Version 1 Effective Date:

Revisions:

Date:

Author:

Description:

The following provisions shall have effect –

1 Scheme-specific Provisions

1.1 The Cyber Essentials Supplier shall perform the Certification Services in accordance with the Service Standards.

1.2 The Cyber Essentials Supplier shall provide the Certification Services in accordance with the Cyber Essentials Documentation and the provisions of the relevant Supplier Agreement.

1.3 The Cyber Essentials Supplier shall only be entitled to provide Certification Services:

1.3.1 from the date on which it is appointed by the Cyber Essentials Partner to provide Certification Services (and in accordance with that appointment);

1.3.2 until the date on which the first of the following events occurs:

1.3.2.1 the Cyber Essentials Scheme is terminated by NCSC or ceases to exist;

1.3.2.2 the agreement between NCSC and the Cyber Essentials Partner expires or is terminated (for whatever reason);

1.3.2.3 the expiry or earlier termination of the Supplier Agreement between the Cyber Essentials Partner and the Cyber Essentials Supplier; or

1.3.2.4 the Cyber Essentials Supplier appointment in respect of Certification Services is suspended or revoked.

1.4 Control of the Scheme: The Cyber Essentials Supplier acknowledges that NCSC shall have sole and absolute control of the Cyber Essentials Scheme (including any permitted amendments to the Cyber Essentials Documentation), including absolute discretion, at any time, in relation to:

i. its existence;

ii. its scope;

iii. its configuration;

iv. its development, implementation, management and operation;

v. its participants; and

vi. its use.

1.5 Changes to the Scheme and Termination: The Cyber Essentials Supplier acknowledges that NCSC may at any time:

i. change the Cyber Essentials Scheme;

ii. incorporate any improvement or change to the Cyber Essentials Documentation; or

iii. terminate the whole or any part of the Cyber Essentials Scheme,

and that, in such event, the Cyber Essentials Partner shall be entitled to terminate or make appropriate amendments to the Supplier Agreement.

1.6 NCSC, or the Cyber Essentials Partner acting on its behalf, will give Cyber Essentials Suppliers notice of such changes or termination (together with copies of any updated or new Cyber Essentials Documentation), together with the date such changes or termination are to take effect ("Relevant Date"), as soon as reasonably practicable (having regard to the circumstances) in advance of the Relevant Date.

1.7 Cyber Essentials Suppliers will not be required to comply with any changes of which they have not been notified by or on behalf of NCSC, but where any Certification Services will not have been concluded as at the Relevant Date, NCSC, or the Cyber Essentials Partner acting on its behalf, reserves the right to require the Cyber Essentials Supplier to restart or modify the relevant Certification Services on the basis of the modified form of the Scheme as will be in place with effect from the Relevant Date. Where that is the case NCSC, or the Cyber Essentials Partner acting on its behalf, will prior to the Relevant Date consult with the affected Cyber Essentials Suppliers and provide reasons for its decision, save where the decision is related to national security.

1.8 Limited rights: Apart from the limited rights described in the Supplier Agreement, the Cyber Essentials Supplier acknowledges that neither it nor any person to whom IPR or Confidential Information owned by NCSC or by the Cyber Essentials Partner is disclosed shall be entitled to any right or licence in respect of such IPR or Confidential Information.

1.9 Veto over use of tools: The Cyber Essentials Supplier acknowledges that NCSC reserves the right to veto the use of any tool the Cyber Essentials Supplier may wish to use to automate either part or all of an assessment. This includes but is not limited to any type of scanning or testing tool.

1.10 Management Information: the Cyber Essentials Supplier shall provide to the Cyber Essentials Partner (with an acknowledgement that the Cyber Essentials Partner will share the same with NCSC) the Management Information, including details of any applications by Organisations for review of a decision by the Cyber Essentials Partner to refuse permission to use a Certification Mark.

1.11 Key Performance Indicators (KPIs): the Cyber Essentials Supplier shall meet and report on the KPIs (as set out in Schedule 8 (Management Information and KPIs).

1.12 Staff: the Cyber Essentials Supplier shall ensure that the Cyber Essentials Services are at all times supplied and rendered by a sufficient number of appropriately experienced, qualified, competent, professional and trained staff, with all due skill, care and diligence, in a first-class professional manner and in accordance with Good Industry Practice and the other provisions of this Agreement.

1.13 Computer Misuse Act 1990: the Cyber Essentials Supplier shall comply with the Computer Misuse Act 1990 in undertaking the Certification Services regardless of geographic location.

2 Cyber Essentials Scheme Enforcement

2.1 The Cyber Essentials Supplier acknowledges that the Cyber Essentials Partner may enforce the Cyber Essentials Scheme (including the Cyber Essentials Documentation) against it and any other Cyber Essentials Supplier that fails to comply with it, and that NCSC may also in certain circumstances require the Cyber Essentials Partner to take action in relation to the Cyber Essentials Supplier (and that the Cyber Essentials Partner may not be free to explain to the Cyber Essentials Supplier why that action is required. The steps to be taken by the Cyber Essentials Partner may include, where appropriate, :

2.1.1 requiring the Cyber Essentials Supplier to take certain action or refrain from taking certain action;

2.1.2 requiring the Cyber Essentials Supplier to cease using certain marketing or other materials or to cease making certain statements, including where the Cyber Essentials Partner or NCSC believes, at its sole and absolute discretion, such materials or statements are misleading or misrepresentative, or bring, or are likely to bring, the Cyber Essentials Scheme into disrepute; and/or

2.1.3 revoking the appointment of a Cyber Essentials Supplier as a Certification Body.

2.1.4 the Cyber Essentials Supplier shall not seek to take or take any action against the Cyber Essentials Partner insofar as and to the Cyber Essentials Partner is exercising its rights or obligations under this clause 2.

3 Cyber Essentials Scheme IPR

3.1 NCSC IPR: the Cyber Essentials Partner hereby grants to the Cyber Essentials Supplier a non-exclusive, royalty-free, non-assignable, revocable licence during the Term of the Supplier Agreement to use the NCSC Background IPR and the Cyber Essentials Scheme IPR solely and to the extent necessary for the performance of the Certification Services and/or the Cyber Essentials Supplier’s performance of its other obligations under the Supplier Agreement.

3.2 Open Government Licence: The Cyber Essentials Supplier acknowledges that any materials containing Crown Copyright or Crown owned rights which are made publicly available ("OGL Materials") shall only be made available subject to the then current version of the Open Government Licence.

3.3 Cyber Essentials Scheme Logo: the Cyber Essentials Partner grants to the Cyber Essentials Supplier a non-exclusive, royalty-free, revocable, non-assignable, licence during the Term of the Supplier Agreement to use the Cyber Essentials Scheme Logo in the United Kingdom solely in relation to the Permitted Activities set out in Part A of Schedule 7 (Trade Marks and Certification Marks), provided that:

3.3.1 the Cyber Essentials Supplier shall observe the Branding Guidelines relating to the Cyber Essentials Scheme Logo and any directions by or instructions of the Cyber Essentials Partner or NCSC from time to time;

3.3.2 the Cyber Essentials Supplier shall not sub-license the Cyber Essentials Scheme Logo; the Cyber Essentials Supplier’s right to use the Cyber Essentials Scheme Logo shall terminate automatically if its appointment as a Certification Body or an Advisory Body has lapsed or been withdrawn or terminated for whatever reason; and

3.3.3 the Cyber Essentials Supplier shall use the Cyber Essentials Scheme Logo on all certificates issued to an Organisation and any literature, documentation, advertising, and publicity material used in connection with the Cyber Essentials Scheme.

3.4 Certification Marks: the Cyber Essentials Supplier shall:

3.4.1 permit and supervise (including undertaking monitoring activities) use of the Cyber Essentials Certification Mark by Organisations in accordance with the Cyber Essentials Trade Mark Regulations; and/or

3.4.2 permit and supervise (including undertaking monitoring activities) use of the Cyber Essentials Plus Certification Mark by Organisations in accordance with the Cyber Essentials Plus Trade Mark Regulations.

4 Review

4.1 The Cyber Essentials Supplier acknowledges that NCSC and/or the Cyber Essentials Partner may at any time during the Term, and for a period of 12 months following the end of the Term, monitor and review the provision of the Certification by the Cyber Essentials Supplier and other activities relating to the Cyber Essentials Scheme. Such monitoring and review activities may include observing the Cyber Essentials Supplier whilst it carries out its certification activities and reviewing the output of the Cyber Essentials Supplier’s certification activities.

4.2 The Cyber Essentials Supplier shall allow NCSC to accompany the Cyber Essentials Partner on any audit undertaken by the Cyber Essentials Partner in connection with the Supplier Agreement and acknowledges that the Cyber Essentials Partner may supply NCSC on request with a copy of the results of any such audit.

5 Exit

5.1 From (i) one month before the expected date of expiry of the Supplier Agreement or (ii) the date of earlier termination of the Supplier Agreement (for whatever reason), the Cyber Essentials Supplier shall not enter into any further contracts with Organisations for Certification Services, provided that the Cyber Essentials Supplier shall be entitled to complete any Certification Services in relation to any contracts entered into with Organisations for Certification Services prior to such date.

6 Sub-contracting

53.1 The Cyber Essentials Supplier may only sub-contract the provision of any of the Certification Services to companies who have a registered office in the United Kingdom unless NCSC or the Cyber Essentials Partner has given its prior written consent.

7 General provisions

7.1 Confidentiality: The Cyber Essentials Supplier shall treat any Confidential Information of any other Scheme Party as confidential and safeguard it accordingly, and at least to the same standard as it would safeguard any confidential information relating to its own business, and in accordance with Good Industry Practice, and shall not further disclose any Confidential Information of any other Scheme Party, except for the purposes of developing, implementing, managing, or operating the Cyber Essentials Scheme.

7.2 Disclosure: In the event that information that is considered to be commercially sensitive is disclosed, the disclosing Cyber Essentials Supplier shall clearly state (at the time of such disclosure) what information being imparted by them is considered to be commercially sensitive and this shall be identified as such in the written record of the relevant meeting.

7.3 Confidence: Any information that is commercially sensitive and is disclosed shall be treated in confidence by the recipient who shall not disclose any commercially sensitive information to any third party without the prior written consent of the disclosing Cyber Essentials Supplier

7.4 No endorsement: The Cyber Essentials Supplier acknowledges that the Cyber Essentials Documentation and all other aspects of the Cyber Essentials Scheme are provided by NCSC or by the Cyber Essentials Partner without any endorsement and without representation or warranty of any kind, whether express or implied, including in respect of accuracy, completeness, reasonableness, adequacy, integrity, content, quality, reliability, or fitness for purpose of all or any part of it.

7.5 No liability: The Cyber Essentials Supplier acknowledges and accepts that the Crown (including NCSC) and the Cyber Essentials Partner cannot accept any liability whatsoever for any loss or damage suffered or costs incurred by any Cyber Essentials Supplier or other person as a result of, or arising from, the disclosure or use of any Confidential Information or IPR, or otherwise of any of the Cyber Essentials Documentation, or any other aspect of the Cyber Essentials Scheme.

7.6 Contracts (Rights of Third Parties) Act 1999: NCSC has the right to enforce the relevant provisions of paragraph 3 (Cyber Essentials Scheme Enforcement) and paragraph 4 (Cyber Essentials Scheme IPR) directly against the relevant Cyber Essentials Supplier. Save as aforesaid the rights of third parties are excluded.