Skip to main content
    NixInfinity-AI
    GCA Frameworks

    Cyber Essentials for Digital Outcomes and Specialists (RM1043.9 and RM1043.8)

    Published 17 August 2026

    How the requirement works on Digital Outcomes

    Unlike agreements that state a flat supplier requirement, the Digital Outcomes agreements push the decision to the buyer. The call-off schedule covers Cyber Essentials and Cyber Essentials Plus, and the buyer sets which applies in the order form for each opportunity. That has two practical consequences:

    • Basic Cyber Essentials is effectively table stakes. Without it you cannot respond to the many opportunities that require it at short notice.
    • CE Plus needs planning. If you wait until an order form asks for it, you are one to two weeks behind competitors who already hold it.

    The full picture across Government Commercial Agency agreements is in our GCA frameworks requirements table.

    What buyers ask for on DOS opportunities

    • Certificate number and issue date, verified against the public IASME register
    • Confirmation the certified scope covers the team and systems delivering the work
    • Whether subcontractors and associates are covered
    • For higher-risk services, a valid Cyber Essentials Plus certificate

    Scope for digital delivery teams

    Digital suppliers usually run developer laptops, cloud hosting, CI pipelines and a lot of SaaS. The certification boundary should reflect the systems used to deliver the outcome, which typically means:

    • All developer and delivery team devices, including macOS and Linux machines
    • Identity provider and any cloud console access, with MFA enforced on every account
    • Source control, CI/CD and secrets management
    • Cloud infrastructure you administer, under the cloud services requirements
    • Associate and contractor devices, unless replaced by managed virtual desktops

    Our controls breakdown and readiness checklist cover the evidence expected for each.

    Common failure points for digital suppliers

    • Cloud admin or root accounts without MFA
    • Long-lived API keys and service accounts with no rotation or review
    • Developer machines on unsupported or beta operating system builds
    • Contractor devices outside any management or patching regime
    • Firewall and remote access rules that were opened for a project and never closed

    Planning for Cyber Essentials Plus

    CE Plus adds a hands-on technical audit including vulnerability scanning and sampled device testing. Allow an extra one to two weeks after basic certification. If you regularly bid on government digital work involving personal data, holding CE Plus continuously is usually the cheaper option compared with rushing it for a single order.

    See Cyber Essentials vs Cyber Essentials Plus for a side-by-side comparison.

    Bidding on Digital Outcomes?

    Get scope, evidence and timing confirmed by a named UK assessor on a 30-minute readiness call.

    Frequently Asked Questions

    Related Cyber Essentials Guides