Skip to content
Cyber Essentials Certificate Verifier

Verify a Cyber Essentials certificate — the official UK register

Free supplier-due-diligence tool. Search the IASME / NCSC register to confirm if a UK organisation holds a current Cyber Essentials or Cyber Essentials Plus certificate, and learn exactly what each result field means before you sign a contract.

Quick answer: Use the official IASME Cyber Essentials register to check if a UK company has Cyber Essentials. The IASME certificate search lets you look up by company name or certificate reference number — results show the certification level (CE or CE Plus), issue date, expiry, score and scope. There is no separate “Cyber Essentials checker” tool; the IASME register is the only authoritative UK source.

Search the official IASME register

The authoritative list of valid certificates is maintained by IASME for the NCSC. Click below to open the official search in a new tab — type a company name or certificate reference number to verify.

How to check if a company has Cyber Essentials

The IASME register only shows certificates issued in the last 12 months — certificates expire annually and drop off when the holder doesn’t renew. Follow these four steps to verify any UK organisation.

1

Open the IASME register

Use the link above. The official URL is iasme.co.uk/cyber-essentials/ncsc-certificate-search — bookmark it for repeat checks.

2

Search by name or certificate ref

Type the exact registered company name. If you have it, the certificate reference number is more reliable — trading names, parent companies and abbreviations can hide a valid certificate.

3

Expand the result

Click the + icon to reveal the full certificate detail: level (CE or CE Plus), issue date, expiry date, scope and the assessor body that signed it off.

4

Check four things

(1) Level matches the requirement; (2) expiry date is in the future; (3) scope covers the part of the business you’re contracting; (4) the certificate reference matches anything they’ve sent you.

What the search results mean

Every entry in the IASME register has the same fields. Here’s how to read them and what to flag during supplier due diligence.

FieldWhat it meansWhat to check
Company NameThe legal entity the certificate was issued to.Match it to the entity on the contract or invoice. Trading names won’t appear if certified under a parent company.
Certificate ReferenceUnique identifier (e.g. CE-2026-1234567). Issued by IASME at the point of certification.Most reliable way to verify — ask the supplier for it directly and search by reference.
Certificate LevelCyber Essentials (self-assessment, IASME-marked) or Cyber Essentials Plus (independent technical audit).For UK government, MoD, NHS and most enterprise contracts you specifically need CE Plus.
Certification DateThe day the certificate was issued.Confirms how long they’ve been certified. CE Plus year-on-year is a stronger signal than first-time CE.
Certification ExpiryAlways 12 months after issue. Certificates do not auto-renew.If expiry is <30 days away, ask the supplier when they will recertify. If it’s in the past, the certificate is no longer valid.
ScoreNumerical score from the assessor (CE Plus only).Higher is better, but pass/fail is the binding outcome.
ScopeThe part of the business the certificate covers (whole-org, division, specific systems).Critical: "Whole organisation" is the gold standard. A narrow scope may exclude the team or system you’re contracting.

What if the search returns nothing?

No result doesn’t always mean “not certified”. Five common reasons:

  1. The certificate has expired (12-month lifespan, no auto-renewal).
  2. They’re certified under a different legal name — ask for the entity on the certificate.
  3. Different spelling, abbreviation or punctuation in the company name.
  4. Their certificate is more than 12 months old and they haven’t renewed.
  5. They never held a certificate — or it was withdrawn.

Always ask the supplier for the certificate reference number and search by that — it removes every ambiguity.

Free supplier due-diligence checklist

  • Got the supplier’s certificate reference number?
  • Verified the entity name matches your contract?
  • Confirmed Level (CE or CE Plus) matches your contract requirement?
  • Expiry date is > 30 days in the future?
  • Scope covers the team / systems you’re contracting?
  • If due to expire, asked when they’ll recertify?
  • For high-risk suppliers: requested a copy of their certificate PDF?
  • Stored screenshot / PDF in your supplier file with the date you verified?

Cyber Essentials verification — FAQs

Common questions from procurement teams, security managers and contract owners verifying suppliers’ Cyber Essentials status.

How do I check if a company has Cyber Essentials?
Search the official IASME Cyber Essentials register at iasme.co.uk/cyber-essentials/ncsc-certificate-search. Type the registered company name (or, more reliably, the certificate reference number the supplier sent you). The register lists every UK organisation holding a current Cyber Essentials or Cyber Essentials Plus certificate issued in the last 12 months — expired certificates drop off automatically. There is no other public “Cyber Essentials check” or “certificate search” tool; IASME is the only authoritative source.
Is the IASME register the only official source for Cyber Essentials verification?
Yes. IASME is the NCSC’s sole Cyber Essentials Delivery Partner and maintains the only authoritative register. The NCSC’s own page at cyberessentials.ncsc.gov.uk/cert-search redirects you to the IASME search.
Can I verify a Cyber Essentials certificate by certificate number alone?
Yes — the IASME search accepts both company name and certificate reference number. Searching by certificate number is the most reliable way to verify because it removes ambiguity from trading names and abbreviations.
How long is a Cyber Essentials certificate valid?
Twelve months from the issue date. Certificates do not auto-renew — the holder must complete the assessment again before expiry. Once a certificate expires it stops appearing in the IASME register.
What’s the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment marked by an IASME assessor. Cyber Essentials Plus adds an independent technical audit — an external vulnerability scan, internal authenticated scan of a sample of every device type, and email/web malware tests. UK government and MoD contracts almost always require CE Plus. See our full breakdown of CE vs CE Plus.
What if a supplier’s scope is “not whole organisation”?
A narrow scope means the certificate only covers part of the business. Confirm in writing that the team, location or systems delivering your contract are inside the certified scope. If they’re not, the certificate provides you with no real assurance for that work.
Can I bulk-verify a list of suppliers?
Yes — IASME offers a paid Supplier Check tool for organisations checking large numbers of suppliers and contractors. Onboarding involves a verification process and a fee. For one or two checks, the free search is fine.
I need to get our own organisation Cyber Essentials certified — what now?
We run a fully managed Cyber Essentials and CE Plus service for UK SMEs from £103/mo — we deploy our compliance agent across every device, automate the five technical controls, submit your IASME-validated assessment and renew the certificate annually. Get a fixed-price quote in under 60 seconds, or read the full service description.

Need to get certified yourself?

If your supplier-due-diligence audit just made you realise your own business needs Cyber Essentials, we can have you fully certified in 4–6 weeks. Fixed-price, fully managed, with the £25k cyber-liability insurance included.

Get my Cyber Essentials quote →
Sitemap
Get an IT Quote 0333 015 2615