Why your customers are asking for Cyber Essentials
2 October 2026 · 5 min read
If a customer or tender has suddenly asked whether you hold Cyber Essentials, you are seeing supply-chain security arrive at small business level. Larger organisations have spent years securing their own systems; now their assessors, insurers and boards are asking the obvious follow-up question: what about everyone we buy from?
The logic is simple. An attacker who cannot get through a big company's defences will try its suppliers instead — the accountant with access to payment details, the designer with the brand files, the IT firm with remote access to everything. A certificate is the buyer's way of checking that the easiest way into their business is not through yours.
That is why the question appears in tenders, framework applications and renewal paperwork rather than in conversation. Procurement teams need a yes or no they can file, and Cyber Essentials gives them one: a recognised UK baseline, checked by an independent certification body, renewed every year.
The practical effect for a small firm is that the certificate has become a commercial asset. It unblocks bids that would otherwise stop at the first page of the questionnaire, it shortens security reviews, and it is increasingly the difference between making a shortlist and never hearing back.
The firms that find this painless are the ones that treat it as a standing state rather than an annual scramble. The controls — updates, access control, multi-factor authentication, supported software — are things a well-run business does anyway; the certificate just proves it.
Kept keeps that proof current all year: a free scan shows where you stand today, the evidence register builds itself month by month, and renewal reminders mean the certificate never lapses the week before a tender lands.
Kept