|
Revisions: |
||
|
Date: |
Author: |
Description: |
Certification Services Requirements
The CB shall meet these requirements and such other Scheme requirements as IASME, or NCSC shall specify from time to time
|
Organisation |
|
|
CR1.2 |
The Certification Body shall hold a Cyber Essentials certificate to the level to which it delivers Certification Services. This certification must be obtained from another Certification Body. |
|
CR1.4 |
The Certification Body shall ensure that all its Assessors have attended training that has been approved by an NCSC certified training provision. |
|
CR1.5 |
The Certification Body shall document and operate a quality assurance process, in accordance with the principles and guidance of ISO9001. |
|
Certification Services |
|
|
CR2.1 |
The Certification Body shall work with the Cyber Essentials Partner to have a consistent impartial process for awarding certificates to Organisations (including guidance for pass/fail guidelines) whose assessment or test has been successful against the Cyber Essentials Technical Standard. |
|
CR2.2 |
The Certification Body shall adhere to the Certification Process when carrying out certification, in accordance with the Cyber Essentials Documentation as stipulated by the Cyber Essentials Partner. |
|
CR2.3 |
The Certification Body shall administer a consistent impartial process for providing appropriate feedback to an Organisation where assessment or testing has not been successful. |
|
CR2.4 |
The Certification Body shall work with the Cyber Essentials Partner to develop a consistent process for recording and storing the results of its assessments and tests against the Cyber Essentials Technical Standard. |
|
CR2.5 |
The Certification Body shall have and document a complaints and appeals process for Organisations, including an escalation process allowing Organisations to raise complaints or appeals to the Cyber Essentials Partner. |
|
CR2.6 |
The Certification Body shall work with the Cyber Essentials Partner to design and develop a process for the consistent, impartial assessment of applicants to be a Cyber Essentials Assessor against the agreed Assessor Criteria, the process shall include providing guidance on pass or fail criteria. |
|
CR2.7 |
The Certification Body shall ensure that Assessors who are assessing information systems have an appropriate level of Cyber Security/IA competence as stipulated by the Cyber Essentials Partner. |
|
CR2.8 |
The Certification Body shall ensure that the administration of Certification Services are delivered digitally. |
|
CR2.9 |
The Certification Body shall provide Organisations with standardised terms and conditions for the provision of Certification Services ensuring that the language is tailored appropriately to audience segments. |
|
CR2.10 |
The Certification Body shall work with the Cyber Essentials Partner to design for Organisations a standardised, personalised report, considering audience segmentation, advising (should they fail) on how they can address any outstanding issues to improve their security ("Feedback Report"). |
|
CR2.11 |
The Certification Body shall provide each Organisation which fails a certification with a Feedback Report. |
|
CR2.12 |
The Certification Body shall request that Organisations complete a standardised customer satisfaction survey after it has undergone assessment and/or certification. |
|
CR2.13 |
The Certification Body shall implement and maintain a process for identifying and addressing any conflicts of interest, however arising, in relation to the provision of Cyber Essentials Services. |
|
CR2.14 |
The Certification Body and their Assessors shall adhere to the principles and guidance of ISO/IEC 27002:2013 when carrying out Certification Services. |
|
CR2.15 |
The Certification Body should perform a spot check on an Organisation’s usage of the relevant Certification Mark, immediately after the Organisation’s renewal of certification date, should an Organisation choose to not renew. |
|
Branding |
|
|
CR3.1 |
The Certification Body shall supervise the use of the Cyber Essentials and Cyber Essentials Plus Certification Marks by Organisations in accordance with the relevant Certification Mark Regulations. |
|
Manage Information |
|
|
CR4.1 |
The Certification Body will conduct Management Information reporting in accordance with the requirements of the Cyber Essentials Partner. |
|
CR4.2 |
The Certification Body shall provide the Cyber Essentials Partner with a monthly report relating to Cyber Essentials MI, sent electronically in a format stipulated by the Cyber Essentials Partner. |
|
CR4.3 |
The Certification Body shall on a monthly basis provide anonymised information to the Cyber Essentials Partner on "Reasons for Failure" to achieve certification. |
|
Marketing and Communications |
|
|
CR5.1 |
The Certification Body shall ensure that the language and content of its website are aligned and consistent with the Cyber Essentials Website (including not making any misleading statements or misrepresentations of its role in and/or of the operation of the Scheme), https://www.cyberessentials.ncsc.gov.uk. |
|
CR5.2 |
The Certification Body shall take account of audience segmentation in developing marketing and promotional activities and events, including location and timing. |
|
CR5.3 |
The Certification Body shall present marketing and promotional material in diverse formats with language and level pitched appropriately for the relevant audience and aligned with HMG’s audience messaging strategy. |
|
Audit |
|
|
CR6.1 |
The Certification Body shall allow NCSC to perform ad-hoc audits to assess whether the Certification Body is meeting the requirements as set out in the Supplier Agreement. |
|
CR6.2 |
The Certification Body shall allow the Cyber Essentials Partner to perform ad-hoc audits to assess whether the Certification Body is meeting the requirements as set out in the Supplier Agreement. |
1 Service Standards: The Cyber Essentials Partner shall perform its obligations under this Agreement, and shall procure that each Cyber Essentials Supplier shall perform its obligations, at all times:
1.1 in compliance with the Security Policy;
1.2 in accordance with the Quality Plans;
1.3 in accordance with the Cyber Essentials Documentation;
1.4 subject to Clause 1.3 (Order of precedence) in the main Agreement in accordance with the Proposal;
1.5 by adequate numbers of appropriately experienced, knowledgeable, qualified, professional and trained personnel, by reference to their role and level of responsibility;
1.6 with all due care, skill and diligence;
1.7 in a good, safe and professional manner;
1.8 in a manner not likely to be injurious to health or to cause damage to property or the environment;
1.9 in co-operation and co-ordination with NCSC and all its relevant agents and other service providers, contractors, and suppliers;
1.10 in compliance with all applicable Laws, guidance and consents, and so as not to prejudice renewal of any consents, or put NCSC in breach of any Law, guidance or consents;
1.11 so as not to embarrass NCSC or bring NCSC or the Cyber Essentials Scheme into disrepute or damage NCSC’s operations, standing, public image, reputation or goodwill or the underlying cyber security of the UK and so as not to attract adverse publicity to NCSC or the Cyber Essentials Scheme; and
1.12 where, in relation to a matter, there is no express obligation or standard imposed on the Cyber Essentials Partner under this Agreement, and insofar as to do so does not conflict with any express provision of this Agreement, in accordance with Good Industry Practice;
(together, the "Service Standards").
2 Cyber Essentials Scheme improvements: The CB shall have an ongoing obligation throughout the Term:
2.1 to identify new or potential improvements to the Cyber Essentials Scheme, the Certification Services and the Cyber Essentials Services;
2.2 to notify those improvements to IASME; and
2.3 to report them in the Cyber Essentials Management Reports.
3 Changes to the Cyber Essentials Scheme: Notwithstanding Clause 2 (Cyber Essentials Scheme improvements), NCSC shall have sole and absolute discretion to make changes to the Cyber Essentials Scheme.
4 The Relationship with the Partner Services – NCSC Requirements for Partner Services
4.1 the following sets out the NCSC’s requirements for the Partner Services (PR) that are to be met by the Cyber Essentials Partner.
4.2 the CB shall at its own expense provide all reasonable support to IASME to enable it to provide the Partner Services and the objectives of the Scheme as a whole.
|
Transition (In) – (Pre-Service Commencement Date) |
|
|
PR1.1 |
The Cyber Essentials Partner shall prioritise the establishment of sufficient capability, in terms of Certification Services, such that Certification Bodies are able to meet sufficient monthly growth targets of Certificates, in agreement with NCSC, from the Service Commencement Date so as to meet the minimum number of Certificates per Month (800 CE and 150 CE+) (the “Initial Certificate Baseline”), in the third Month after Service Commencement Date. |
|
PR1.2 |
The Cyber Essentials Partner shall develop impartial assessment criteria for appointing and on-boarding Certification Bodies taking account of their technical cyber security competence and capability (including pass or fail guidance), such criteria (the "Certification Body Criteria") to be agreed with NCSC, by the Service Commencement Date. |
|
PR1.3 |
The Cyber Essentials Partner shall develop impartial assessment criteria (including pass or fail guidance) that a Certification Body will use for appointing and on-boarding Assessors, taking account of their Cyber Security competence; such criteria ("Assessor Criteria") will be agreed with NCSC by the Service Commencement Date. |
|
PR1.4 |
The Cyber Essentials Partner shall by the Service Commencement Date design and develop a process (including guidance on pass or fail criteria) (the "Appointing and On-boarding Process") for the consistent and impartial assessment of applicants to be a Certification Body, in agreement with NCSC. |
|
PR1.5 |
The Cyber Essentials Partner shall work with NCSC to develop and update the Cyber Essentials Documentation and Cyber Essentials Management Report by the Service Commencement Date including taking account of the fact that there will be a single Cyber Essentials Partner going forwards. |
|
PR1.6 |
The Cyber Essentials Partner shall work with NCSC to agree how the interface and day-to-day working arrangements (including communications, governance and liaison regarding technical matters) between the Cyber Essentials Partner and NCSC is to work by the Service Commencement Date. |
|
PR1.7 |
The Cyber Essentials Partner shall establish and manage the Staff, resources, processes, systems and infrastructure which it needs to ensure that it is ready to deliver the Cyber Essentials Scheme from the Service Commencement Date. |
|
PR1.8 |
The Cyber Essentials Partner shall work with NCSC and the outgoing Accreditation Bodies to ensure that new Organisations and Organisations seeking to renew their certification have a route to obtain certification under the Cyber Essentials Scheme from the Service Commencement Date. |
|
PR1.9 |
The Cyber Essentials Partner shall work with NCSC to agree the provision of training for its Staff and Assessors involved in operating the Cyber Essentials Scheme by the Service Commencement Date. |
|
PR1.10 |
The Cyber Essentials Partner shall work with NCSC to design, document and agree by the Service Commencement Date a marketing and communications strategy and plan for the Cyber Essentials Scheme ("the Marketing and Communications Strategy and Plan"). The Marketing and Communications Strategy and Plan shall reflect audience segmentation and must be aligned with HMGs current approach to cyber security marketing and communications. |
|
PR1.11 |
The Cyber Essentials Partner shall work with NCSC to design and agree by the Service Commencement Date the user journey from initial awareness through to achieving Certification; the journey should be simple and intuitive to understand for all audiences. |
|
PR1.12 |
The Cyber Essentials Partner shall work with the NCSC to define and agree by the Service Commencement Date all aspects of the arrangements for the process for renewal of Certificates. |
|
PR1.13 |
The Cyber Essentials Partner shall develop and agree with NCSC by the Service Commencement Date a pricing strategy to ensure that Certification Services are available to Organisations at a level that is accessible, affordable and attractive. |
|
PR1.14 |
The Cyber Essentials Partner shall make available digital Certification Marks for use by Organisations by no later than 6 Months after the Service Commencement Date. |
|
PR1.15 |
The Cyber Essentials Partner shall work with NCSC to create and make available by the Service Commencement Date a standardised live reporting dashboard showing the Cyber Essentials Management Information ("the Cyber Essentials Dashboard"). |
|
Organisational Requirements |
|
|
PR2.1 |
The Cyber Essentials Partner shall have and shall maintain a Cyber Essentials Plus Certification Mark throughout the Term and shall provide proof to NCSC of such certification annually and on request. |
|
PR2.2 |
The Cyber Essentials Partner shall ensure that Certification Bodies operate to a consistent, transparent and measurable standard, which the Cyber Essentials Partner must propose for agreement with the NCSC during the transition phase. |
|
PR2.4 |
The Cyber Essentials Partner shall require that each Certification Body providing Cyber Essentials Services to hold Cyber Essentials certification at the level to which it delivers Certification Services. This certification must be obtained from another Certification Body. |
|
PR2.5 |
The Cyber Essentials Partner shall require that all Assessors adhere to the principles and guidance of ISO/IEC 27002:2013 as updated from time to time when carrying out Certification Services. |
|
PR2.6 |
The Cyber Essentials Partner shall on an ongoing basis make recommendations to the NCSC to mature the standard for Certification Bodies. |
|
Administrative Management |
|
|
PR3.1 |
The Cyber Essentials Partner shall provide Partner Services digitally, unless there is sufficient justification not to, in agreement with NCSC. |
|
PR3.2 |
The Cyber Essentials Partner shall document and follow a quality assurance process, in accordance with the principles and guidance of ISO/IEC 9001:2015, detailing methods by which it shall review and continually improve the Cyber Essentials Scheme. |
|
PR3.3 |
The Cyber Essentials Partner shall ensure that any training, trainers and content it provides in relation to the Cyber Essentials Scheme has been approved by NCSC. Where appropriate this should include training certified under GCHQ Certified Training. |
|
PR3.4 |
The Cyber Essentials Partner shall administer the ongoing provision of training (to be agreed in Transition) for its Staff and Assessors involved in operating the Cyber Essentials Scheme. |
|
PR3.5 |
The Cyber Essentials Partner shall, in agreement with NCSC, commission research to inform the performance, take up, benefit realisation and impact of the Cyber Essentials Scheme. |
|
PR3.6 |
The Cyber Essentials Partner shall have a complaints and appeals process for Certification Bodies. |
|
PR3.7 |
The Cyber Essentials Partner shall have and duly administer a process for taking appropriate corrective action against Certification Bodies (including, without limitation, withdrawal or termination of any agreement to operate as a Certification Body under the Cyber Essentials Scheme) where it becomes aware (or is made aware) of a failure to comply with any of the Cyber Essentials Documentation or of the Cyber Essentials Partner bringing the reputation of the Cyber Essentials Scheme or NCSC into disrepute. |
|
PR3.8 |
The Cyber Essentials Partner shall ensure that the language used to describe the Certification Services, the Cyber Essentials Technical Standard and the terms on which an Organisation engages a Certification Body are tailored appropriately to audience segments. |
|
PR3.9 |
The Cyber Essentials Partner shall ensure that the user journey, from initial awareness through to achieving Certification, is reviewed annually with recommendations for improvement. |
|
PR3.10 |
The Cyber Essentials Partner shall work with NCSC to annually review and make improvements to the operation of the Cyber Essentials Scheme. |
|
PR3.11 |
The Cyber Essentials Partner shall ensure that the Certification Bodies supervise the use of the Cyber Essentials Certification Mark and the Cyber Essentials Plus Certification Mark by certified Organisations in accordance with the relevant Certification mark regulations and inform NCSC of any incorrect usage. |
|
PR3.12 |
The Cyber Essentials Partner shall continue to prioritise the growth of the number of certificates issued per month in excess of the Initial Certificate Baseline as defined in PR1.1 |
|
Manage Cyber Essentials Documentation |
|
|
PR4.1 |
The Cyber Essentials Partner shall document in agreement with NCSC a process (including version control) for managing the Cyber Essentials Documentation. |
|
PR4.2 |
The Cyber Essentials Partner shall operate the agreed process for managing the Cyber Essentials Documentation. |
|
PR4.3 |
The Cyber Essentials Partner shall work with NCSC to review annually and make improvements to the Cyber Essentials Documentation. |
|
PR4.4 |
The Cyber Essentials Partner shall work with NCSC to develop arrangements for asking Organisations to give express consent to receive requests for information regarding whether the Technical Controls have been effective in protecting its organisation against cyber-attack. This may be anonymised as appropriate. |
|
PR4.5 |
The Cyber Essentials Partner shall work with NCSC to design, develop and issue questionnaires to seek responses about the effectiveness of the Technical Controls in protecting Organisations against cyber-attacks/incidents, annually or at the request of NCSC. |
|
PR4.6 |
The Cyber Essentials Partner shall work with NCSC to review the Cyber Essentials Technical Standard regarding whether the Technical Controls have been effective in protecting Organisations against the most common, non-targeted, internet based cyber-attacks. |
|
PR4.7 |
The Cyber Essentials Partner shall continuously review the efficacy of the Technical Controls and make evidence-based recommendations to the NCSC for possible improvements on at least an annual basis. |
|
Appointing and Onboarding |
|
|
PR5.1 |
The Cyber Essentials Partner shall administer the Appointing and On-boarding Process for the Certification Bodies. |
|
PR5.2 |
The Cyber Essentials Partner shall ensure that the Appointing and On-boarding Process is reviewed annually. |
|
PR5.3 |
The Cyber Essentials Partner shall appoint and on-board Certification Bodies to maximise access to Certification Services for Organisations, including the ability for Organisations to gain access to physical assessment and testing regardless of geographical location in the UK or Crown Dependencies. |
|
Certification Services |
|
|
PR6.1 |
The Cyber Essentials Partner shall ensure that Certification Services are delivered in accordance with the Certification Services Requirements. |
|
PR6.2 |
The Cyber Essentials Partner shall introduce and implement a consistent process for Certification Bodies to issue reminders for Organisations who are approaching renewal of certification time. |
|
PR6.3 |
The Cyber Essentials Partner shall ensure that Certification Services are not provided as wholly automated technical solution except by agreement with NCSC. |
|
Branding |
|
|
PR7.1 |
The Cyber Essentials Partner shall use the Cyber Essentials Scheme Logo as the primary identifier for the Cyber Essentials Scheme. |
|
PR7.2 |
The Cyber Essentials Partner shall ensure that any Cyber Essentials Supplier also uses the Cyber Essentials Scheme Logo as the primary identifier for the Cyber Essentials Scheme. |
|
PR7.3 |
The Cyber Essentials Partner shall ensure that the Certification Bodies appropriately supervise Organisations’ use of the Cyber Essentials and Cyber Essentials Plus Certification Marks in accordance with the relevant Certification Mark Regulations. |
|
Manage Information |
|
|
PR8.1 |
The Cyber Essentials Partner shall provide NCSC with the Cyber Essentials Management Report, sent electronically in a format agreed by NCSC. |
|
PR8.2 |
The Cyber Essentials Partner shall maintain the Cyber Essentials Dashboard. |
|
PR8.3 |
The Cyber Essentials Partner shall work with NCSC to set consistent requirements for Management Information reporting from each Certification Body. |
|
PR8.4 |
The Cyber Essentials Partner shall work with the NCSC to ensure that basic information about an Organisations certification is held in a database and made publicly available. |
|
Marketing and Communications |
|
|
PR9.1 |
The Cyber Essentials Partner shall ensure that the language and content of its website are aligned to and are consistent with the Cyber Essentials Website – https://www.cyberessentials.ncsc.gov.uk/ . |
|
PR9.2 |
The Cyber Essentials Partner shall implement the Marketing and Communications Strategy and Plan, ensuring it maintains alignment, throughout the Term, with HMGs current approach to cyber security marketing and communications. |
|
PR9.3 |
The Cyber Essentials Partner shall work with NCSC to review annually and continuously improve the Marketing and Communications Strategy and Plan ensuring it maintains alignment with HMGs current approach to cyber security marketing and communications. |
|
PR9.4 |
The Cyber Essentials Partner shall take account of audience segmentation in developing marketing and promotional activities and events, including location and timing. |
|
PR9.5 |
The Cyber Essentials Partner shall present marketing and promotional material in formats targeted to audience segments with language and level pitched appropriately for the relevant audience and aligned with HMG’s current approach to cyber security marketing and communications. |
|
PR9.6 |
The Cyber Essentials Partner shall work with NCSC to provide face to face community events for Certification Bodies at least annually. |
|
Audit |
|
|
PR10.1 |
The Cyber Essentials Partner shall document, in agreement with NCSC, a process for auditing Certification Bodies’ compliance with the Certification Services Requirements. |
|
PR10.2 |
The Cyber Essentials Partner shall audit a sample size agreed with NCSC of Certification Bodies at least annually. |
|
PR10.3 |
The Cyber Essentials Partner shall collect and keep records of all audit activity including results and remedial actions and these will be provided to NCSC annually, or on request. |
|
PR10.4 |
The Cyber Essentials Partner shall document, in agreement with NCSC, a process for checking the validity and accuracy of Certification Body assessments and tests. |
|
PR10.5 |
The Cyber Essentials Partner shall spot-check a sample size, agreed with NCSC, of Certification Bodies assessments and tests at least annually or as agreed with NCSC. |
|
Future Evolutions |
|
|
PR11.1 |
The Cyber Essentials Partner shall work with NCSC to define the scope of upskilling and supporting Organisations to achieve Cyber Essentials and Cyber Essentials Plus Certification or to further improve their IT security to be known as ("Advisory Services"). |
|
PR11.2 |
The Cyber Essentials Partner shall work with NCSC to define the scope of developing and implementing additional levels below the current Cyber Essentials and/or above Cyber Essentials Plus to the Cyber Essentials Scheme. |
|
PR11.3 |
The Cyber Essentials Partner shall work with NCSC to review the scope of systems that are awarded certificates at either CE or CE+ level and to work with the NCSC to communicate to potential government and industry purchasers of goods and services from Organisations who hold Cyber Essentials certification. |
|
PR11.4 |
The Cyber Essentials Partner shall work with NCSC to define the provision of automated services to allow a secure and affordable route to certification. |
|
PR11.5 |
The Cyber Essentials Partner shall work with the NCSC to explore how to measure the impact that the Cyber Essentials Scheme is having on the basic cyber security health of the UK. |
|
PR11.6 |
The Cyber Essentials Partner shall work with the NCSC to develop a feedback mechanism to ensure that the Scheme keeps pace with evolving technology and new cyber threats. |