Cleaning and facilities management firms increasingly need Cyber Essentials to win NHS, council, school, and corporate FM contracts — this guide breaks down the certification routes, costs, and controls that matter for your sector in 2026.
Why This Matters
Facilities management and cleaning contracts run on trust — your staff hold keys, access badges, and sometimes network credentials for client sites. Procurement teams know this, which is why Cyber Essentials shows up as a pre-qualification line item on more tenders every year, including many G-Cloud and NHS supply chain contracts in 2026.
Miss it and you're out of the bid before pricing is even discussed. Get it wrong — a lapsed certificate, an incomplete self-assessment — and a renewal gap can cost you a contract renewal conversation with a client who assumed you'd stay covered.
Check the cyber essentials certification cost in 2026 before you commit to a route, because cost and effort vary a lot between self-assessment and an assisted audit.
Who This Is For
This guide is for owners and operations leads at cleaning contractors, FM companies, and multi-site building services firms with 10 to 250 staff — the size band where you're big enough to bid on public sector and enterprise contracts but too lean to have a dedicated IT security team. If your business relies on subcontractors, agency staff, or a rotating workforce with shared devices, the controls below apply directly to you.
What to Look For in Cyber Essentials for Facilities Management
Coverage for Subcontractor and Agency Devices
Cleaning and FM firms lean on subcontractors and agency staff more than most sectors. Cyber Essentials scope has to account for any device that connects to your business data — including phones and laptops that agency staff bring themselves. Get the scope wrong and your certificate won't hold up under a client's own due diligence check.
Access Control for a Mobile Workforce
Your staff log in from client sites, vans, and personal phones, not a single office network. Cyber Essentials requires proper access control and user permissions — the assessment checks that former staff and ex-subcontractors can't still log into scheduling or invoicing systems months after they've left.
Patch Management Across Shared Equipment
FM firms often manage building systems — access control panels, alarm systems, HVAC controllers — that sit on the same network as office devices. Cyber Essentials expects a patch management routine, and outdated firmware on a shared device is a common reason firms fail on first submission.
Malware Protection on BYOD
Bring-your-own-device is the norm for site supervisors and cleaning teams checking rotas on personal phones. Malware protection is one of the five core controls, and it has to extend to any device touching company data, not just company-owned laptops.
Choosing Cyber Essentials vs Cyber Essentials Plus
Self-assessment (Cyber Essentials) is a questionnaire; Cyber Essentials Plus adds an external technical audit of your systems. Some public sector and NHS-adjacent contracts specifically require Plus, not just the base certificate — check your target contracts before you pick a tier, because upgrading later means starting the audit process from scratch.
Renewal Without Relying on One Person's Memory
Cyber Essentials certificates expire every 12 months. Firms that pass once and then let renewal slip lose the certificate right when a contract renewal or new tender lands. Build a renewal date into your compliance calendar, not into one manager's inbox.
Three Routes to Certification — and Which One Fits Your Firm
Route 1: DIY Self-Assessment — the cheapest route
You complete the questionnaire yourself through an IASME-accredited certification body, covering all five technical controls without external help. It's the lowest-cost path in cash terms, but it demands someone in-house who genuinely understands firewalls, secure configuration, and patch management across every device in scope.
Most cleaning and FM firms don't have that person, and a wrong answer on the questionnaire means a failed submission and a resubmission fee. Verdict: Consider only if you already have IT expertise in-house — otherwise Skip.
Route 2: Certification-Body-Assisted — the hand-held route
A consultant or the certification body itself walks you through the questionnaire and helps you close gaps before submission. It costs more than pure self-assessment but cuts the risk of a failed first attempt significantly.
This route works well for a one-off certification but doesn't solve renewal — you're back to paying for guidance again in 12 months. Verdict: Consider for a first-time certification if budget allows.
Route 3: Automated Platform — the low-effort route for lean teams
An automated compliance platform pulls evidence, tracks your five controls continuously, and flags gaps before the renewal deadline hits — instead of a one-time push every 12 months. OneClickComply automates the evidence collection that facilities firms otherwise chase down manually across site managers, subcontractors, and IT vendors; see how automate evidence collection for audits works in practice.
This route costs more than pure DIY but removes the dependency on a single in-house expert and keeps you audit-ready year-round, not just in the weeks before a deadline. Verdict: Buy for facilities firms bidding on repeat public sector or enterprise contracts.
Automate your Cyber Essentials certification
OneClickComply handles evidence collection end-to-end so your FM team stays focused on operations.
What to Avoid
- Generic IT-only guidance that ignores site staff. Most Cyber Essentials content is written for office-based tech firms — it skips subcontractor devices, shared building systems, and mobile cleaning teams entirely.
- Treating Cyber Essentials as a one-time project. A certificate earned once and left to lapse after 12 months looks worse to a procurement team than never having one, because it signals the programme wasn't maintained.
- Skipping the scope conversation with your certification body. If subcontractor laptops or a shared building management system aren't explicitly scoped in, a client's own security review can flag a gap your certificate didn't actually cover.
Verdict Comparison
| Route | Cost Predictability | Renewal Handling | Staff Effort | Best For | Verdict |
|---|---|---|---|---|---|
| DIY self-assessment | Low upfront, risk of resubmission fees | Manual, easy to miss | High — needs in-house IT knowledge | Firms with existing IT expertise | Consider/Skip |
| Certification-body-assisted | Predictable, higher one-off cost | Manual, paid again each year | Medium | First-time certification | Consider |
| Automated platform | Predictable, ongoing | Automated, tracked to deadline | Low | Firms with repeat public sector bids | Buy |
Frequently asked questions
One Last Thing
Cyber Essentials Plus involves an actual technical audit, not just a questionnaire — assessors need to test your systems directly, and slots get booked up in the quarters when public sector tenders cluster. If your renewal date falls near a busy tender season in 2026, book the audit slot early rather than waiting for the certificate to lapse.
