Cyber Essentials certificate check — how to look up any company on the register
Suppliers claim it on tenders, websites wear the badge for years, and procurement teams take it on trust. You don't have to: every current Cyber Essentials certificate is publicly searchable, free, in under a minute. Here's exactly how — and how to read what you find.
The short answer
Search the company’s name on the official IASME Cyber Essentials register — it’s free, public and needs no login. If the company appears with a certificate that hasn’t expired, they hold it; if they don’t appear, they don’t, whatever their website says. A certificate is valid for twelve months from the date shown. Everything else on this page is how to read the result and what to do about a supplier who has lapsed.
The one place that counts
The official record is the Cyber Essentials Certificate Search run by IASME, the scheme's delivery partner — the NCSC's own site points there. Find it at iasme.co.uk under Certificate Search, and search by organisation name or certificate number. It covers both Cyber Essentials and Cyber Essentials Plus. Nothing else — a logo on a website, a PDF from 2023, a line in a bid — is verification; certificates are frequently claimed long after they've lapsed, usually through forgetfulness rather than dishonesty.
Why companies “disappear” from the search
The search only returns certificates issued in the last 12 months — because that's how long a Cyber Essentials certificate is valid. This is the single most misunderstood fact in the scheme: certification is an annual event, not a lifetime award. A supplier who certified eighteen months ago and hasn't renewed is, in scheme terms, not certified, whatever their proposal says. (If you're the certified company, this is also why the renewal deserves a calendar entry — your customers can check.)
Reading the result like a buyer
Three things to note when a search comes back: the level — Cyber Essentials (verified self-assessment) or Cyber Essentials Plus (independently tested); if your contract specifies Plus, a basic certificate doesn't satisfy it (the difference explained). The date — a certificate expiring next month protects your three-year contract rather less than the badge implies; it's fair to ask about renewal intentions. The exact entity — certificates name a legal organisation and scope; “our parent company holds it” may not cover the entity you're actually contracting with (why entity details matter).
Checking a whole supply chain
Verifying suppliers one by one works to a point; for volume, IASME operates a separate Supplier Check platform for large organisations to verify certification across many suppliers at once — registration and verification required, and it exists precisely because certificate-claiming and certificate-holding are different populations.
It's rarely malice — renewal simply slipped. The productive move is a deadline, not a drama: “our supplier requirements need current Cyber Essentials; can you evidence recertification within X weeks?” Most suppliers fix it fast when a contract depends on it — recertification takes days once the controls are in place.
And if the lapsed supplier is you
Then this page is your customer's next move, which is worth sitting with for a moment. An expired certificate undoes the tender eligibility, the supply-chain standing and the free cyber liability insurance that comes with certification (included for UK organisations under £20m turnover). Renewal is a fresh assessment against the current standard — our year-two guide covers what drifts — and it's exactly the work we do at a fixed price.
Certificate lapsed — or about to?
Our free readiness check shows in five minutes whether you'd pass today's standard, before anyone — customer or insurer — checks the register. Fixed-price, done-for-you support to certification or renewal.
Take the readiness check · hello@passcyber.co.uk
PassCyber is a trading name of Edwards Bros (Spaldwick) Ltd