UK tender certifications, ranked by what buyers ask for
Most guides to UK tender certifications are a list of ISO standards. Our own notices say that is the wrong list.
ISO 9001 — the most-named ISO standard in UK procurement — is only the 31st most common requirement we track. Ahead of it sit DBS checks, CQC registration, Constructionline, employers’ liability and professional indemnity insurance, audited accounts and UKAS accreditation.
-
Apprenticeships4,747 notices, 3.8% obligations
-
Safeguarding policy2,907 notices, 7.9% obligations
-
Net zero commitment2,630 notices, 2.5% obligations
-
Social value2,273 notices, 11.8% obligations
-
TUPE transfer2,142 notices, 13.3% obligations
-
CDM 20151,863 notices, 4.6% obligations
-
CQC registration1,822 notices, 14.7% obligations
-
DBS check1,366 notices, 23.1% obligations
-
Biodiversity / environmental net gain1,248 notices, 2.6% obligations
-
Ofsted registration1,052 notices, 13.7% obligations
Tender certification requirements, ranked
Before any number, what it counts. We read the published text of each notice — title and description — not the tender pack, where requirements usually live. Every count is a floor: what is said out loud.
With that stated: across 753,797 dated UK notices, ISO 9001 is the 31st most-named requirement overall and the 24th most-named supplier credential. The 23 credentials ahead of it are not standards at all.
That is the single most useful thing on this page, and it reorders what a small supplier should do first. A DBS check, a Constructionline membership or an employers’ liability certificate is faster and cheaper to obtain than a management-system certification, and each is asked for more often.
The second column matters as much as the first. How often something is named and how often naming it is an obligation are different questions, and they rank the list differently. Insurance and financial standing sit near the top on obligation rate because when a buyer asks for them they nearly always mean it; policy commitments sit near the bottom because they are usually described rather than demanded.
The route to market matters more than any certificate
The five commonest signals in the entire corpus are not credentials. They describe how the work is being bought — and if you are not on the route, no certificate you hold will let you bid.
Framework agreement alone appears in 27,843 notices — more than every supplier credential on this page put together. That is not a certification you can go and buy. It is a position you hold or do not hold, and the way you get it is to be on the framework or dynamic market when it is open.
The practical consequence, and it is the most commercially useful sentence here: if you are not winning UK public work, the first question is not which certificate you are missing. It is whether the contracts you want are being let through a framework you are not on — and if so, when that framework next reopens. Our forward calendar exists to answer that.
You cannot buy your way onto a framework today. You get on when it reopens, which is why knowing the reopening date is worth more than another certificate.
What certifications do I need to bid? The classes
Requirements are not one kind of thing, and treating them as one list is why most guides mislead. Our taxonomy sorts them by what a supplier actually does about them.
Standards certify a management system and are audited on a three-year cycle. Schemes pre-qualify you once and are then accepted by many buyers, which is why they punch above their weight in construction. Clearances attach to people rather than the company, so their cost is per head and recurring. Registrations are permissions from a regulator without which the work is simply unlawful. Financial standing is insurance and accounts, and it has the highest obligation rates on the page because buyers rarely mention it without requiring it.
Clearances and registrations
These are the two classes most often underestimated, and the two where getting it wrong stops the bid rather than costing points.
DBS checks are named in 1,366 notices at 23.1% obligations — more than any ISO standard, and with a far higher obligation rate than most. They gate work in education, health, social care and anything involving children or vulnerable adults. Crucially they attach to people, not the company: the cost is per head, it recurs as staff change, and a contract requiring enhanced checks on twenty staff is a materially different proposition from one requiring a company certificate.
CQC registration appears in 1,822 notices at 14.7%. Registrations are a different kind of thing again: without them the activity is not merely unbid, it is unlawful. You cannot deliver a regulated care service without CQC registration in England, and no certificate substitutes for it.
Insurance and financial standing
The highest obligation rates on the whole page, and the cheapest to satisfy. If you are going to fix one thing this week, fix this.
Employers’ liability is named in 791 notices at 33.1% obligations, and professional indemnity in 461 notices at 36.7% — among the highest rates we measure. When a buyer names insurance they are almost always stating a condition, usually with a minimum level of cover attached.
Audited accounts appear in 449 notices at 31.0%. Financial standing tests are where small and young companies most often fall out, and where the Procurement Act 2023’s proportionality requirement most often bites: a condition of participation must be a proportionate means of assessing financial capability for that contract, and a three-year audited-accounts requirement on a small contract is challengeable.
Government tender certifications: where ISO actually sits
Not nowhere — but not where the guides put it either.
ISO 9001 is the 31st most-named requirement in the corpus, at 414 notices and 34.5% obligations. That obligation rate is the interesting half: ISO standards are low-frequency, high-obligation credentials. They are named rarely, and when they are named they are usually a hard gate rather than a preference. That is a genuinely different purchase decision from a scheme membership, which is named often and is frequently one of several acceptable options.
The exception worth knowing is Cyber Essentials at 297 notices — not an ISO standard, far cheaper than one, and named at a comparable rate. For most technology suppliers it is the first credential worth holding.
The full ISO picture has its own page, because the family behaves differently within itself: which standards are named most are not the ones demanded hardest, and the most-demanded of the lot was withdrawn in 2021. ISO tenders, counted.
What to get first, and in what order
The corpus supports a default order. It is not universal — your sector overrides it — but it is a better starting point than a list of standards.
First, the things that are not certifications at all. Check your insurance cover levels, that your accounts are filed, and whether the contracts you want are let through a framework or dynamic market you are not on. Those three account for more lost bids than any missing certificate, and two of them are fixable this week.
Second, the clearances your work actually requires. If you employ people who will be near children or vulnerable adults, DBS at the right level is not optional and it is not fast. If you are in a regulated activity, the regulator’s registration precedes everything.
Third, the cheap scheme membership for your sector. Construction and facilities: Constructionline and an SSIP-recognised health-and-safety scheme. Technology and data: Cyber Essentials. These are pre-qualification instruments accepted by many buyers from one assessment.
Fourth, and only then, the management-system standards. ISO 9001, ISO 27001, ISO 45001 and ISO 14001 are worth real money when a specific pipeline of contracts names them, or when you are certifying an integrated management system where three standards share one process set. Buy them against a pipeline you can point at — not speculatively.
The credential-by-credential guides
What each one asks of you, how it is evidenced in a bid, and how often UK buyers actually name it.
ISO tenders
The whole ISO family counted — which standards are named most, and which are demanded hardest. 414 notices in our corpus.
Cyber Essentials
The cheapest credential on this page, and named more often than most ISO standards. 297 notices in our corpus.
ISO 27001
Information security — the assurance credential most often asked for beside Cyber Essentials.
ISO 9001
Quality management — rarely named, and usually a hard gate when it is. 414 notices in our corpus.
ISO 45001
Health and safety — and the scheme memberships buyers ask for instead.
ISO 42001 procurement
The AI management standard, counted across the whole corpus with the accreditation chain behind it.
The Requirements Observatory
Every certification, clearance, scheme and registration UK buyers name, with the sentence each demand was found in.
The forward calendar
When the frameworks reopen — which on the evidence above matters more than any certificate.
Questions people actually ask about UK tender certifications
Answered from the corpus rather than the brochure.
what certifications do i need to bid for uk public contracts?
Fewer than you have been told, and probably not the ones you expect. On our own corpus the most-named ISO standard sits around thirtieth among all requirements; ahead of it are DBS checks, CQC registration, Constructionline membership, employers' liability and professional indemnity insurance, audited accounts and UKAS accreditation. The honest default order is: get your insurance cover levels and filed accounts right, obtain the clearances your work legally requires, take the cheap sector scheme membership, and only then consider a management-system standard — and buy that against a specific pipeline of contracts that names it rather than speculatively. Your sector overrides this: a laboratory, a care provider or a medical-device maker has gates that nothing else substitutes for.
what actually stops small suppliers bidding for public contracts?
On the evidence of the notices, usually not a missing certificate. The five commonest signals in the whole corpus are route signals — framework agreements, CCS agreements, dynamic purchasing systems, the regional buying consortia and G-Cloud — which describe how the work is being bought rather than what a supplier must hold. If the contracts you want are let through a framework you are not on, no certificate you obtain will let you bid on them. The second commonest blocker is financial: insurance cover levels and audited-accounts requirements carry among the highest obligation rates we measure, and they are where young and small companies most often fall out at the selection stage. Both are worth checking before spending anything on certification.
is iso 9001 worth it for public sector work?
It depends on your sector, and the corpus gives a usable rule. ISO 9001 is a low-frequency, high-obligation credential: it is named in a small fraction of UK notices, but when it is named it is usually a hard condition rather than a preference. So it is worth real money if the contracts you want name it — and worth very little if they do not, because it wins you no points where it is not asked for. In construction, facilities management and manufacturing it usually arrives as part of an integrated management system with ISO 14001 and ISO 45001, which is the case where it most clearly pays. Search your own categories for notices naming it before you commit.
what does it mean when you say a percentage of mentions are obligations?
It describes how the demand is worded, not how many tenders require the thing. Our extractor records separately whether the sentence a credential was found in uses obligation language — "must hold", "is required to" — as opposed to describing a preference or listing recognised frameworks. So a 33% figure means: of the notices that name this credential, about a third name it as an obligation. It does not mean a third of UK tenders require it. Most notices name no credential at all, so both numbers describe the small population that names one. It is a confidence tier, and it is deliberately never used as a filter.
why are your counts lower than other sites claim?
Because we count the notices rather than estimating, and we tell you what the count misses. We read each notice's published title and description, which is a summary running to a few hundred characters. Certification requirements overwhelmingly live in the documents the notice points to — the SQ or PQQ, the ITT pack, the conditions of participation — and those are attachments we do not hold. So every figure here is a floor, and the direction of the error is known: it understates. Figures like "40% of tenders require ISO 9001" are not measurements of anything we can find; our own corpus puts it at a small fraction of one percent of notices. We would rather publish a floor with its method than a number whose origin nobody can state.
How we counted
Every figure on this page is read from our corpus when the page loads.
The population. 753,797 UK notices carrying a publication date, from Find a Tender and Contracts Finder under the Open Government Licence v3.0 — the same population the counts are built from, so numerator and denominator cannot drift apart.
The matcher. One extractor, classifier version 5, last full run 1 August 2026, across 137 tracked requirements. It matches notice title and description, stores the sentence each match came from, and records separately whether that sentence uses obligation language. Same matcher as the Observatory — a second matcher would be a second truth.
The route/credential split. Framework, CCS, DPS, consortium and G-Cloud rows are separated from supplier credentials throughout, because they are the notice describing its own procurement route rather than a demand on the supplier. Their obligation rates — all very low — are the evidence for that reading. Framework values in our data layer are flagged as ceilings with heavy double-counting for the same reason, and there is deliberately no “market size” figure anywhere on this site.
The obligation floor. No percentage is shown for anything named fewer than 30 times; the count appears instead. Enforced in the data layer, not the template.
Related reading
ISO tenders
The ISO family in detail — named most is not demanded hardest, and the most-demanded was withdrawn in 2021.
The Requirements Observatory
All 137 tracked requirements with their live counts and the receipts.
Cyber Essentials
The cheapest credential here, and named more often than most ISO standards.
The Procurement Act 2023
Conditions of participation and the proportionality test that limits what a buyer may demand.
The forward calendar
When frameworks reopen — the thing that gates more bids than any certificate.
Search live tenders
Check which credentials the contracts in your own categories actually name.
Sources
- rfp.quest corpus, read live at the moment this page was served. 753,797 UK notices carrying a publication date, from Find a Tender and Contracts Finder under the Open Government Licence v3.0. Counts produced by the extractor at
src/lib/requirements/extract.ts, classifier version 5, last full run 1 August 2026, across 137 tracked requirements. Matches against notice title and description only. Counts are floors; obligation shares suppressed below 30 matches; route signals separated from supplier credentials throughout. - Procurement Act 2023, legislation.gov.uk. Conditions of participation, award criteria, and the requirement that both be a proportionate means of assessing capability.
- Procurement Policy Notes, Cabinet Office. The instrument by which UK government procurement policy is issued.
- Disclosure and Barring Service, GOV.UK. The basic, standard and enhanced check levels and who is eligible for each.
- Care Quality Commission. The regulator whose registration is a precondition of delivering regulated activities in England.
- United Kingdom Accreditation Service. The sole national accreditation body, and the thing that makes a certificate mean something to a buyer.
- Health and Safety Executive. The statutory duties underneath any health-and-safety credential.