OneClickComply
    Back to BlogCyber Essentials

    Cyber Essentials for Facilities Management (2026 Guide)

    23 August 2026
    Cyber Essentials for cleaning and facilities management firms

    TL;DR

    • Cyber Essentials for facilities management is now a standard bid requirement on NHS, council, and school cleaning contracts in 2026.
    • Self-assessment covers five technical controls and renews every 12 months; Cyber Essentials Plus adds an external audit.
    • OneClickComply automates evidence collection for Cyber Essentials, removing the manual paperwork lean FM teams get stuck on.
    • DIY self-assessment only works if someone in-house already understands firewalls and patch management — most cleaning firms don't have that person.

    Cleaning and facilities management firms increasingly need Cyber Essentials to win NHS, council, school, and corporate FM contracts — this guide breaks down the certification routes, costs, and controls that matter for your sector in 2026.

    Why This Matters

    Facilities management and cleaning contracts run on trust — your staff hold keys, access badges, and sometimes network credentials for client sites. Procurement teams know this, which is why Cyber Essentials shows up as a pre-qualification line item on more tenders every year, including many G-Cloud and NHS supply chain contracts in 2026.

    Miss it and you're out of the bid before pricing is even discussed. Get it wrong — a lapsed certificate, an incomplete self-assessment — and a renewal gap can cost you a contract renewal conversation with a client who assumed you'd stay covered.

    Check the cyber essentials certification cost in 2026 before you commit to a route, because cost and effort vary a lot between self-assessment and an assisted audit.

    Who This Is For

    This guide is for owners and operations leads at cleaning contractors, FM companies, and multi-site building services firms with 10 to 250 staff — the size band where you're big enough to bid on public sector and enterprise contracts but too lean to have a dedicated IT security team. If your business relies on subcontractors, agency staff, or a rotating workforce with shared devices, the controls below apply directly to you.

    What to Look For in Cyber Essentials for Facilities Management

    Coverage for Subcontractor and Agency Devices

    Cleaning and FM firms lean on subcontractors and agency staff more than most sectors. Cyber Essentials scope has to account for any device that connects to your business data — including phones and laptops that agency staff bring themselves. Get the scope wrong and your certificate won't hold up under a client's own due diligence check.

    Access Control for a Mobile Workforce

    Your staff log in from client sites, vans, and personal phones, not a single office network. Cyber Essentials requires proper access control and user permissions — the assessment checks that former staff and ex-subcontractors can't still log into scheduling or invoicing systems months after they've left.

    Patch Management Across Shared Equipment

    FM firms often manage building systems — access control panels, alarm systems, HVAC controllers — that sit on the same network as office devices. Cyber Essentials expects a patch management routine, and outdated firmware on a shared device is a common reason firms fail on first submission.

    Malware Protection on BYOD

    Bring-your-own-device is the norm for site supervisors and cleaning teams checking rotas on personal phones. Malware protection is one of the five core controls, and it has to extend to any device touching company data, not just company-owned laptops.

    Choosing Cyber Essentials vs Cyber Essentials Plus

    Self-assessment (Cyber Essentials) is a questionnaire; Cyber Essentials Plus adds an external technical audit of your systems. Some public sector and NHS-adjacent contracts specifically require Plus, not just the base certificate — check your target contracts before you pick a tier, because upgrading later means starting the audit process from scratch.

    Renewal Without Relying on One Person's Memory

    Cyber Essentials certificates expire every 12 months. Firms that pass once and then let renewal slip lose the certificate right when a contract renewal or new tender lands. Build a renewal date into your compliance calendar, not into one manager's inbox.

    Three Routes to Certification — and Which One Fits Your Firm

    Route 1: DIY Self-Assessment — the cheapest route

    You complete the questionnaire yourself through an IASME-accredited certification body, covering all five technical controls without external help. It's the lowest-cost path in cash terms, but it demands someone in-house who genuinely understands firewalls, secure configuration, and patch management across every device in scope.

    Most cleaning and FM firms don't have that person, and a wrong answer on the questionnaire means a failed submission and a resubmission fee. Verdict: Consider only if you already have IT expertise in-house — otherwise Skip.

    Route 2: Certification-Body-Assisted — the hand-held route

    A consultant or the certification body itself walks you through the questionnaire and helps you close gaps before submission. It costs more than pure self-assessment but cuts the risk of a failed first attempt significantly.

    This route works well for a one-off certification but doesn't solve renewal — you're back to paying for guidance again in 12 months. Verdict: Consider for a first-time certification if budget allows.

    Route 3: Automated Platform — the low-effort route for lean teams

    An automated compliance platform pulls evidence, tracks your five controls continuously, and flags gaps before the renewal deadline hits — instead of a one-time push every 12 months. OneClickComply automates the evidence collection that facilities firms otherwise chase down manually across site managers, subcontractors, and IT vendors; see how automate evidence collection for audits works in practice.

    This route costs more than pure DIY but removes the dependency on a single in-house expert and keeps you audit-ready year-round, not just in the weeks before a deadline. Verdict: Buy for facilities firms bidding on repeat public sector or enterprise contracts.

    Automate your Cyber Essentials certification

    OneClickComply handles evidence collection end-to-end so your FM team stays focused on operations.

    What to Avoid

    • Generic IT-only guidance that ignores site staff. Most Cyber Essentials content is written for office-based tech firms — it skips subcontractor devices, shared building systems, and mobile cleaning teams entirely.
    • Treating Cyber Essentials as a one-time project. A certificate earned once and left to lapse after 12 months looks worse to a procurement team than never having one, because it signals the programme wasn't maintained.
    • Skipping the scope conversation with your certification body. If subcontractor laptops or a shared building management system aren't explicitly scoped in, a client's own security review can flag a gap your certificate didn't actually cover.

    Verdict Comparison

    RouteCost PredictabilityRenewal HandlingStaff EffortBest ForVerdict
    DIY self-assessmentLow upfront, risk of resubmission feesManual, easy to missHigh — needs in-house IT knowledgeFirms with existing IT expertiseConsider/Skip
    Certification-body-assistedPredictable, higher one-off costManual, paid again each yearMediumFirst-time certificationConsider
    Automated platformPredictable, ongoingAutomated, tracked to deadlineLowFirms with repeat public sector bidsBuy

    Frequently asked questions

    One Last Thing

    Cyber Essentials Plus involves an actual technical audit, not just a questionnaire — assessors need to test your systems directly, and slots get booked up in the quarters when public sector tenders cluster. If your renewal date falls near a busy tender season in 2026, book the audit slot early rather than waiting for the certificate to lapse.

    Cyber Essentials at a glance

    5 controls

    Technical controls assessed

    12 months

    Certificate validity period

    2 tiers

    Self-assessment vs Plus audit