BLOG
September 28, 2026
decorative
Travis Good

UK Buyer Asked for Cyber Essentials - Does SOC 2 Count, and What Changed in April 2026?

SOC 2 does not replace UK Cyber Essentials for UK bids. Non-UK SaaS can certify remotely - April 2026 MFA and EOL rules, plus G-Cloud 15 stakes.
Illustration for UK Cyber Essentials certification for US SaaS selling into the UK

A UK public-sector or enterprise buyer drops Cyber Essentials into a security questionnaire or tender pack. You already hold SOC 2 - maybe ISO 27001 too. The instinctive reply is that your US attestation should cover it. For UK government procurement and a growing set of UK primes, that reply is wrong, and it can end the bid before diligence starts.

This post is for US and other non-UK SaaS founders, Heads of Sales, and compliance owners selling into UK public sector, NHS, MoD supply chain, or UK enterprises that put Cyber Essentials on questionnaires - especially teams that already invested in SOC 2 or ISO and need a clear read on what else is required. If you are searching for how Cyber Essentials SaaS deals actually work for a non-UK vendor, the short version is below: what the scheme is, why SOC 2 does not substitute, what tightened on 27 April 2026, and how to show the certificate next to the attestations you already have.

Does SOC 2 count as UK Cyber Essentials?

No. UK Cyber Essentials is a distinct NCSC scheme, administered via IASME-accredited certification bodies. It is not CISA US Cyber Essentials guidance (same name, no UK procurement recognition), and it is not satisfied by SOC 2, ISO 27001, NIS2, FedRAMP, or CMMC. Forensic Control states that UK procurement teams do not accept those frameworks as a substitute; Steerlab (9 May 2026) makes the same commercial point for vendors: Cyber Essentials is the UK baseline credential buyers ask for by name.

Non-UK companies can certify. There is no requirement to be UK-registered or to keep a UK office. The certificate is issued in your organisation legal name and stands like one issued to a UK company. Assessment and Cyber Essentials Plus technical verification can run fully remotely (Forensic Control).

If a UK contract or questionnaire says Cyber Essentials, they mean the UK NCSC/IASME scheme - not a US guidance PDF and not a SOC 2 report with a different cover letter.

What are the two Cyber Essentials levels?

Steerlab (9 May 2026) and BidFinder (30 May 2026) describe two complementary levels, both valid for twelve months and renewed annually:

LevelHow it worksTypical ask
Cyber EssentialsSelf-assessment questionnaire verified by an accredited certification bodyBaseline for many supplier lots and questionnaire gates
Cyber Essentials PlusSame questionnaire plus independent technical verification (remote or on-site testing / scanning of controls)Often specified for higher-sensitivity work and for cloud hosting lots

Five technical control areas sit under both levels (Steerlab; Forensic Control):

1. Firewalls - boundary and host firewalls; block unapproved connections; change defaults

2. Secure configuration - no manufacturer defaults; unnecessary accounts/services removed

3. User access control - least privilege, account lifecycle, MFA where the scheme requires it

4. Malware protection - anti-malware or application allowlisting, kept current

5. Patch / security-update management - timely patching of high-risk updates; no unsupported software under the tightened rules

Cyber Essentials is deliberately narrow and prescriptive. It proves baseline hygiene against common commodity attacks. It does not claim to be a full information-security management system the way ISO 27001 or a SOC 2 Type 2 report does. UK enterprise buyers who are serious about diligence typically want CE alongside SOC 2 or ISO - not instead of them (Steerlab, 9 May 2026). For extending SOC 2 toward ISO when that is the next maturity step, see extending SOC 2 to ISO 27001.

What changed on 27 April 2026?

From 27 April 2026, new certifications and renewals sit under tightened rules. BidFinder (30 May 2026) summarises two commercial-critical changes; Push Security (12 February 2026) foreshadowed the MFA expansion against the NCSC/IASME update path:

1. Mandatory MFA on all cloud services the organisation uses - no exceptions. Email suites, storage, CRM, accounting, project tools, and any SaaS accessed with a business account are in play. If a service offers MFA, it must be enabled for users; if MFA is only in a higher tier, you buy and enable it; if native MFA is missing but SSO with MFA is available, that path must be used. Push Security notes that shadow apps and ghost local logins that skip MFA can fail an assessment even when your IdP dashboard looks clean. For a SaaS company, that often means inventorying every tool sales, finance, eng, and contractors touch - not only the production cloud that already sits behind Okta or Entra.

2. Zero tolerance for end-of-life software. The prior allowance for mitigating controls around unsupported software is removed for certification purposes (BidFinder). Unsupported OS versions, unpatched network firmware, and legacy apps on dead platforms fail unless they are genuinely out of scope (for example fully isolated with no internet path) - and isolation is a stopgap, not a strategy. BidFinder flags common renewal blockers such as Windows 10 after vendor end-of-support and office suites or network gear that no longer receive security updates.

Under Cyber Essentials v3.3 framing (Forensic Control): within the boundary you define, internet-connected devices are in scope; cloud services that store or process business data cannot be excluded. Scope design for a multi-country SaaS (whole org vs UK-facing subset) is still allowed, but the boundary has to be honest and procurement-defensible.

If your current certificate predates April 2026, treat renewal as a MFA inventory + EOL cleanup project, not a rubber-stamp questionnaire. That is the work that usually blocks renewals more than the five control labels themselves.

When do UK buyers ask for Cyber Essentials?

Non-UK suppliers hit the requirement in predictable places (Forensic Control; BidFinder; Steerlab):

  • UK central government - contracts involving personal data or IT products/services (PPN lineage; BidFinder also notes PPN 01/25 for contracts over GBP 5 million from April 2025). Without a valid certificate, bids can be excluded.
  • MoD / defence supply chain - baseline CE (some contracts specify Plus); international tier-2/3 suppliers are not exempt.
  • NHS and broader UK public sector - frameworks and onboarding that treat CE (and often Plus for IT/digital/data) as a supplier gate.
  • UK private-sector primes - banks, insurers, and enterprise buyers increasingly mirror the public baseline in questionnaires even when statute does not name you.

G-Cloud 15 (launching September 2026 per BidFinder): Cyber Essentials for supplier lots; Cyber Essentials Plus for cloud hosting lots. If you plan to list, start Plus remediation early - technical findings can take weeks to clear. Treat that as a calendar gate on your UK public-sector roadmap, not a last-week scramble after the lot application opens.

No invented win-rate or tender-volume stats belong here. Treat the buyer invitation to tender and your chosen certification body scope rules as the legal source of truth for any one deal. Your SOC 2 Type 2 period and ISO surveillance cycle remain valuable for US and global enterprise buyers; they simply do not fill the UK CE checkbox on their own.

How does Cyber Essentials compare to FedRAMP, CMMC, and NIS2?

Same foreign buyer asked for a country artifact family - different country and different artifact. Do not answer a UK CE question with a US federal or EU narrative.

ArtifactGeographyWhat it isSibling reading
UK Cyber Essentials / PlusUK bids and questionnairesNCSC baseline cert via IASME bodies; annualThis post
FedRAMPUS federal cloudUS authorization programFedRAMP 20x cost
CMMCUS defense supply chainMaturity model for DoD contractorsSOC 2 vs CMMC | CMMC
NIS2EUDirective on essential/important entities + supplier diligenceNIS2 for US SaaS

Holding FedRAMP or answering NIS2 Article 21 questionnaires does not produce a UK Cyber Essentials certificate. Holding CE does not authorize US federal cloud use. Keep the stacks separate in RFPs and Trust Center tiles.

What should you put on questionnaires and a Trust Center?

When a UK reviewer asks, answer with verifiable specifics - not we are SOC 2 compliant, so we are fine:

1. Level - Cyber Essentials or Cyber Essentials Plus

2. Certificate number

3. Issue and expiry dates (12-month clock)

4. Certifying body (IASME-accredited)

5. Verification link - point to IASME / scheme verification where the certificate can be checked independently (Steerlab)

6. Scope note - what org boundary and systems the certificate covers, especially if you certified a UK-facing subset

A one-line Trust Center blurb that only says certified without level, expiry, and body forces the reviewer to chase you in email. Put the six fields above in the same place you already publish SOC 2 and ISO artifacts so UK and US diligence can run in parallel.

Show CE next to SOC 2 and ISO as complementary evidence. Packaging that pack at scale is the same problem as every other questionnaire surge - see SOC 2 vs security questionnaires and building trust with a company trust page.

Indicative cost bands quoted in public channel pieces vary by body and size: BidFinder cites roughly GBP 300 - GBP 500 for basic CE and GBP 1,500 - GBP 5,000 for Plus; Steerlab cites similar basic bands and roughly GBP 1,500 - GBP 4,000+ for Plus. Treat those as source-attributed quotes that vary - get a current quote from your certification body for your scope. Legal and scope decisions stay with the buyer contract plus the body you choose.

Soft next step

If UK questionnaires and G-Cloud packs are asking for Cyber Essentials while your team is still answering we have SOC 2, the first commercial fix is usually a current CE (or Plus) certificate plus clean answers in every RFP. Workstreet primary help here is security questionnaire automation so level, number, expiry, and body stay consistent across UK deals. For MFA-everywhere and EOL cleanup before renewal - especially under the April 2026 rules - a Trust Center tile and vCISO ownership can keep the readiness work from landing on the founder the week before a bid. That is packaging and program help, not a claim that Workstreet issues NCSC certificates or that CE replaces SOC 2 for US buyers.

Turn compliance into a growth engine: Workstreet delivers full-stack solutions that transform security and compliance into growth accelerators. Talk to an expert →
Build trust, accelerate growth.
Workstreet offers Al-first security solutions that help high growth technology companies get compliant, scale securely, and close bigger deals.
Get started
Ready to Transform Security into a Growth Advantage
Schedule a consultation with our trust solutions experts to see how we can accelerate your security program and compliance journey.
Talk to an engineer
Travis Good

Architect of security and privacy programs for 1,000+ hypergrowth companies. Author of "Complete Cloud Compliance," HITRUST 3rd Party Council member, and recognized speaker on startup security.