Skip to main content
    NixInfinity-AI
    GCA Frameworks

    Cyber Essentials for MCF4 (RM6309) and Consultancy and Professional Services (RM6399)

    Published 17 August 2026

    What the agreements ask for

    MCF4 (RM6309) covers management consultancy across business, finance, human resources, procurement and technology lots. RM6399, Consultancy and Professional Services, is the successor agreement covering broadly the same buying need. In both cases the Cyber Essentials Scheme sits in the framework schedules, and buyers are told that suppliers on the agreement hold certification.

    In practice, that means a current certificate issued by an IASME-licensed Certification Body, verifiable on the public IASME register, covering the systems your consultants actually use to deliver client work. See the full GCA framework requirements table.

    What goes in scope for a consultancy

    • Every laptop and desktop used by consultants, including personal devices used for work
    • Mobile phones and tablets that access company email or client documents
    • Microsoft 365 or Google Workspace, including SharePoint, Teams, Drive and email
    • Any client-facing collaboration or file transfer tooling
    • Your own cloud infrastructure, if you host anything for clients

    Distributed and associate-heavy consultancies trip up most often on associate devices. If an associate accesses client data on their own laptop, that device is in scope unless you can demonstrate a genuine separation, such as a managed virtual desktop.

    The controls that fail consultancy submissions

    • Multi-factor authentication not enforced on every cloud account, including admin accounts
    • Associate or contractor laptops running unsupported operating systems
    • Legacy authentication protocols still enabled in Microsoft 365
    • Missing mobile device management for phones accessing client data
    • Software left unpatched beyond 14 days for high-severity fixes

    The MFA requirements guide covers the first point in detail, and the readiness checklist covers the rest.

    Timing your certification against the bid

    Framework onboarding and call-off competitions both move fast. Allow one to two weeks for a standard route, or use the fast-track if your evidence is already in place. We assess eligibility for a same or next working day certificate on a 30-minute readiness call.

    Do you need Cyber Essentials Plus?

    Basic Cyber Essentials satisfies the framework itself. Individual buyers can specify Cyber Essentials Plus in a call-off where the engagement involves sensitive personal data or higher-value delivery, so read the order form rather than assuming the framework baseline is enough.

    How NixInfinity-AI helps consultancies

    • Scope set with a named assessor before you spend money on remediation
    • Practical answers for associate and BYOD device questions
    • Pre-submission review to maximise first-time pass
    • Same or next working day certificate issue once approved
    • £25,000 cyber insurance included for eligible UK organisations

    Bidding on RM6309 or RM6399?

    Speak to a named UK assessor today. 30-minute readiness call, IASME-aligned pricing, same or next-day certificate issue if you're prepared.

    Frequently Asked Questions

    Related Cyber Essentials Guides