Selling to UK Government: The Security Evidence Buyers Ask For

Selling to UK Government: The Security Evidence Buyers Ask For

Public sector procurement asks security questions early and expects documents rather than assurances. Cyber Essentials has been a requirement for central government contracts involving personal or sensitive information since a Cabinet Office procurement policy note took effect in October 2014, and most buyers now ask for considerably more than that. Knowing which evidence applies to your contract saves weeks.

The baseline every supplier needs

Certification comes first because it is the fastest to obtain and the most commonly specified. Cyber Essentials covers the basic technical controls and takes a few weeks. Cyber Essentials Plus adds an audit and is required for some contracts, particularly where you handle citizen data. ISO 27001 appears in larger tenders and takes months rather than weeks, so check the requirement before assuming you can meet a deadline. Where a framework agreement is involved, read the security schedule rather than the summary, since obligations flow down from it to you. Subcontractors inherit the same terms, so check what you have passed on to anyone delivering part of the service.

Testing evidence and who may perform it

Buyers routinely ask for a current penetration test report or an executive summary. For systems that process government information, the requirement may specify testing under the NCSC’s CHECK scheme, which means the supplier must hold that approval and the consultants must be cleared. That is a different question from whether your tester is competent, and it cannot be resolved after the tender closes. Where the contract does not name CHECK, a report from a UK penetration testing company with recognised accreditation is normally accepted.

“The suppliers who win this work are the ones with the evidence pack ready before the tender opens. Certification current, test report from this year, remediation record, named security contact and a data flow diagram. Assembling it during a bid is possible and it puts you in the position of writing about security while you are also trying to write about your actual service.”

William Fieldhouse, Director, Aardwolf Security Ltd

Questions about people and data

Expect detailed questions about staff and location. Security clearance for personnel touching certain systems, right to work and vetting standards, where data will be stored and processed, which subcontractors are involved and what they can access. Vagueness costs marks and invites follow-up questions you then have to answer under time pressure. If your support team is offshore, say so and explain the controls, because the answer is often acceptable and an evasive response never is. The same applies to cloud hosting: name the provider and the region rather than describing it as secure cloud infrastructure.

See also: Building a Mental Wellness Plan for Illinois Life

Planning the timeline backwards

Work back from the tender deadline and be realistic. Certification takes weeks, testing takes weeks to book and days to run, and remediation plus retest adds more. A supplier starting three weeks before submission will be writing optimistic answers rather than evidenced ones, which is exactly what buyers have learned to look for. If public sector work is on your roadmap for the next year, ask about testing for public sector work now so the report exists and the findings are closed before the first opportunity appears.

Frequently asked questions about public sector requirements

These questions come up whenever a supplier bids for government work for the first time.

Does Cyber Essentials cover every contract?

No. It is the baseline for many, and larger or more sensitive contracts add ISO 27001, testing evidence, clearance requirements and sometimes an assessment against the NCSC’s Cyber Assessment Framework.

Can you use the same evidence for several bids?

Yes, and keep it current. A single evidence pack reviewed quarterly serves every bid, as long as the test report and certificates have not expired between submissions.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *