Skip to content
Cyber Essentials Checker

Cyber Essentials checker: verify a supplier’s certificate — and know what to do if it’s expired or missing

Free supplier-due-diligence guide. Search the official IASME / NCSC register to confirm a UK organisation holds a current Cyber Essentials or Cyber Essentials Plus certificate, read the result correctly, and handle the three awkward outcomes: expired, not listed, or a scope that doesn’t cover your contract.

Quick answer: The only official Cyber Essentials checker is the IASME certificate register. Search by company name or, better, certificate reference number; the result shows the level (CE or CE Plus), issue and expiry dates, scope and assessor. Certificates last 12 months and drop off the register when they lapse, so no result means the supplier is not currently certified — see what to do next.

Search the official IASME register

The authoritative list of valid certificates is maintained by IASME for the NCSC. Click below to open the official search in a new tab — type a company name or certificate reference number to verify.

How to check if a company has Cyber Essentials

The IASME register only shows certificates issued in the last 12 months — certificates expire annually and drop off when the holder doesn’t renew. Follow these four steps to verify any UK organisation.

1

Open the IASME register

Use the link above. The official URL is iasme.co.uk/cyber-essentials/ncsc-certificate-search — bookmark it for repeat checks.

2

Search by name or certificate ref

Type the exact registered company name. If you have it, the certificate reference number is more reliable — trading names, parent companies and abbreviations can hide a valid certificate.

3

Expand the result

Click the + icon to reveal the full certificate detail: level (CE or CE Plus), issue date, expiry date, scope and the assessor body that signed it off.

4

Check four things

(1) Level matches the requirement; (2) expiry date is in the future; (3) scope covers the part of the business you’re contracting; (4) the certificate reference matches anything they’ve sent you.

What the search results mean

Every entry in the IASME register has the same fields. Here’s how to read them and what to flag during supplier due diligence.

FieldWhat it meansWhat to check
Company NameThe legal entity the certificate was issued to.Match it to the entity on the contract or invoice. Trading names won’t appear if certified under a parent company.
Certificate ReferenceUnique identifier (e.g. CE-2026-1234567). Issued by IASME at the point of certification.Most reliable way to verify — ask the supplier for it directly and search by reference.
Certificate LevelCyber Essentials (self-assessment, IASME-marked) or Cyber Essentials Plus (independent technical audit).For UK government, MoD, NHS and most enterprise contracts you specifically need CE Plus.
Certification DateThe day the certificate was issued.Confirms how long they’ve been certified. CE Plus year-on-year is a stronger signal than first-time CE.
Certification ExpiryAlways 12 months after issue. Certificates do not auto-renew.If expiry is <30 days away, ask the supplier when they will recertify. If it’s in the past, the certificate is no longer valid.
ScoreNumerical score from the assessor (CE Plus only).Higher is better, but pass/fail is the binding outcome.
ScopeThe part of the business the certificate covers (whole-org, division, specific systems).Critical: "Whole organisation" is the gold standard. A narrow scope may exclude the team or system you’re contracting.

What if the search returns nothing?

No result doesn’t always mean “not certified”. Five common reasons:

  1. The certificate has expired (12-month lifespan, no auto-renewal).
  2. They’re certified under a different legal name — ask for the entity on the certificate.
  3. Different spelling, abbreviation or punctuation in the company name.
  4. Their certificate is more than 12 months old and they haven’t renewed.
  5. They never held a certificate — or it was withdrawn.

Always ask the supplier for the certificate reference number and search by that — it removes every ambiguity.

Expired or missing certificate: what to do

  1. Treat a lapsed certificate as no certificate. The register only lists certificates issued in the last 12 months, so an expired entry gives you no current assurance.
  2. Ask for the certificate PDF and reference number in writing, plus the renewal date if they say a reassessment is under way.
  3. Check the scope on any certificate they send. “Whole organisation” is what you want; a narrow scope may exclude the team delivering your work.
  4. Make certification a contract condition with a deadline, and keep a dated screenshot of the register result in your supplier file.
  5. If they need to get certified, point them at a managed service: our managed Cyber Essentials is from £103/month ex VAT and most clients are certified inside four weeks.

Free supplier due-diligence checklist

  • Got the supplier’s certificate reference number?
  • Verified the entity name matches your contract?
  • Confirmed Level (CE or CE Plus) matches your contract requirement?
  • Expiry date is > 30 days in the future?
  • Scope covers the team / systems you’re contracting?
  • If due to expire, asked when they’ll recertify?
  • For high-risk suppliers: requested a copy of their certificate PDF?
  • Stored screenshot / PDF in your supplier file with the date you verified?

Cyber Essentials verification — FAQs

Common questions from procurement teams, security managers and contract owners verifying suppliers’ Cyber Essentials status.

How do I check if a company has Cyber Essentials?
Search the official IASME Cyber Essentials register at iasme.co.uk/cyber-essentials/ncsc-certificate-search. Type the registered company name (or, more reliably, the certificate reference number the supplier sent you). The register lists every UK organisation holding a current Cyber Essentials or Cyber Essentials Plus certificate issued in the last 12 months — expired certificates drop off automatically. There is no other public “Cyber Essentials check” or “certificate search” tool; IASME is the only authoritative source.
Is the IASME register the only official source for Cyber Essentials verification?
Yes. IASME is the NCSC’s sole Cyber Essentials Delivery Partner and maintains the only authoritative register. The NCSC’s own page at cyberessentials.ncsc.gov.uk/cert-search redirects you to the IASME search.
Can I verify a Cyber Essentials certificate by certificate number alone?
Yes — the IASME search accepts both company name and certificate reference number. Searching by certificate number is the most reliable way to verify because it removes ambiguity from trading names and abbreviations.
How long is a Cyber Essentials certificate valid?
Twelve months from the issue date. Certificates do not auto-renew — the holder must complete the assessment again before expiry. Once a certificate expires it stops appearing in the IASME register.
What’s the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment marked by an IASME assessor. Cyber Essentials Plus adds an independent technical audit — an external vulnerability scan, internal authenticated scan of a sample of every device type, and email/web malware tests. UK government and MoD contracts almost always require CE Plus. See our full breakdown of CE vs CE Plus.
What if a supplier’s scope is “not whole organisation”?
A narrow scope means the certificate only covers part of the business. Confirm in writing that the team, location or systems delivering your contract are inside the certified scope. If they’re not, the certificate provides you with no real assurance for that work.
What does it mean if a supplier’s Cyber Essentials certificate has expired?
The supplier is not currently certified. Certificates last 12 months, do not auto-renew and drop off the IASME register when they lapse. Ask for their reassessment date in writing, make certification a contract condition, and treat them as uncertified until a new certificate appears on the register.
What should I do if my supplier is not on the Cyber Essentials register?
First rule out a naming problem: ask for the certificate reference number and the exact legal entity certified, then search again. If there is still no result, the supplier does not hold a current certificate. Ask for the certificate PDF, set a deadline for certification in the contract, and record the check in your supplier file.
Can I bulk-verify a list of suppliers?
Yes — IASME offers a paid Supplier Check tool for organisations checking large numbers of suppliers and contractors. Onboarding involves a verification process and a fee. For one or two checks, the free search is fine.
I need to get our own organisation Cyber Essentials certified — what now?
We run a fully managed Cyber Essentials and CE Plus service for UK SMEs from £103/month ex VAT — we deploy our compliance agent across every device, automate the five technical controls, submit your IASME-validated assessment and renew the certificate annually. Get a fixed-price quote, or read the full service description.

Need to get certified yourself?

If checking a supplier just made you realise your own business needs Cyber Essentials, our managed service is from £103/month ex VAT and most clients are certified inside four weeks. Fixed price, fully managed, with the £25k cyber-liability insurance that comes with certification.

Get my Cyber Essentials quote →
Sitemap
Get an IT Quote 0333 015 2615