signs now says the controls stay in place for the whole twelve months, not merely on the day you were assessed. Signing that when you can’t name half your systems is a poor idea, whatever the assessor concludes.

What I’d do about it

Not buy a cyber security platform. Start with an afternoon and one sheet of paper: every service the firm uses, what data is in it, whose account it sits under, who pays for it. Ask the estimators and the site managers, not the IT provider — he only knows about the things he was told about. Most firms finish that exercise with a longer list than they expected and at least one thing nobody can log into.

Then shorten the list. This is the part where I have an interest, so weigh it accordingly. The reason there are eleven services is that not one of them fits — each got signed up to because the last wouldn’t handle variations, or plant hire, or the way your firm actually prices work. Software built to how the business runs collapses several of those into one place, on accounts the company owns. The scope question stops being an archaeological dig and becomes a sentence. The certificate turns into a by-product of knowing where your own information lives.

Worth having anyway. Data in personal accounts leaves when the person does, and you find out which parts mattered a fortnight later.

Now the caveat. If you never bid for public work and no main contractor has asked, you don’t need the certificate. Buying it as a badge won’t win you work nobody required it for. And if you already run everything through Microsoft 365, multi-factor authentication is on, and an IT provider patches your machines properly, this is just form-filling. Pay the £320 and move on. Don’t let anyone talk you into rebuilding your systems to pass an audit — that’s the wrong way round. Fix the systems because they’re costing you time, and let the audit be easy as a consequence.

But if the honest answer to “what does this business run on?” is “I’d have to ask a few people,” that’s worth sorting out whether or not a tender ever asks. Get in touch.

Work with me

Recognise the pattern? Let's talk.

I take on a handful of new clients a year. If any of this echoes your business, let's start the conversation.