G-Cloud 15: The Cyber Essentials Requirements for Every Lot

G-Cloud 15: The Cyber Essentials Requirements for Every Lot

By EJN Labs · 17 Jun 2026 · 9 min read

G-Cloud 15 Cyber Essentials is mandatory across every lot from 5 December 2025: basic Cyber Essentials for Lots 2a, 2b and 3, and Cyber Essentials Plus for Lots 1a and 1b. Subcontractors handling personal or OFFICIAL data also need CE. With award anticipated 17 September 2026, valid certificates are needed through the first half of 2026.

If you are bidding on the new cloud framework, the G-Cloud 15 Cyber Essentials requirement is no longer a nice-to-have. This guide tells you exactly which certificate each lot needs, how the rule flows down to your subcontractors, and the lead time to certify before the framework goes live. For how this fits wider public-sector procurement, see our public-sector penetration testing page.

What the G-Cloud 15 Cyber Essentials rule actually says

A current Cyber Essentials certificate is a condition of being on the G-Cloud 15 framework, not an optional differentiator, as the Crown Commercial Service (CCS) has confirmed. G-Cloud 15 (G15) is the successor cloud-services framework run by CCS, replacing G-Cloud 14 and Cloud Compute 2 under the Procurement Act 2023.

The framework is the route public-sector buyers use to buy cloud hosting, software and support without running a full tender each time, and it has five lots.

The requirement is tiered by lot. The two infrastructure lots, which carry the highest risk because they host the customer’s data and workloads, require Cyber Essentials Plus; the software and support lots require basic Cyber Essentials. On top of that, suppliers must make sure any subcontractor that processes personal data or data classified at OFFICIAL also holds Cyber Essentials, a clause most suppliers miss that can pull two or three other companies into a deadline they did not plan for.

Which certificate does each G-Cloud 15 lot need?

Here is the practical mapping, lot by lot. Find the lot you are bidding on, confirm which certificate it needs, and check whether any subcontractor in your delivery chain touches personal or OFFICIAL data.

LotWhat it coversCertificate you need to bid
Lot 1aCloud hosting (IaaS / PaaS)Cyber Essentials Plus
Lot 1bCloud hosting above OFFICIAL (defence and security)Cyber Essentials Plus
Lot 2aInfrastructure softwareCyber Essentials (basic)
Lot 2bCloud software (SaaS)Cyber Essentials (basic)
Lot 3Cloud supportCyber Essentials (basic)
SubcontractorProcessing personal or OFFICIAL dataCyber Essentials (basic)
G-Cloud 15 Cyber Essentials requirements by lot, confirmed by CCS on 5 December 2025. The infrastructure lots (1a and 1b) require the hands-on Cyber Essentials Plus audit; the software and support lots require basic Cyber Essentials.

The split is risk-based: Lots 1a and 1b put your platform underneath someone else’s workloads, so CCS wants the independent, hands-on assurance of Cyber Essentials Plus. The Plus-for-1a/1b decision drew anti-SME criticism, because Plus is a higher bar for a small cloud vendor, but the requirement stands. If you bid on more than one lot, satisfy the highest requirement that applies.

The G-Cloud 15 timeline and why H1 2026 is the deadline

The dates are what make this urgent. The tender was published on 23 October 2025, supplier submissions were due by 30 January 2026, and the framework award is anticipated for 17 September 2026. Certificates are valid for twelve months, so the practical window to certify or recertify runs through the first half of 2026.

DateMilestoneWhat it means for your certificate
23 Oct 2025Tender publishedCE requirement set in framework terms
5 Dec 2025CCS confirms CE mandatory, CE Plus for 1a/1bThe rule is live
30 Jan 2026Supplier submissions dueDeclare your certification position
H1 2026Certify or recertify windowBest time to sit CE or CE Plus
17 Sep 2026 (anticipated)Framework awardValid certificate must be in place
G-Cloud 15 timeline. Certificates last twelve months, so certifying in the first half of 2026 keeps you valid through the anticipated September 2026 award.

One detail to plan around: the Cyber Essentials scheme updated in April 2026, with multi-factor authentication mandatory for in-scope cloud services and an automatic fail if it is missing. If you certify in the first half of 2026 you are assessed against the current question set, so evidence MFA across your administrative and user accounts first. This matters even more for the infrastructure lots, because the Cyber Essentials Plus audit verifies MFA on your real systems rather than taking your word for it.

Cyber Essentials vs Cyber Essentials Plus on G-Cloud 15

Both levels test the same five technical controls, but they verify them differently:

  • Cyber Essentials (basic), for Lots 2a, 2b and 3. A self-assessment questionnaire that an assessor reviews, with no hands-on audit.
  • Cyber Essentials Plus, for Lots 1a and 1b. Everything in basic CE plus an independent, hands-on technical audit: an external vulnerability scan, an authenticated internal scan on a device sample, malware and configuration tests, and MFA verification. The pass threshold is no vulnerability scoring CVSS 7.0 or above.

For a fuller breakdown of where the line sits between the two levels in a government-procurement context, including the PPN 014 rules that govern central-government and NHS contracts, see our guide to Cyber Essentials vs CE Plus for government contracts.

Lead time: how long does it take to get certified?

The assessment is quick but the readiness is not, and that is where suppliers run out of runway. Basic Cyber Essentials can be turned around in days if your controls already meet the standard. The risk is remediation: unsupported software, missing patches or no MFA all have to be fixed before you pass, which can stretch a few-day exercise into a few weeks.

Cyber Essentials Plus needs more planning. You need a current basic CE certificate first, the Plus audit has to be booked, and any vulnerability scoring CVSS 7.0 or higher has to be remediated before you pass. From a standing start, treat Plus as a several-week project, and run a readiness scan before the formal audit so you fix problems on your schedule rather than on assessment day. Working back from a September 2026 award, that work wants to be underway in the first half of 2026.

Do not forget your subcontractors

Any subcontractor that processes personal or OFFICIAL-classified data on your behalf must also hold Cyber Essentials under G-Cloud 15. The subcontractor clause turns one certification into several: if a third party provides hosting, data processing, support or analytics for your SaaS product and touches in-scope data, they need certifying too.

Map your delivery chain now, not the week before award, because a subcontractor starting from scratch faces the same lead time you do.

This subcontractor flow-down is a recurring theme across UK public-sector procurement, and the NHS applies the same supplier-assurance logic beyond G-Cloud. If you also sell into the health sector, our security-assurance checklist for selling software to the NHS walks through the parallel set of certificates and evidence NHS buyers expect.

Why EJN Labs for G-Cloud 15 readiness

G-Cloud 15 asks a cloud supplier to produce two things: a valid Cyber Essentials or Cyber Essentials Plus certificate, and the technical-security evidence that underpins it. EJN Labs covers both in one engagement. We are a Cyber Essentials and Cyber Essentials Plus certification body through our IASME relationship, so we assess and certify directly rather than handing you off, and we are CREST members for penetration testing, the recognised quality signal public-sector buyers and assessors look for. We are also ISO 27001 and ISO 9001 certified, so we run your audit from the position of an organisation that lives by the same controls.

For the infrastructure lots, that combination matters. The Cyber Essentials Plus audit overlaps heavily with vulnerability scanning, and the cleanest way to pass first time is to find and fix the CVSS 7.0-and-above issues before the assessor arrives. When we scope a G-Cloud 15 readiness engagement, we start with an external scan of your internet-facing estate and an authenticated internal scan on a device sample, exactly the surfaces the Plus audit checks, then run the formal certification once the gaps are closed. We routinely catch the same blockers, missing MFA on an admin console, an unsupported operating-system build, or a forgotten internet-facing service, which is precisely why a readiness pass saves a failed first attempt.

All of this is delivered by UK-based senior and principal testers; we do not put junior or associate practitioners on client engagements. Pricing is fixed against a written scope agreed up front from your device count, cloud footprint and the lots you are bidding on, so the figure you approve is the figure you pay. Where a scoped vulnerability assessment or penetration test sits alongside the certification, it is priced on tester days at a typical UK day rate of around £1,200, with the exact figure coming from your scope.

Frequently Asked Questions

Is Cyber Essentials mandatory for G-Cloud 15?

Yes, Cyber Essentials is mandatory across every G-Cloud 15 lot, as the Crown Commercial Service confirmed on 5 December 2025. Basic Cyber Essentials is required for Lots 2a, 2b and 3, and Cyber Essentials Plus is required for the infrastructure Lots 1a and 1b.

Suppliers must also ensure that any subcontractor processing personal or OFFICIAL data on their behalf holds Cyber Essentials.

Which G-Cloud 15 lots need Cyber Essentials Plus?

Lots 1a and 1b, the cloud hosting (IaaS and PaaS) lots, require Cyber Essentials Plus. The software and support lots, 2a, 2b and 3, require basic Cyber Essentials only. If you bid on more than one lot, you must satisfy the highest requirement that applies.

Lot 1b covers hosting above the OFFICIAL classification for defence and security.

When do I need my certificate by for G-Cloud 15?

By the framework award date, anticipated for 17 September 2026, you need a current Cyber Essentials certificate in place. Certificates are valid for twelve months, which means the practical window to certify or recertify runs through the first half of 2026.

Supplier submissions were due 30 January 2026, and certification involves readiness and remediation time, so do not leave it late.

Do my subcontractors need Cyber Essentials for G-Cloud 15?

Yes, if they process personal data or data classified at OFFICIAL on your behalf. G-Cloud 15 requires suppliers to ensure those subcontractors also hold Cyber Essentials, so map your delivery chain early rather than discovering a gap close to award.

A subcontractor certifying from scratch faces the same readiness and remediation lead time you do, and a late start can put your bid at risk.

How much does G-Cloud 15 certification and readiness cost?

Costs split three ways: the basic Cyber Essentials fee is fixed nationally by IASME and banded by organisation size, the Cyber Essentials Plus audit fee is set by the certifying body and scales with the size of your estate, and supporting testing is priced on tester days at £1,100 to £1,400 per day.

That day-rate line covers any scoped vulnerability assessment or penetration test that supports the audit. We return a fixed-price figure from your written scope, so request a quote for an exact number.

Get a fixed-price G-Cloud 15 readiness quote

Tell us which G-Cloud 15 lots you are bidding on, your device count and your cloud footprint, and we will return a fixed-price quote for the Cyber Essentials or Cyber Essentials Plus certification you need, with a readiness scan to keep your first attempt clean. No obligation and no sales pipeline, just a clear figure from a CREST member and Cyber Essentials Plus certification body, delivered by UK-based senior and principal testers.

Leave a Reply

Your email address will not be published. Required fields are marked *