Cyber Security

Cyber Essentials for Engineering and Manufacturing Suppliers: What the Primes Are Actually Asking For

Two colleagues at a small UK engineering firm standing together at a workbench in their production office, looking at a laptop and a clipboard, with the company's own machine shop out of focus behind a glazed partition.
On this page

You have had the email. It came from procurement, or from a quality contact you have dealt with for years, and it says something like: all suppliers must hold current Cyber Essentials certification by the end of the quarter. There may be a PDF attached. There may be a supplier portal you now have to upload something to.

If you make things for a living, this lands awkwardly. You run a quality system. You hold accreditations that took real work. You are used to standards that come with a clause-by-clause specification and an auditor who understands your process. This one arrives as a two-line contract requirement with no explanation, and the person who sent it often cannot tell you much more than the deadline.

This article is about the part nobody explains: what the requirement actually obliges you to do, why engineering and manufacturing firms fail this when a pure office business of the same size sails through, and how to sequence the work when the clock is already running.

We are not going to walk you through the certification scheme itself. If you want that, we have written separately about what Cyber Essentials Plus involves and what changed in 2026. This is the supplier's-eye view.

Read the requirement properly before you spend a penny

Almost every expensive mistake in this process comes from acting on an assumption about what was asked for. Get the exact wording in front of you and answer four questions.

Which certification, exactly

There are two levels. Basic Cyber Essentials is a verified self-assessment. Cyber Essentials Plus adds independent hands-on technical testing by an assessor. The difference in effort, cost and lead time between them is significant, and contracts are frequently vague about which one they mean.

If the requirement just says "Cyber Essentials", ask procurement to confirm in writing whether the Plus level is required now or expected later. It is a reasonable question and it is far cheaper to ask it than to discover the answer after you have certified at the wrong level. A surprising number of requirements say Cyber Essentials this year and Cyber Essentials Plus next year, which changes how you build things now.

What "or equivalent" is doing in that sentence

Some requirements read "Cyber Essentials or equivalent". Do not assume your existing certifications cover it. Whether an alternative is accepted is a decision your customer makes, not a decision the scheme makes, and different primes treat it very differently. If you hold something you believe should qualify, put it to them explicitly and get the acceptance in writing before you rely on it.

Who the certificate has to cover

This is the one that catches people. A certificate can cover your whole organisation, or it can cover a defined part of it. Those are not the same document and they do not carry the same weight in a tender. A certificate that says it applies to a named subset of your business invites the obvious follow-up question from procurement, and you may find it does not satisfy the clause you were trying to satisfy.

Before you make any scoping decisions internally, check whether the requirement specifies whole-organisation coverage. If it does, several of the shortcuts described below are closed to you.

Whether the requirement is even your customer's

If you supply into defence, the requirement may have originated several tiers above the company that sent it to you. The Ministry of Defence uses a contractual condition, DEFCON 658, together with the Def Stan 05-138 standard, to push cyber security obligations down through the supply chain. Cyber Essentials sits at the baseline of that model and Cyber Essentials Plus is required at higher risk levels. If that is the machinery behind your letter, the prime has limited discretion to waive it, and negotiating the requirement away is not realistic. Better to know that early.

Why manufacturers fail this when office businesses pass

An accountancy practice with thirty staff, a set of laptops and Microsoft 365 can usually get through Cyber Essentials without much drama. A thirty-person precision engineering firm has a materially harder job, and it is worth understanding why, because the reasons are all fixable if you find them early enough.

The machine that runs software nobody will patch

You have a machine tool, a CMM, a laser cutter or a test rig with a controller PC attached. That PC runs an operating system version that stopped receiving security updates years ago. The OEM will not certify a newer one. Your maintenance contract may explicitly forbid you from touching it. It has been running perfectly well for a decade and nobody wants to go near it.

Cyber Essentials requires that software in scope is supported and receiving security updates. Unsupported software inside the assessment boundary is a fail. This is not a judgement call you can argue your way out of on the questionnaire.

The requirements are specific about the two ways out. All software on in-scope devices must be licensed and supported, and anything unsupported must either be removed from the device, or removed from scope by using a defined sub-set that prevents all traffic to or from the internet. A sub-set, in the scheme's own words, is part of the organisation whose network is segregated from the rest of the organisation by a firewall or VLAN.

That is the route through, and it does not require you to scrap a working machine. Note what the test actually is: not "it is on its own network", but no traffic to or from the internet at all, with a firewall or VLAN enforcing it. Partial isolation, or an outbound-only exception so the OEM can still phone home, does not meet it. Confirm the exact evidence your certification body expects before you build anything, because the boundary has to be agreed with them and this is the difference between a pass and a wasted quarter.

Engineering software that lags the operating system

CAD, CAM, PDM and ERP or MRP systems are often two or three versions behind, sometimes because a newer release breaks a post-processor or a customisation, sometimes because the licence uplift never got approved. Cyber Essentials cares about applications as well as operating systems. From the April 2026 update, questions covering the installation of high-risk and critical security updates for operating systems, firmware and applications within fourteen days of release became automatic failure conditions. One unpatched, unsupported application on an in-scope workstation can now sink the whole assessment regardless of how good everything else is.

There is a detail here that catches engineering firms specifically. The fourteen-day clock starts on any update the vendor labels critical or high risk, on anything carrying a CVSS v3 base score of 7 or above, and, crucially, on any update where the vendor gives no severity information at all. Plenty of machine tool and niche engineering software vendors publish release notes with no severity rating whatsoever. Those updates do not fall outside the rule, they fall inside it by default.

Find out now which of your engineering applications are still supported by the vendor. That is a purchasing conversation with a lead time, not an IT task you can do in the last week.

Remote access you had forgotten about

Machine suppliers often have a remote support route into their equipment for diagnostics. So do ERP vendors, calibration providers and sometimes the company that installed your access control. These connections are frequently set up once at commissioning and never reviewed. Each one is a door into your network, and each one needs to be accounted for.

Ask your maintenance and production teams a direct question: who outside this business can connect to something in this building, and how. The answers are usually more numerous than anyone expects.

Shared logins on the shop floor

The terminal by the goods-in door that everyone uses. The single account on the shop floor tablet for booking jobs on and off. The generic operator login on the cell controller. These exist for good practical reasons: gloves, speed, shift patterns, people who do not want another password.

Cyber Essentials expects individual user accounts with appropriate access. It also expects password policy to be managed in one of a small number of defined ways: multi-factor authentication in place, or a minimum password length of twelve characters, or a minimum of eight characters combined with automatic blocking of common passwords. There are workable answers for shop floor access that do not wreck your throughput, but they need designing with your production supervisors rather than imposing on them.

Cloud services you cannot leave out

The April 2026 update added an explicit definition of a cloud service and made it clear that cloud services used by your organisation cannot be excluded from the assessment scope. Multi-factor authentication on cloud services also became an automatic failure condition: if MFA is available on a service and you have not enabled it, that fails the assessment on its own.

For most manufacturers the biggest single item here is Microsoft 365. If that is your position, the practical configuration work is worth understanding in its own right, and we have covered getting Microsoft 365 into a Cyber Essentials-ready state separately.

The scoping decision that shapes the whole project

Everything above funnels into one decision, and it is a commercial decision, not a technical one. It should be made by a director, not delegated.

Option one is whole-organisation scope. Every device, every user, every cloud service, with legacy production equipment properly segregated so it sits outside the boundary. This produces the certificate that answers a procurement question cleanly, and it is the version that will still be useful when the next customer asks. It takes more work up front.

Option two is a defined subset. Faster, narrower, and it produces a certificate that names its own limits. Under the April 2026 changes you are also now required to describe the areas of your infrastructure that sit outside the scope, so the boundary is more visible than it used to be.

Be clear that a subset is not a quiet internal shortcut. The scheme requires you to agree the scope with your certification body before assessment begins, so the boundary is a conversation you will be having either way. If the point of the exercise is to satisfy a prime, a narrow certificate can create more questions than it answers.

Our view for engineering and manufacturing firms is to aim for whole-organisation scope with a properly segregated production network. Two reasons. The certificate answers a procurement question cleanly, without an appendix explaining what it leaves out, and it will still do that when the next customer asks. And the shop floor segregation work has independent value beyond certification: it limits what a ransomware incident on the office side can reach, which is the scenario that actually stops you shipping. You end up doing that work eventually. Doing it as part of a certification project means it gets funded.

If you want the structured version of what that assessment and remediation looks like, that is what our Cyber Essentials service is built around.

A realistic order of work

Assume a deadline of a quarter. The sequence matters more than the speed.

First: find out what you actually have

Not what the asset register says. What is genuinely connected, what it runs, who can reach it, and which vendors have a way in. In a manufacturing environment this always turns up surprises, and every surprise found in week two is cheap while every surprise found in week ten is not. If you want a broader framework for that kind of stocktake, our cyber security audit checklist covers the wider ground beyond certification.

Do this before you fill in a single question. The self-assessment is signed off by a board-level director who is confirming the answers are accurate, and the April 2026 declaration also asks that director to acknowledge ongoing compliance. That signature is worth taking seriously.

Second: clear the automatic failures

MFA on every cloud service where it is available. Supported and updated operating systems and applications on everything in scope. High-risk and critical updates applied within fourteen days. These are the conditions that fail an assessment outright, so they come before anything discretionary.

In parallel, start the long-lead items: the segregation design for legacy production equipment, and any vendor conversations about application versions. These are the ones with external dependencies and they will set your true finish date.

Third: individual accounts and the shop floor conversation

Removing shared logins is the change most likely to cause friction with production. Involve supervisors, pilot it on one cell, and solve the glove problem before you roll it out. Certification projects that get resented tend to get quietly undone within a year.

Fourth: submit, then keep it true

Certification is a point in time. IASME defines that point as the date the certificate is issued, which means the certificate says your controls were right that day. The value of it, and the honesty of the director declaration behind it, depends on the controls staying right afterwards. Build the patching and account management into your normal routine rather than treating it as an annual scramble, because you will be asked to renew and the requirements are tightening rather than relaxing.

What to tell your customer while you are working on it

Do not go quiet. Reply to the requirement confirming you have understood it, state the level you are certifying at, and give a target date you actually believe. Primes are generally reasonable about a supplier who has a plan and a date. They are much less reasonable about a supplier who does not respond and then misses the deadline.

If the deadline is genuinely unachievable because of a machine tool dependency with a vendor lead time, say so, with the specifics. That is a credible engineering answer and it is far better received than silence.

Where we fit

HGC IT Solutions is a UK-based managed service provider working with businesses across Dorset, including the engineering and manufacturing firms around Poole and Bournemouth. We help suppliers work out what their customer's requirement actually demands, scope it sensibly around production equipment, close the gaps that cause automatic failures, and get through certification without disrupting output.

Two things worth knowing. We hold our own in-date Cyber Essentials certificate, so we are asking you to do something we have done ourselves. And we are a Microsoft Partner and Cloud Solution Provider, which matters if Microsoft 365 is going to be a large part of your scope.

Our support is delivered by a UK-based team, and we do not tie clients into long lock-in contracts. If certification turns out to be the start of a longer conversation about how your IT is run, our managed IT support is there when you want it and not a condition of getting help with this.

If you have a supplier requirement in front of you and a date on it, send us the wording. We will tell you what it means and what it will take.

Talk to us about Cyber Essentials certification

More on Cyber Security

How to Make Your Business Cyber Essentials Compliant with Microsoft 365

How to Make Your Business Cyber Essentials Compliant with Microsoft 365

Your M365 Already Has Everything You Need for Cyber Essentials Compliance If you have been following our blog on Cyber Essentials Plus changes for 2026, you know that cybersecurity requirements are getting stricter every year. But here is the good news: your Microsoft 365 subscription already includ

Talk to a real IT team

Plain-English advice from a UK team that picks up the phone. Call 01305 310006 or email [email protected].