The short answer
Cyber Essentials is a five-control scheme about device and account hygiene. Email authentication is not one of the five controls, and the scheme’s requirements document does not mention DMARC, SPF or DKIM at all. We checked: the current Cyber Essentials: Requirements for IT Infrastructure v3.3 (April 2026, effective 27 April 2026) contains zero occurrences of “DMARC”, “SPF”, “DKIM” or “spoof”.
That is not a criticism of the scheme. Cyber Essentials was never designed to be an email standard. The problem is that suppliers treat the certificate as evidence that their email posture has been assessed, and it has not been. The email requirements exist, they are published by the same organisation, and they live in a completely different document: NCSC’s email security and anti-spoofing guidance.
What Cyber Essentials actually requires
The scheme sets out five technical control themes, described on the NCSC Cyber Essentials overview and specified in the requirements document:
- Firewalls— “Create a security filter between the internet and your network”.
- Secure configuration— “Set up computers securely to minimise ways that a cyber-criminal can find a way in”.
- Security update management— “Prevent cyber criminals using vulnerabilities they find in software as an access point to your systems”.
- User access control— “Control who can access your data and services and what level of access they have”.
- Malware protection— “Identify and immobilise viruses or other malicious software before it has a chance to cause harm”.
Every one of those is about the machines and accounts your staff use. None of them is about what a stranger can do with your domain name. A supplier can hold a valid certificate while publishing no DMARC record at all, and nothing in the assessment would catch it.
It is worth knowing what v3.3 did tighten, because that is the part an assessor will ask about: multi-factor authentication. The requirements document states that “authentication to cloud services must always use MFA”. Cyber Essentials Plus, per the NCSC overview, covers “the same protections, but with more rigorous, independent technical testing” — the same five controls, verified rather than self-declared. Neither level adds an email authentication requirement. The current version and its effective date are published on the NCSC Cyber Essentials resources page, which is the page to check before an assessment rather than a cached PDF.
Why you are asked for Cyber Essentials anyway
Because a Cabinet Office procurement policy note says so. PPN 014: Cyber Essentials scheme replaced PPN 09/14 and PPN 09/23, and in-scope organisations were told to apply it from 24 February 2025. It “applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies”.
It bites on contracts with any of four characteristics: where a supplier handles personal information of citizens such as home addresses, bank details or payment information; where a supplier handles personal information of government employees, ministers and special advisors, such as payroll, travel booking or expenses; where ICT systems and services are supplied that are designed to store or process data at the OFFICIAL level of the Government Security Classifications Policy; and where contracts deal with information related to the day-to-day business of Government, service delivery and public finances.
On timing, PPN 014 is explicit that suppliers and in-scope organisations “should note that evidence of holding a Cyber Essentials certificate (or equivalent) is essential at the point when data is to be passed to the supplier”. In practice that means the certificate is a gate, not a report card. Passing through it says nothing about whether your domain can be spoofed tomorrow.
Where the email requirements really come from
NCSC’s email security and anti-spoofing collection is the document a public sector security questionnaire is usually derived from. Its recommended implementation plan sets out six phased steps:
- Choose an anti-spoofing management tool.
- Protect email in transit.
- Configure anti-spoofing controls.
- Send spoof emails to spam.
- Spoof emails being rejected.
- Continuous improvement.
Step one is a tooling decision, and NCSC is direct about what the tool is for: “Most of these tools will provide you with information as to whether your DMARC, SPF, DKIM and TLS configurations are correct”. Step two is transport security: “your email servers should be configured to support encryption of the communications channel that the email is sent over. This task is best handled by TLS”, and “You should also implement the email security standard MTA-STS”, which “forces all inbound email connections to use TLS”.
Steps three to five are the DMARC policy progression, and NCSC gives it in a specific order with specific dwell times. Start at p=none: “A policy of ‘none’ means this DMARC record won’t affect the delivery of your email, but it will provide you with reports on where your outbound email appears to be coming from”, a stage NCSC calls a “monitoring phase”. Move to p=quarantine “as soon as you are confident DKIM and SPF are configured correctly, and all known legitimate sources of email for your domain have been added to your records”; NCSC notes that many organisations move on from ‘none’ after about six to eight weeks and says to monitor reports for at least four weeks once quarantine is at 100%. Then p=reject: “Having a DMARC policy of ‘reject’ on all of your domains is the best way to prevent spoofing of your email”, rolled out on a rising percentage, with reports monitored closely for at least a two week period afterwards.
Read that sequence next to Cyber Essentials and the gap is obvious. The certificate asks whether your laptops are patched. The anti-spoofing guidance asks whether a criminal can send invoices in your name to the council that just awarded you a contract. Both matter; only one of them is on the certificate.
What changed on 31 March 2026
NCSC retired Mail Check and Web Check on 31 March 2026. The stated reason was market maturity: “there are many commercial EASM products widely available – most of which provide additional features and checks”, consistent with NCSC’s policy of delivering solutions only where the market cannot. NCSC recommended that organisations implement a commercial external attack surface management product before the retirement date, and published a buyer’s guide to help. Early Warning and DNS Check continue.
What that means for suppliers is a change of burden of proof. Until March 2026, a public sector buyer could look your domain up in a free central service that the buyer and NCSC both trusted. Now, if a buyer wants to know whether your DMARC posture is real, they either ask you or check it themselves. NCSC also points organisations at Check your cyber security, “a free, easy-to-use online tool to help UK organisations identify and fix common cyber vulnerabilities” that includes an Email Security Check and is aimed at small businesses, charities, schools and sole traders. It is a point-in-time check of a single domain, not continuous monitoring across an estate, so it answers “is this domain configured correctly today” rather than “who is sending mail as us this week”.
How far the buying side of the sector has actually got is measurable, and we publish it: our UK public sector DMARC tracker re-measures every domain in the official .gov.uk register and records the policy in force and whether the aggregate reports go anywhere. If you are about to be asked hard questions about your own posture, it is worth knowing what your customer’s looks like.
A supplier checklist
If you sell to central government, an executive agency, a non-departmental public body or an NHS body, this is the order that matches the published requirements rather than the order that feels urgent:
- Hold the certificate the contract actually names. PPN 014 asks for Cyber Essentials or equivalent, evidenced before data is passed to you. Do not assume Plus unless the tender says Plus.
- Stop claiming the certificate covers email.If a questionnaire asks about anti-spoofing and you answer “we are Cyber Essentials certified”, an assessor who has read the requirements document knows that is a non-answer.
- Publish SPF, DKIM and DMARC on every domain you own, including the ones that never send mail. Our guides on creating the three records and locking down parked domains cover both cases.
- Send aggregate reports somewhere that reads them. A
rua=address that nobody parses is the most common failure we see. NCSC expects the address to be provided by the tool you chose in step one. - Work the policy up on NCSC’s timetable, not a calendar deadline. None, then quarantine once SPF and DKIM are correct and every legitimate sender is authorised, then reject. Our step-by-step move from p=none to p=reject follows the same progression.
- Cover transport as well as authentication. TLS on your mail servers, then MTA-STS, as set out in step two of the NCSC plan and explained in our guide to MTA-STS and TLS-RPT.
- Keep evidence dated. Buyers who lost Mail Check now ask suppliers for their own evidence. A monitoring platform that can show a policy history per domain answers that in one screenshot.
You can check where a domain stands right now with our free Security Grade scan, which reads SPF, DKIM, DMARC, MTA-STS, DNSSEC and TLS in one pass and needs no account. If you were a Mail Check user, our Mail Check migration page covers the switch, and the ShieldMarc Starter plan is permanently free for one domain with 10,000 messages a month and a year of retention, which is enough to keep aggregate reporting running while you decide what to buy.
Frequently asked questions
Does Cyber Essentials require DMARC?
No. Cyber Essentials covers five technical control themes — firewalls, secure configuration, security update management, user access control and malware protection — and email authentication is not one of them. The current Cyber Essentials: Requirements for IT Infrastructure v3.3, effective 27 April 2026, does not mention DMARC, SPF or DKIM anywhere. A supplier can hold a valid Cyber Essentials or Cyber Essentials Plus certificate while publishing no DMARC record at all.
Which NCSC guidance sets the email requirements instead?
NCSC’s email security and anti-spoofing collection. Its recommended implementation plan has six phased steps: choose an anti-spoofing management tool, protect email in transit, configure anti-spoofing controls, send spoof emails to spam, spoof emails being rejected, and continuous improvement. That collection is where SPF, DKIM, DMARC, TLS and MTA-STS are specified, and it is the document most public sector security questionnaires about email are derived from.
Why do public sector contracts ask suppliers for Cyber Essentials?
Because of PPN 014: Cyber Essentials scheme, which replaced PPN 09/14 and PPN 09/23 and applied from 24 February 2025. It applies to all central government departments, their executive agencies and non-departmental public bodies, and NHS bodies, and it says evidence of holding a Cyber Essentials certificate or equivalent is essential at the point when data is to be passed to the supplier. It bites on contracts handling citizen personal data, government employee personal data, ICT systems designed to store or process data at OFFICIAL, or information related to the day-to-day business of Government, service delivery and public finances.
What DMARC policy does NCSC recommend?
NCSC says a policy of reject on all of your domains is the best way to prevent spoofing of your email, reached in stages. Start at p=none as a monitoring phase to collect aggregate reports, move to p=quarantine as soon as you are confident DKIM and SPF are configured correctly and all known legitimate senders are in your records, monitor for at least four weeks at quarantine 100%, then roll p=reject out on a rising percentage and monitor closely for at least a further two weeks. NCSC notes many organisations move on from p=none after about six to eight weeks.
What replaced NCSC Mail Check for suppliers?
Nothing free and equivalent. NCSC retired Mail Check and Web Check on 31 March 2026 on the basis that many commercial external attack surface management products are widely available, most of which provide additional features and checks, and recommended organisations adopt one before the retirement date. Early Warning and DNS Check continue, and NCSC’s free Check your cyber security service includes a point-in-time Email Security Check for a single domain. Continuous multi-domain monitoring is now a procured service rather than a free central tool.
Sources
Every claim on this page about what a scheme or a policy requires is taken from the primary document, linked here so you can check it rather than trust us. Where we say a document does not mention something, we mean we searched the published text of the version named.
- PPN 014: Cyber Essentials scheme (Cabinet Office)
- Cyber Essentials overview and requirements (NCSC)
- Cyber Essentials: Requirements for IT Infrastructure v3.3, April 2026 (PDF, NCSC)
- Cyber Essentials help and resources, where the current version is published (NCSC)
- Email security and anti-spoofing (NCSC collection)
- Recommended implementation plan (NCSC)
- Choose an anti-spoofing management tool (NCSC)
- Protect email in transit (NCSC)
- Implement a DMARC policy of none (NCSC)
- Mark spoof emails as spam (NCSC)
- Reject spoof emails (NCSC)
- NCSC to retire Web Check and Mail Check (NCSC blog)
- Check your cyber security (NCSC Active Cyber Defence)
For the wider market view, our 2026 guide to the best DMARC monitoring tools for UK buyers compares platforms on hosting region, published pricing and cost per domain, and our guide for NHS trusts and councils covers the buying side of the same problem.