Could anything stop you bidding for a public contract?
A free, plain-English eligibility check (Procurement Act 2023 baseline 2026.1) for UK suppliers. It covers the grounds a public buyer must exclude you for, the ones they can, and the condition of participation that actually stops most small suppliers — Cyber Essentials. No login, and we don't store your answers.
A readiness / gap report to help you prepare before you bid — not legal advice, and not a determination of your eligibility.
Mandatory grounds: your directors and the debarment list
Schedule 6 of the Procurement Act 2023 lists grounds a buyer MUST exclude you for. Two of them are publicly checkable: whether a connected person is a disqualified director, and whether your business is on the centrally-published debarment list that every buyer has to check in every procurement.
Are you confident that none of your current directors — or anyone with significant control of the business — is disqualified from acting as a company director?
A disqualified director is someone a court or the Insolvency Service has barred from running a company. It is recorded on a public register anyone can search, and it is one of the grounds a public buyer must exclude a supplier for. If you are not sure, that is worth resolving before you bid rather than after.
Mandatory ground — a "No" here means a buyer has to exclude you, not weigh it up.
The detail (dig in)
Director disqualification (under the Company Directors Disqualification Act 1986, or an equivalent order) engages a mandatory exclusion ground under Schedule 6 of the Procurement Act 2023, which attaches to a supplier and to 'connected persons' — directors, shadow directors and persons with significant control — not only to the corporate entity. Companies House publishes the disqualified-officers register and it is searchable by name, so a contracting authority can and does check it. Note the register is searchable by NAME ONLY: it cannot be queried by company, so both we and the buyer are matching names, and same-name confusion cuts both ways.
Is your officer list at Companies House up to date — every current director appointed, and every former director's resignation filed?
Buyers check the register, not your website. If a director who left two years ago is still listed, their history becomes your problem in a procurement check; if a current director is missing, your declarations won't match the public record.
The detail (dig in)
Appointments and terminations must be filed (forms AP01/TM01 and their equivalents) and the confirmation statement keeps the PSC register current. A stale officer list creates two distinct procurement problems: an ex-officer's disqualification or conduct can be attributed to your supplier record, and any mismatch between your declared connected persons and the public register looks, at best, careless — at worst like a misrepresentation in a bid, which is itself an exclusion ground.
Have you checked whether any director or person with significant control has an unspent conviction of a kind that triggers a mandatory exclusion (for example fraud, bribery, tax offences, cartel offences or modern slavery)?
Some criminal convictions of the people connected to a business exclude it from public contracts automatically. This is not something anyone can check for you from outside — you have to ask, and record that you asked.
The detail (dig in)
Schedule 6 lists specific offences (including fraud, bribery and corruption, tax evasion and facilitation, cartel offences under the Competition Act 1998, theft and money-laundering offences, terrorism, and offences under the Modern Slavery Act 2015) which, where unspent and attaching to the supplier or a connected person, engage a mandatory exclusion. The practical control is a documented declaration process for directors and PSCs, refreshed periodically and before significant bids, so the answer in your supplier questionnaire is evidenced rather than assumed. Convictions are not publicly checkable — this stays self-declared by design.
Discretionary grounds: conduct, performance and financial standing
Schedule 7 grounds are the buyer's discretion, not an automatic bar: poor past performance on a public contract, professional misconduct, labour-market or environmental infringements — and insolvency. A buyer weighs them, so what matters is having an honest, evidenced answer ready rather than being caught out by the question.
In the last three years, is your record free of a public contract being terminated early, damages being awarded against you, or a settlement over poor performance?
Buyers ask about this directly, and they can ask other public bodies. A past problem does not automatically bar you — but being unable to explain it, or appearing to hide it, is far more damaging than the problem itself.
The detail (dig in)
Poor performance is a discretionary ground under Schedule 7: broadly, a breach of a public contract that led to termination, damages or a settlement, or performance that fell so far short it warranted such a step. Contracting authorities can share supplier performance information, and poor-performance notices can be published, so this is checkable by the buyer in a way most Schedule 7 grounds are not. Keep the contemporaneous record — the dispute, the resolution, and what changed after.
Is your business free of findings against it for breaches of employment, labour-market or health-and-safety law?
Enforcement action over how people are treated — unpaid wages, unsafe work, employment-agency rules — is something a buyer can take into account when deciding whether to let you bid.
The detail (dig in)
Labour-market and health-and-safety infringements sit among the discretionary grounds in Schedule 7, alongside environmental misconduct. Relevant evidence includes HSE enforcement notices and prosecutions, employment-tribunal awards, labour-market enforcement undertakings and orders, and national-minimum-wage naming. Some of these are published, so a buyer may find them whether or not you volunteer them.
Could you evidence a modern-slavery and supply-chain due-diligence position if a buyer asked for it?
Even below the legal reporting threshold, public buyers routinely ask what you do to check your own suppliers. A short, honest, written answer is usually enough — having nothing at all is the problem.
The detail (dig in)
Modern-slavery offences are a mandatory ground; supply-chain due diligence is the practical control buyers probe for. Businesses over the Modern Slavery Act 2015 s.54 turnover threshold must publish an annual statement, but smaller suppliers are asked for the substance regardless: supplier screening, a policy, a route for workers to raise concerns, and evidence it is applied rather than filed.
If something has gone wrong in the past, can you evidence what you changed afterwards?
The Act deliberately leaves a route back: show the problem was dealt with and is unlikely to happen again. That evidence is what turns a past issue into a closed matter rather than a reason to exclude you — but it has to exist in writing.
The detail (dig in)
This is 'self-cleaning'. Where a ground applies, an authority must consider whether the circumstances are continuing or likely to occur again, taking account of the steps the supplier has taken: the people responsible no longer involved, the failure investigated and its causes addressed, controls and training changed, and cooperation with any investigating body. Contemporaneous documentation is what makes the argument; a retrospective account written during a bid rarely persuades.
Is your business free of current insolvency proceedings — not in administration, liquidation, receivership or a voluntary arrangement?
This one we check for you: your company's status is public at Companies House, and it is the first thing a buyer sees. Being in proceedings does not automatically bar you — it is a ground the buyer weighs — but they will know, so it is far better to address it than to hope it is missed.
The detail (dig in)
Insolvency sits in Schedule 7 of the Procurement Act 2023 ("Insolvency, bankruptcy, etc") as a DISCRETIONARY ground: it applies where the supplier or a connected person has become bankrupt, become subject to insolvency or winding-up proceedings, or had assets placed in administration or receivership. Because it is discretionary, an authority may still contract with a supplier in proceedings — commonly where an administrator is trading the business on and can evidence capacity to perform. Companies House publishes the live status (`company_status`) plus a `has_insolvency_history` flag covering past events; we read both. Note the ground reaches CONNECTED PERSONS' personal bankruptcy too, which is held on the Insolvency Service's Individual Insolvency Register — a separate source we do not check.
Conditions of participation: Cyber Essentials
Separate from exclusion, and far more likely to be what actually stops your bid: a condition the buyer sets that you must meet to take part. Cyber Essentials is one of the most common, mandated across central-government supply chains and increasingly pushed down by large private buyers too.
Do you currently hold a Cyber Essentials certificate that is in date?
Cyber Essentials certificates last twelve months. An expired one is treated as no certificate at all — and this is the single most common technical condition on UK public contracts, so an expiry can cost you a bid you would otherwise win.
The detail (dig in)
Cyber Essentials is mandated for central-government contracts involving the handling of certain personal or sensitive information, and is widely imposed below that as a condition of participation or a contract term. Certification is annual and non-retrospective, so lapse dates matter: set a renewal reminder at 10–11 months, because re-certifying takes longer than most suppliers expect and a bid deadline will not wait for it.
Where a buyer requires Cyber Essentials Plus, do you hold it — or could you achieve it before the deadline?
Cyber Essentials Plus is the same five controls, but with a hands-on technical audit instead of a self-assessment. Some contracts specify it, and you cannot produce one at short notice.
The detail (dig in)
CE Plus adds an independent assessor's technical verification (authenticated vulnerability scanning of a sampled device set, malware-protection and patch-level testing) on top of the self-assessed baseline, and must be achieved within three months of the corresponding CE certification. Higher-assurance requirements sit above it again. The audit surfaces exactly the gaps a self-assessment lets you talk past, which is why lead time, not paperwork, is the binding constraint.
Would your technical controls pass a Cyber Essentials assessment today — patching within 14 days, MFA on every account, no unsupported software, secure configuration?
Holding the certificate and still meeting the controls are different questions. This is the one we can partly check for you: our free scan looks at your public website's configuration and encryption, which is a real slice of what an assessor checks. For the full picture, the Cyber Essentials readiness report walks all five controls.
The detail (dig in)
The five controls (firewalls, secure configuration, security update management, user access control, malware protection) are assessed against the current question set, and several are hard-fail items — unsupported software still in use, missing MFA on cloud services, unapplied high/critical updates beyond 14 days. Our passive scan observes secure-configuration and encryption-in-transit signals on the public site only; it cannot see endpoints, so a clean scan evidences part of one control, not the certificate.
Check your directors against the public register (optional)
Find your company below and we'll search the Companies House disqualified-officers register for each of your current directors — the same public check a contracting authority can run. Nothing is stored.
Cross-check the Cyber Essentials answer against your website (optional)
Enter your website and we'll run a quick, free passive check (HTTP headers and TLS) — the slice of a Cyber Essentials assessment anyone can see from outside — and flag it if what's published contradicts your answer. No login, nothing stored.
Leave blank for a questionnaire-only check.