Version 1 Effective Date:

Revisions:

Date:

Author:

Description:

28 April 2025

Updated to include removal of the word ‘illustrative’ when referring to the Cyber Essentials Plus Test Specification, and updated document links.

  1. In this Agreement (including the background recitals), unless expressly stated otherwise:

"Accreditation Bodies"

means the group of bodies appointed under the previous contract to deliver the Partner Services;

"Agreement"

means the agreement between IASME and the CB under which the CB provides services in relation to the Cyber Essentials Scheme;

"Appointing and On-boarding Process"

shall have the meaning given in PR1.4 Schedule 2 (Certification Services and Relationship with Partner Services);

"Approval", "Approve", "Approved"

means NCSC’s or IASME’s express prior written approval or consent that may, at NCSC’s or IASME’s sole and absolute discretion, be withheld or delayed;

"Assessor"

an individual who will assess the compliance of an Organisation’s systems with the Cyber Essentials Technical Standard;

"Assessor Criteria"

shall have the meaning given in PR1.3 Schedule 2 (Certification Services and Relationship with Partner Services);

"Auditor General"

has the meaning given in the National Audit Act 1983;

"Branding Guidelines"

means the branding guidelines applicable (as the case may be) to use of:

(a) the Cyber Essentials Scheme Logo (as set out in Part A of Schedule 7);

(b) CB Badges and Assessor Badges (as set out in Part B of Schedule 7); and

(c) the Cyber Essentials Certification Mark (as set out in Part C of Schedule 7); and

(d) the Cyber Essentials Plus Certification Mark (as set out in Part D of Schedule 7),

(e) the IASME Consortium Logo (as set out in Part E of Schedule 7

in each case as may be updated by NCSC or IASME from time to time;

"Certificate"

the certificate (in the form specified by IASME/NCSC) issued by a Cyber Essentials Supplier to an Organisation which has successfully been assessed against the Cyber Essentials Technical Standard;

"Certification Body"

means a Cyber Essentials Supplier which has been appointed by the Cyber Essentials Partner to provide Certification Services;

“Certification Body Criteria”

means the criteria set out in Schedule 9.

"Certification Mark"

means the Cyber Essentials Certification Mark and the Cyber Essentials Plus Certification Mark;

"Certification Process"

means the process by which an Organisation is assessed against the Cyber Essentials Technical Standard and, if successful, is awarded a Certificate;

"Certification Services"

means the certification services provided by a Certification Body (CB) in connection with the Cyber Essentials Scheme which must as a minimum include the Certification Services Requirements;

"Certification Services Requirements"

means the minimum requirements which the Cyber Essentials Partner must include within each Supplier Agreement, as set out in Schedule 2 (Certification Services and Relationship with Partner Services) and Schedule 3 (NCSC Mandated Terms));

"Change"

means any amendment or variation of this Agreement (including to the Cyber Essentials Services or Cyber Essentials Scheme) effected in accordance with the Change Control Procedure;

"Change Control Procedure"

means the procedure referred to in Clause 27 (Change Control Procedure);

"Change of Control"

means, on or after the Effective Date:

(a) any person acquiring Control of the Cyber Essentials Partner; or

(b) any person having Control of the Cyber Essentials Partner ceasing to have such Control

"Claim"

means any claim, demand, action, cost, expense (including legal cost and disbursement), loss, damage and liability of whatsoever nature;

"Classification"

a security marking of OFFICIAL, SECRET or TOP SECRET (including any STRAP marking) (and also including the legacy classifications of PROTECT, RESTRICTED and CONFIDENTIAL) which may be applied to material;

"Classified Information"

any material in whatever form to which a Classification may be or has been attributed, or where no Classification has been applied and the nature of the material is such that it ought to be protected with a Classification

"Classification Policy"

means the Cabinet Office Government Security Classifications Policy (which, as at the Effective Date, can be found at: https://www.gov.uk/government/publications/government-security-classifications;

"Comptroller"

has the meaning given in the National Audit Act 1983;

"Confidential Information"

means all information relating to either Party or its operations or business, disclosed in confidence by or on behalf of one Party, or generated from such information by the receiving Party (whether before or after the Effective Date), either in writing, orally, or in any other form, directly or indirectly from or pursuant to discussions with the other Party or which is obtained through observations made by the receiving Party, including commercial, policy, technical, scientific, operational, personnel, personal, property and other information, and including ideas, concepts, schemes, information, knowledge, techniques, generic business methodologies (and anything else in the nature of know-how relating to the Cyber Essentials Services, Cyber Essentials Scheme or otherwise to this Agreement), and all analyses, compilations, studies and other documents, whether prepared by or on behalf of either Party that contain or otherwise reflect or are derived from such information (and any copy of such information), whether or not marked or designated as "confidential", which ought reasonably to be considered as confidential, except any information that:

(a) at the time of disclosure, is already public knowledge, or subsequently becomes public knowledge, other than by way of any breach of this Agreement or by way of any breach of the handling requirements for any Protectively Marked Material;

(b) prior to disclosure, was not subject to any confidentiality obligation of any sort;

(c) is properly disclosed under any legal requirement to a designated regulatory or other body; or

(d) prior to disclosure, was already known (by some other means ) by the recipient;

"Contracting Authority"

has the meaning given in Regulation 2 of the Public Contract Regulations 2015, as amended from time to time;

"Control"

the possession by a person, directly or indirectly, of the power to direct or cause the direction of the management and policies of the other person (whether through the ownership of voting shares, by contract or otherwise) and “Controls” and “Controlled” shall be interpreted accordingly;

"Controller"

has (as the case may be and as the context allows) the meaning given in Data Protection Law, as applicable to NCSC and (if applicable) the Cyber Essentials Partner and to their individual circumstances;

"Crown"

means the UK central government and its associated bodies, including the Central Government Bodies;

"Crown Body"

means any department, office, or agency of the Crown;

"Crown Dependencies"

means the self-governing possessions of the British Crown which, at the time of signature, include the Bailiwicks of Jersey and Guernsey and the Isle of Man;

"Cyber Essentials "

means the first tier of certification under the Cyber Essentials Scheme. It involves the Organisation carrying out a verified self-assessment which will then be sent to a Cyber Essentials Supplier for checking and certification, if appropriate;

"Cyber Essentials Assurance Specification"

means the process set out in Schedule 13 for ensuring consistency when Cyber Essentials Suppliers are assessing Organisations against the Cyber Security Technical Standard;

"Cyber Essentials Certification Mark"

means the Cyber Essentials Certification Mark as set out in Part C of Schedule 7 (Trade Marks and Certification Marks)

"Cyber Essentials Trade Mark Regulations"

the trade mark regulations relating to the Cyber Essentials Certification Mark, as set out in Appendix F to Schedule 7 (Trade Marks and Certification Marks);

"Cyber Essentials Partner Agreement"

means the agreement between NCSC and the Cyber Essentials Partner under which the Cyber Essentials Partner provides services relating to the Cyber Essentials Scheme;

"Cyber Essentials Documentation"

means each or any of the following:

(a) Cyber Essentials Technical Standard;

(b) Cyber Essentials Illustrative Questionnaire;

(c) Cyber Essentials Assurance Specification;

(d) Cyber Essentials Plus Test Specification;

(e) Cyber Essentials Certificate; and/or

(f) any documents recording or relating to the Appointing and On-Boarding Process (including any guidance produced by the Cyber Essentials Partner),

(as may be varied by IASME OR NCSC);

"Cyber Essentials Questionnaire"

means the questionnaire to be used to assess Organisations against the Cyber Essentials Technical Standard;

"Cyber Essentials Levels"

means the two levels of the Cyber Essentials Scheme: Level 1 – Cyber Essentials; and Level 2 – Cyber Essentials Plus; and such other levels as IASME or NCSC shall specify.

"Cyber Essentials Management Report"

means the monthly report to be prepared and submitted by the Cyber Essentials Partner to NCSC and containing:

(a) the information listed in Schedule 8 (Management Information and KPIs);

(b) any other information agreed between the Parties from time to time;

"Cyber Essentials Partner"

means IASME Consortium Limited;

“Cyber Essentials Platform”

means the platform provided by Pervade Software or such other platform that IASME may specify for the use in relation to the provision of the Certification Services

"Cyber Essentials Plus "

means the second level of certification under the Cyber Essentials Scheme. It involves a number of tests being carried out on an Organisation by a Cyber Essentials Supplier who will award certification on satisfactory completion of these tests;

"Cyber Essentials Plus Certification Mark"

means the certification mark set out in Part D Schedule 7 (Trade Marks and Certification Marks);

"Cyber Essentials Plus Trade Mark Regulations"

means the trade mark regulations relating to the Cyber Essentials Plus Certification Mark, a copy of which is set out in Appendix G of Schedule 7 (Trade Marks and Certification Marks);

"Cyber Essentials Plus Test Specification"

means the test specification to be used for testing an Organisation’s systems against the Cyber Essentials Technical Standard;

"Cyber Essentials Scheme" or "Scheme"

the certification scheme developed by NCSC with the aim of testing the compliance of organisations with the Cyber Essentials Technical Standard. Under this scheme, organisations can apply for certification, which recognizes the achievement of government endorsed standards of cyber hygiene and provides an assurance mechanism for companies of all sizes to help demonstrate to customers and other stakeholders that the most important basic cyber security controls have been implemented;

"Cyber Essentials Scheme Data"

means any data, diagrams, drawings, images, information, text, or sounds, back-up data, or other materials or items that are embodied in any medium (including all electronic, magnetic, optical, or tangible medium) which are:

(a) supplied to the Cyber Essentials Partner by or on behalf of the Authority; and/or

(b) which the Cyber Essentials Partner and/or a Cyber Essentials Supplier is required to generate, process, store or transmit pursuant to this Agreement or in relation to the Cyber Essentials Scheme;

"Cyber Essentials Scheme IPR"

means:

(a) (a) IPR in the Cyber Essentials Documentation;

(b) (d) IPR in any management information provided by the CB to IASME (including the Cyber Essentials Management Reports) and in any reports, materials and data relating to assessments made either by the Cyber Essentials Partner or by the Supplier (including certificates issued);

(c) the Cyber Essentials Scheme Logo and Badges and any IPR associated with the creation, development, and maintenance of the Cyber Essentials Scheme Logo; and

(d) the Cyber Essentials Certification Mark and Cyber Essentials Plus Certification Mark and any IPR associated with the creation, development and maintenance of the Cyber Essentials Certification Mark and Cyber Essentials Plus Certification Mark,

"Cyber Essentials Scheme Logo"

means the logo set out in Part A (Cyber Essentials Scheme Logo) of Schedule 7 (Trade Marks and Certification Marks);

"Cyber Essentials Supplier"

means an organisation which is appointed by the Cyber Essentials Partner to provide Certification Services in relation to the assurance of organisations against the Cyber Essentials Technical Standard;

"Cyber Essentials Technical Standard"

means the Cyber Essentials technical standard (containing the five technical controls) to be found at Cyber Essentials ;

"Cyber Essentials Test Specification"

Cyber Essentials Common Test Specification that is found at Cyber Essentials ;

"Cyber Essentials Website"

means NCSC’s microsite relating to the Cyber Essentials Scheme, to be found at https://www.cyberessentials.ncsc.gov.uk;

"Data Loss Event"

any event that results, or may result, in unauthorised access to Personal Data held by the CB under this Agreement, and/or actual or potential loss and/or destruction of Personal Data in breach of this Agreement, including any Personal Data Breach;

"Data Protection Law"

means (as the case may be and the context allows):

(a) the GDPR and any applicable national implementing Laws as amended from time to time;

(b) the DPA 2018 to the extent that it relates to processing of Personal Data and privacy; and/or

(c) all applicable law about the processing of Personal Data and privacy;

"Data Subject"

has the meaning given in the DPA 2018;

"Default"

means any breach of the obligations of the relevant party (including abandonment of this Agreement in breach of its terms, repudiatory breach or breach of a fundamental term) or any other default, act, omission, negligence or statement:

(a) in the case of IASME, of its employees, servants, agents; or

(b) in the case of the Supplier of its Sub-contractors or any Staff,

in connection with or in relation to the subject-matter of this Agreement and in respect of which such Party is liable to the other;

"Default Event"

shall have the meaning given in Clause 16.2 (Termination);

"Digital by Default"

means the use of secure online services to deliver a personalized user experience including process automation, information collection, storage and analytics;

"DPA 2018"

the Data Protection Act 2018;

"Dispute"

any dispute, difference or question of interpretation arising out of or in connection with this Agreement, including any dispute, difference or question of interpretation relating to the Certification Services, failure to agree in accordance with the Change Control Procedure or any matter where this Agreement directs the parties to resolve an issue by reference to the Dispute Resolution Procedure;

"Dispute Resolution Procedure"

means the procedure, set out at Clause 25 (Dispute Resolution Procedure), by which the Parties shall seek to settle any Dispute;

"Effective Date"

means the date of this Agreement;

"EIRs"

the Environmental Information Regulations 2004, ether with any guidance and/or codes of practice issued by the Information Commissioner or any Central Government Body in relation to such Regulations;

"Expiry Date"

means the last day of the Initial Term or any Extension Period, when this Agreement shall cease to have effect;

"Extension Period"

the period by which extends the Initial Term;

"FOIA"

the Freedom of Information Act 2000 and any subordinate legislation made under that Act from time to time, together with any guidance and/or codes of practice issued by the Information Commissioner or any relevant Central Government Body in relation to such Act;

"Force Majeure Event"

means an event beyond the reasonable control of a Party, including acts of God, civil commotion, war, fire, flood or political interference;

"GDPR"

the General Data Protection Regulation (Regulation (EU) 2016/679);

"Good Industry Practice"

means the use of standards, practices, methods and procedures conforming to Law, and the exercise of that degree of skill, care, diligence, prudence and foresight that would reasonably and ordinarily be expected from a skilled and experienced person engaged in England and Wales in the provision of services of the same type as the Certification Services in the same or similar circumstance;

IASME Logo

means the logo identified in part E of Schedule 7

"ICT"

means any electronic equipment used for processing, storing or transmitting information, including hardware, software, and electronic communications networks and equipment;

"Individual Recipients"

shall have the meaning set out in Clause 7.1.3 (Limited access);

"Initial Term"

shall have the meaning set out in Clause 3.1 (Term);

"Insolvency Event"

means the occurrence of any of the following events (or any event analogous to any of the following in a jurisdiction other than England and Wales) in relation to the relevant entity:

(a) the entity passing a resolution for its winding up or a court of competent jurisdiction making an order for the entity to be wound up or dissolved or the entity being otherwise dissolved or a petition being presented for the winding up of the entity save for a frivolous or vexatious petition which is discharged within 10 days;

(b) the appointment of an administrator of or, the making of an administration order in relation to the entity or the appointment of a receiver or administrative receiver of, or an encumbrancer taking possession of or selling, the whole or part of the entity’s undertaking, assets, rights or revenue or any steps being taken by any person for or with a view to the appointment of an administrator in relation to the entity;

(c) the entity entering into an arrangement, compromise or composition in satisfaction of its debts with its creditors or any class of them or takes steps with a view to the same or to obtain a moratorium or makes an application to a court of competent jurisdiction for protection from its creditors;

(d) the entity being unable to pay its debts or being capable of being deemed unable to pay its debts within the meaning of section 123 of the Insolvency Act 1986 without the need to prove any matter to the court’s satisfaction; or

(e) the entity proposing or entering into any arrangement, compromise or composition in satisfaction of its debts with its creditors;

(f) however, a resolution by the relevant entity or a court order that such entity be wound up for the purpose of a bona fide reconstruction or amalgamation shall not amount to an Insolvency Event;

(g) where the CB is an individual, any order for bankruptcy against the CB.

"IPR"

means any right, title or interest in:

(a) patents, trademarks, service marks, certification marks, unregistered trade marks, trade names, goodwill, registered designs, design rights, copyrights and other forms of intellectual or industrial property (in each case, in any part of the world), whether or not registered or registrable for their full period of registration with all extensions, renewals and revivals, and including all applications for registration or otherwise;

(b) inventions, formulae, confidential information (including know-how and secret processes);

(c) computer software; and

(d) any similar or equivalent rights and assets that may now or in the future subsist anywhere in the world;

"KPIs"

means the key performance indicators set out in Schedule 8 (Management Information and KPIs);

"Law"

means any Act of Parliament or subordinate legislation within the meaning of section 21(1) of the Interpretation Act 1978 and any enforceable European Union legislation;

"Malicious Software"

means any software program or code intended to destroy, interfere with, corrupt, or cause undesired effects on or to program files, data or other information, executable code or application software macros, whether or not its operation is immediate or delayed, and whether introduced wilfully, negligently or without knowledge of its existence;

"Management Information"

means the information to be provided by the Cyber Essentials Partner in the Cyber Essentials Management Report;

"Month"

means a calendar month;

"NCSC"

means the Secretary of State for Foreign and Commonwealth Affairs, acting through the National Cyber Security Centre, a part of the Government Communications Headquarters

"Open Government Licence"

means the Open Government Licence for public sector information to be found at http://www.nationalarchives.gov.uk/doc/open-government-licence/version/3/ (as the same may be updated from time to time);

"Organisation"

means a recipient of Certification Services;

"Parties"

means IASME and the CB;

"Partner Services"

means the services to be provided by the Cyber Essentials Partner to meet NCSC’s requirements set out in Schedule 2 (Certification Services);

"Permitted Activities"

means the Permitted Activities set out in Schedule 7 (Trade Marks and Certification Marks);

"Personal Data"

has the meaning given in Data Protection Law;

"Personal Data Breach"

has the meaning given in Data Protection Law;

"Processor"

has the meaning given in the Data Protection Law;

"Prohibited Act"

means any of the acts referred to in Clause 33

"Protectively Marked Material"

means any material, in whatever form, which is marked as "Secret" or "Top Secret", or which should properly be so marked and "Protectively Marked" shall be construed accordingly;

"Protective Measures"

appropriate technical and organisational measures which may include: pseudonymising and encrypting Personal Data, ensuring confidentiality, integrity, availability and resilience of systems and services, ensuring that availability of and access to Personal Data can be restored in a timely manner after an incident, and regularly assessing and evaluating the effectiveness of the measures adopted by it;

"Public Sector Entity"

means any entity that falls within the definition of a "contracting authority", as set out in Regulation 2 of the Public Contracts Regulations 2015;

"Quality Plan"

has the meaning given in Clause 24.1 (Quality Plans);

"Quarter"

means a period of three consecutive Months beginning on 1 January, 1 April, 1 July or 1 October;

"Rectification"

means as set out at Clause 16.5 (Rectification);

"Rectification Notice"

shall have the meaning set out in Clause 16.5 (Rectification) ;

"Regulatory Bodies"

means a public organisation or government agency that is set up to exercise a regulatory function;

"Request for Information"

has the meaning given in section 8 of the FOIA or a request made under Regulation 5 of the EIRs;

"Scheme Party"

means NCSC, the Cyber Essentials Partner, any Cyber Essentials Supplier (CB) or any Organisation;

"Security"

means all aspects of physical, logical, documentary, personnel and other security;

"Security Policy"

means the security policy applicable to NCSC and/or its suppliers (as updated from time to time) and related documents, guidance and operating procedures, including the Security Policy Framework;

"Security Policy Framework"

means the HMG Security Policy Framework, which is accessible at https://www.gov.uk/government/publications/security-policy-framework ;

"Security Requirements"

means the security requirements set out in this Agreement, including those set out in Clause 5 (Security), Schedule 4 (Security Requirements). Requirements and any requirements specifically identified as such in Schedule 2 (Certification Services and Relationship with Partner Services”);

"Sensitive Claim"

has the meaning given in Clause 13.3 (Sensitive Claims);

"Service Commencement Date

1st April 2020

"Service Standards"

means the service standards set out in Schedule 2;

"Site"

means any building, location or other site used for providing or supporting the provision of the Certification Services, whether in live use or as a back-up site, and whether or not used exclusively in connection with the Certification Services, excluding any Premises;

"Staff"

means any principal, employee, agent, supplier, or Sub-contractor of the CB, (and its principals, employees, agents, suppliers, and sub-contractors), employed or otherwise engaged directly in the provision of the Certification Services including without limitation (and where the context requires or permits) any Assessor engaged by the CB;

"Sub-contractor"

any third party with whom the CB enters into a sub-contract in connection with the performance of all or any part of the Certification Services or the CB’s other obligations under this Agreement;

"Supplier Agreement"

this agreement between IASME and an entity appointed to provide Certification Services,

"Technical Controls"

means the 5 controls within the Cyber Essentials Technical Standard;

"Term"

has the meaning given in Clause 3 (Term);

"Termination Date"

means midnight on the date specified for that purpose in a termination notice given under this Agreement;

"Third Party IPR Claim"

has the meaning given in Clause 11.1 (Claims);

"VAT"

means value added tax as provided for in the Value Added Tax Act 1994 and any supplemental Law;

"Working Day"

means a day (excluding Saturdays, Sundays and bank holidays in England and Wales) on which banks are open for normal business in London.