From 1 October 2014, the UK Government requires suppliers bidding for central government contracts that involve handling personal information or providing certain ICT products and services to demonstrate that they meet the Cyber Essentials requirements.
This is set out in a Cabinet Office Procurement Policy Note and applies to new procurements. Contracts will typically require certification to be maintained throughout the contract term.
What should suppliers do?
- Check whether your current or planned public sector work falls within scope.
- Assess your organisation against the five Cyber Essentials control themes.
- Decide whether Cyber Essentials or Cyber Essentials Plus is appropriate for your customers’ expectations.
- Build certification renewal into your annual compliance calendar.
We expect many large private sector organisations to follow the Government’s lead and begin asking their own suppliers for Cyber Essentials.
Source: Procurement Policy Note 09/14 – Cyber Essentials (GOV.UK)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.