Cyber Essentials Certificate Checker
Check whether any UK company holds a live Cyber Essentials or Cyber Essentials Plus certificate. Enter the company name and we take you straight to the official IASME register — the single source of truth for UK certification — with nothing to sign up for.
Quick answer
To check a company's Cyber Essentials certification, search the official register operated by IASME on behalf of the National Cyber Security Centre. It is free, needs no account, and is searchable by company name, postcode or certificate number. The register lists certificates issued in the last 12 months — Cyber Essentials certificates expire after a year, so anything older is no longer current.
Check a Cyber Essentials certificate
Enter the company name exactly as registered. We copy it for you and open the official IASME register — the single source of truth for live UK Cyber Essentials certification — in a new tab.
Opens the official IASME certificate search in a new tab. The register lists certificates issued in the last 12 months, searchable by company name, postcode or certificate number.
How the check works
Enter the company name
Use the registered company name where you can — trading names and abbreviations are the most common reason a genuinely certified company appears missing.
Check the official record
We copy the name for you and open the official IASME certificate search in a new tab. The result you see there is the live record: certification level, certifying body and expiry.
Act on what you find
Certified? Note the level and expiry date for your supplier file. Not listed? Ask the supplier directly — and decide whether certification becomes a condition of doing business with you.
What the official register tells you
Certification level
Whether the organisation holds Cyber Essentials (verified self-assessment) or Cyber Essentials Plus (independently audited) — an important distinction if you are vetting a supplier for a sensitive contract.
Certificate currency
Certificates are valid for 12 months, and the register only lists certificates issued in the last 12 months. A supplier who "has Cyber Essentials" from two years ago is not currently certified.
Three ways to search
Search by company name, postcode or certificate number. If a supplier has given you a certificate number, checking it against the register confirms the certificate is genuine and current.
Procurement evidence
Certain UK government and MoD contracts require Cyber Essentials, and larger private-sector buyers increasingly demand it through supplier questionnaires. The register is the evidence trail.
Checking only — by design
The register's terms restrict its use to checking certification. That is why this tool links you to the official search rather than scraping or republishing the data.
Certified ourselves
AMVIA holds Cyber Essentials Plus and prepares UK businesses for both tiers — including the remediation work that comes before the questionnaire.
Why check a supplier's Cyber Essentials certificate?
Most Cyber Essentials checks are supply-chain checks: a customer confirming that a supplier who claims certification actually holds it, and that the certificate is still in date. Supplier security questionnaires, cyber insurance applications and public-sector tenders all increasingly turn on this one question, and the answer takes under a minute to verify against the official record. If you are new to the scheme itself, start with our complete Cyber Essentials guide.
What the register shows — and what it doesn't
The official search, operated by IASME on behalf of the National Cyber Security Centre, returns the organisation's name, certification level (Cyber Essentials or Cyber Essentials Plus) and certificate details, and it only lists certificates issued in the last 12 months. It does not show expired history, and it says nothing about the scope the organisation chose to certify — a supplier can legitimately certify a subset of its business, so for sensitive contracts it is worth asking what the certificate covers.
What it means if a supplier isn't listed
Three explanations, in descending order of likelihood: the name you searched doesn't match the name they certified under (try the registered company name from Companies House); their certificate has lapsed — Cyber Essentials expires every 12 months and lapsed certificates simply drop off the register; or they were never certified. Whichever it is, the next step is the same: ask the supplier for their certificate number and check it against the register. A certified supplier can always produce a number that verifies.
Vetting multiple suppliers?
If you are working through a supplier list rather than a single check — onboarding requirements, insurer conditions, or a customer pushing certification down the chain — the manual approach doesn't scale well, and the harder question is usually what to do with the suppliers who fail. AMVIA helps UK businesses set a certification bar for their supply chain, get their own Cyber Essentials certification in place, and remediate the gaps that stop suppliers passing. As a managed IT provider holding Cyber Essentials Plus ourselves, we handle the technical controls, the evidence and the questionnaire — talk to us before you send fifty chasing emails.
Cyber Essentials resources
Cyber Essentials: the complete guide
What the scheme is, the five controls it verifies, and how certification works when an MSP handles remediation.
Cyber Essentials cost
2026 assessment fees by organisation size, what Plus audits cost, and the remediation budget most guides skip.
Cyber Essentials vs Plus
Same five controls, different proof. Which tier enterprise and government buyers actually demand.
All free security tools
The full toolkit: attack surface scan, readiness assessments, certificate checker and more.
Free email security scan
Vetting suppliers usually starts because someone is vetting you. Run a free scan and see in seconds how exposed your own domain is to spoofing and phishing — real DNS checks, plain-English results.
Need Cyber Essentials yourself?
AMVIA prepares UK businesses for Cyber Essentials and Cyber Essentials Plus — remediation first, then certification, handled by a provider that holds Plus itself.
Cyber Essentials certification check — questions
Search the official certificate register operated by IASME on behalf of the NCSC. It is free, requires no account, and is searchable by company name, postcode or certificate number. The tool on this page takes the company name you enter and opens the official search for you — the result you see there is the authoritative record.
Yes. The official IASME certificate search is free and public, with no login required. Its terms restrict use to checking certification — it must not be used for marketing or data research, which is why no third-party tool should scrape or republish it.
Twelve months. Certification is an annual cycle: the organisation re-answers the assessment questionnaire (and re-sits the audit, for Plus) every year. The public register only lists certificates issued in the last 12 months, so a lapsed certificate disappears from it.
Usually one of three reasons: you searched a trading name rather than the name they certified under; the certificate has expired and dropped off the register; or the organisation was never certified. Ask the supplier for their certificate number — a currently certified organisation can always give you a number that verifies against the register.
Both certify the same five technical control themes. Cyber Essentials is a verified self-assessment — the organisation answers the questionnaire and a qualified assessor reviews it. Cyber Essentials Plus adds an independent technical audit, with tests run against a sample of the organisation's actual systems. For higher-risk suppliers, Plus is the stronger evidence.
First confirm it with them directly — register misses are often name mismatches or lapsed renewals. If they are genuinely uncertified, decide whether certification is a condition of the relationship, and give them a reasonable deadline: Basic certification is achievable in weeks for a well-run IT estate, and an MSP can handle the remediation and assessment end to end.
Certain UK central government and MoD contracts require suppliers to hold Cyber Essentials — particularly where the work involves handling certain government or personal data. Many prime contractors flow the requirement down to subcontractors, which is how the scheme spreads through supply chains.
Yes — AMVIA holds Cyber Essentials Plus, the audited tier of the scheme. We also prepare UK businesses for their own certification, including the remediation work (MFA, patching, access control, firewall configuration) that comes before the questionnaire.