HomeFrameworksNational Cyber & Cloud SchemesCrown Commercial Service (UK)

Framework  National Cyber & Cloud Schemes

Crown Commercial Service (UK)

Crown Commercial Service (CCS) is the UK government's central purchasing body, an executive agency of the Cabinet Office. It does not publish a security standard of its own; the label refers to the compliance conditions a supplier meets to sell through CCS frameworks such as G-Cloud, Digital Outcomes, and Technology Products and Services.

Those conditions are set by government procurement policy. The most relevant is Procurement Policy Note 014 (which replaced PPN 09/23 and the original 2014 note), requiring contracting authorities to demand Cyber Essentials or Cyber Essentials Plus certification, or equivalent, for contracts that involve handling personal data or providing ICT systems and services, where that is relevant and proportionate.

Frameworks also ask suppliers to complete security questionnaires, meet the Government Security Classifications handling rules, hold Data Protection Act and UK GDPR compliance, and, for some lots, ISO/IEC 27001 or an NCSC-recognized equivalent; cloud suppliers are expected to explain how they meet the NCSC Cloud Security Principles.

In writing, a supplier bidding through CCS typically needs a current Cyber Essentials or Cyber Essentials Plus certificate, a completed supplier security assurance questionnaire, an information security policy and risk assessment, data protection documentation (privacy notice, processing records, breach procedure, data processing agreement), incident reporting procedures that meet the contract's timelines, and evidence of ongoing compliance for the life of the call-off contract.

AI-compiled
Share
Sponsored
Crown
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with Crown Commercial Service (UK)
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Suppliers awarded UK central government contracts, and contracts let by other public bodies that adopt the PPNs, where the contract involves personal data or ICT systems and services. The requirement is contractual and proportionate to the risk of the contract; small suppliers are in scope if the work touches such data or systems.

What the assessor asks to see

Cyber Essentials or Cyber Essentials Plus certificate; framework security questionnaire responses; information security policy and risk assessment; asset and data inventory for the contract; data protection documentation and data processing agreement; incident management and notification procedures; staff vetting (Baseline Personnel Security Standard) records where required; business continuity plans; where relevant, ISO/IEC 27001 certificate and statement of applicability or mapping to the NCSC Cloud Security Principles.

Assessors

Who assesses Crown Commercial Service (UK)

Cyber Essentials certification bodies licensed by IASME for the certification element; contracting authorities and CCS assess questionnaire responses themselves; NCSC-recognized bodies or UKAS-accredited certification bodies where ISO/IEC 27001 is required.

Accredited by IASME (as NCSC's delivery partner) for Cyber Essentials certification bodies; UKAS for ISO/IEC 27001 certification bodies.

Public register of assessors: https://iasme.co.uk/cyber-essentials/find-a-certification-body/

No firm has claimed a Crown Commercial Service (UK) assessor listing yet. Claim yours →

Consultants

Who helps with Crown Commercial Service (UK)

Bid consultants, Cyber Essentials certification bodies, and information security consultancies help suppliers obtain certification, complete framework security questionnaires, and build the policy set. Preparation for Cyber Essentials Plus usually takes a few weeks to a few months.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

Silent SectorScottsdale, AZ, USANot yet verified
What they do
Cybersecurity programme
Who they help
Silent Sector is a cybersecurity programme based in Scottsdale, AZ, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TruvantisSan Francisco, CA, USANot yet verified
What they do
Full-service GRC + vCISO
Who they help
Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
VistradaUSANot yet verified
What they do
CISO-as-a-Service
Who they help
Vistrada is a cISO-as-a-Service based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
Omega SystemsUSANot yet verified
What they do
MSP - Compliance as a Service
Who they help
Omega Systems is an MSP - Compliance as a Service based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
MeriplexUSANot yet verified
What they do
MSP - Compliance as a Service
Who they help
Meriplex is an MSP - Compliance as a Service based in USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Software

Tools for Crown Commercial Service (UK)

Tools that name this framework in their own material.

No firm has claimed a Crown Commercial Service (UK) tool listing yet. Claim yours →

Related reading

  1. Cyber Essentials and government contracts: what UK suppliers need to knowExplains when PPN 014 makes Cyber Essentials a condition of bidding and how the requirement flows down to subcontractors.Periculo
  2. Cyber Essentials for UK government contractsCovers which frameworks, including G-Cloud, require certification as a condition of participation rather than per contract.FIG Group

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for Crown Commercial Service (UK)

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with Crown Commercial Service (UK)

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.