Skip to main content
    NixInfinity-AI
    GCA Frameworks

    Cyber Essentials for Supply Teachers and Education Recruitment (RM6376)

    Published 17 August 2026

    Why RM6376 takes cyber security seriously

    Education recruitment agencies hold some of the most sensitive personal data in the public supply chain: candidate identity documents, DBS certificates, safeguarding records, right to work evidence and school placement details. Framework Schedule 9 attaches the Cyber Essentials Scheme to the agreement and marks it as essential, so certification is not an optional differentiator here.

    The wider picture across Government Commercial Agency agreements is set out in our GCA frameworks requirements table.

    What goes in scope for an agency

    • Your applicant tracking or CRM system, whether hosted or on-premise
    • Microsoft 365 or Google Workspace, including shared mailboxes used by consultants
    • Every laptop, desktop and mobile device used by recruitment staff
    • Document storage holding DBS, right to work and safeguarding evidence
    • Home and hybrid workers' devices and routers where company devices are not issued

    Where education recruiters usually fail first time

    • Shared consultant logins on the CRM, which break the user access control requirement
    • MFA not enforced on shared or generic mailboxes
    • Old Windows machines in branch offices past their support date
    • Personal phones accessing candidate data with no device management or screen lock policy
    • Long-lived accounts for leavers that were never disabled

    The user access control and MFA requirements are the two that cost agencies the most time. See the MFA requirements guide and the five controls explained.

    Cyber Essentials and safeguarding expectations

    Schools and trusts increasingly ask agencies for evidence of technical controls alongside safeguarding policies. A current Cyber Essentials certificate answers that question in one line on a PQQ and is verifiable on the public IASME register. If you also supply directly to schools and academy trusts, our education sector page covers what trusts ask for.

    Timing

    Most agencies come to us with days rather than weeks before a submission. If MFA is enforced, devices are supported and patched and anti-malware is running, we can review and issue inside 24 hours as an IASME-licensed Certification Body. If not, one to two weeks is realistic.

    Bidding on RM6376?

    Talk to a named UK assessor about scope, timing and evidence. IASME-aligned pricing, no rush fees.

    Frequently Asked Questions

    Related Cyber Essentials Guides