- What they do
- Cybersecurity programme
- Who they help
- Silent Sector is a cybersecurity programme based in Scottsdale, AZ, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework National Cyber & Cloud Schemes
Crown Commercial Service (UK)
Crown Commercial Service (CCS) is the UK government's central purchasing body, an executive agency of the Cabinet Office. It does not publish a security standard of its own; the label refers to the compliance conditions a supplier meets to sell through CCS frameworks such as G-Cloud, Digital Outcomes, and Technology Products and Services.
Those conditions are set by government procurement policy. The most relevant is Procurement Policy Note 014 (which replaced PPN 09/23 and the original 2014 note), requiring contracting authorities to demand Cyber Essentials or Cyber Essentials Plus certification, or equivalent, for contracts that involve handling personal data or providing ICT systems and services, where that is relevant and proportionate.
Frameworks also ask suppliers to complete security questionnaires, meet the Government Security Classifications handling rules, hold Data Protection Act and UK GDPR compliance, and, for some lots, ISO/IEC 27001 or an NCSC-recognized equivalent; cloud suppliers are expected to explain how they meet the NCSC Cloud Security Principles.
In writing, a supplier bidding through CCS typically needs a current Cyber Essentials or Cyber Essentials Plus certificate, a completed supplier security assurance questionnaire, an information security policy and risk assessment, data protection documentation (privacy notice, processing records, breach procedure, data processing agreement), incident reporting procedures that meet the contract's timelines, and evidence of ongoing compliance for the life of the call-off contract.
help
Who has to comply
Suppliers awarded UK central government contracts, and contracts let by other public bodies that adopt the PPNs, where the contract involves personal data or ICT systems and services. The requirement is contractual and proportionate to the risk of the contract; small suppliers are in scope if the work touches such data or systems.
What the assessor asks to see
Cyber Essentials or Cyber Essentials Plus certificate; framework security questionnaire responses; information security policy and risk assessment; asset and data inventory for the contract; data protection documentation and data processing agreement; incident management and notification procedures; staff vetting (Baseline Personnel Security Standard) records where required; business continuity plans; where relevant, ISO/IEC 27001 certificate and statement of applicability or mapping to the NCSC Cloud Security Principles.
Assessors
Who assesses Crown Commercial Service (UK)
Cyber Essentials certification bodies licensed by IASME for the certification element; contracting authorities and CCS assess questionnaire responses themselves; NCSC-recognized bodies or UKAS-accredited certification bodies where ISO/IEC 27001 is required.
Accredited by IASME (as NCSC's delivery partner) for Cyber Essentials certification bodies; UKAS for ISO/IEC 27001 certification bodies.
Public register of assessors: https://iasme.co.uk/cyber-essentials/find-a-certification-body/
No firm has claimed a Crown Commercial Service (UK) assessor listing yet. Claim yours →
Consultants
Who helps with Crown Commercial Service (UK)
Bid consultants, Cyber Essentials certification bodies, and information security consultancies help suppliers obtain certification, complete framework security questionnaires, and build the policy set. Preparation for Cyber Essentials Plus usually takes a few weeks to a few months.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- Full-service GRC + vCISO
- Who they help
- Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- CISO-as-a-Service
- Who they help
- Vistrada is a cISO-as-a-Service based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- MSP - Compliance as a Service
- Who they help
- Omega Systems is an MSP - Compliance as a Service based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- MSP - Compliance as a Service
- Who they help
- Meriplex is an MSP - Compliance as a Service based in USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for Crown Commercial Service (UK)
Tools that name this framework in their own material.
No firm has claimed a Crown Commercial Service (UK) tool listing yet. Claim yours →
Related reading
- Cyber Essentials and government contracts: what UK suppliers need to knowExplains when PPN 014 makes Cyber Essentials a condition of bidding and how the requirement flows down to subcontractors.Periculo
- Cyber Essentials for UK government contractsCovers which frameworks, including G-Cloud, require certification as a condition of participation rather than per contract.FIG Group
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for Crown Commercial Service (UK)
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with Crown Commercial Service (UK)
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.