Skip to main content
    NixInfinity-AI
    Government Commercial Agency

    Cyber Essentials for Government Commercial Agency Frameworks

    Which GCA agreements require Cyber Essentials, by RM number, what Framework Schedule 9 actually asks of suppliers, and how to certify before your submission window closes.

    GCA agreements and their Cyber Essentials position

    Framework requirements change between iterations, so treat this as a starting point and confirm against the schedules published for your agreement. Each RM number links to the GCA agreement page so you can verify.

    Government Commercial Agency frameworks and their Cyber Essentials requirements
    AgreementReferenceCE positionWhat it means
    Management Consultancy Framework Four (MCF4)RM6309RequiredGCA states suppliers on the agreement are Cyber Essentials accredited.
    Consultancy and Professional ServicesRM6399RequiredSuccessor agreement to MCF4, with the same Cyber Essentials expectation on suppliers.
    Supply Teachers and Education RecruitmentRM6376Required (Schedule 9)Framework Schedule 9 lists the Cyber Essentials Scheme as essential for suppliers.
    Digital Outcomes and Specialists 7RM1043.9Order levelCyber Essentials schedule included; CE or CE Plus can be specified at call-off.
    Digital Outcomes 6RM1043.8Order levelCall-off schedule covers Cyber Essentials and Cyber Essentials Plus requirements.
    Learning and Development 2RM6303RequiredThe agreement advertises Cyber Essentials accredited suppliers to buyers.
    Security – Physical, Technical and Support ServicesRM6257Required (Schedule 9)Includes the Framework Schedule 9 Cyber Essentials Scheme provisions.
    Fuel Cards and Associated Services VIIRM6367Required (Schedule 9)Framework Schedule 9 lists Cyber Essentials as essential for suppliers.
    Courier, Distribution, Storage and Specialist SolutionsRM6354OptionalA Cyber Essentials schedule exists but is applied at the buyer's discretion.
    G-Cloud 15RM1557.15RequiredCloud framework; see our dedicated G-Cloud 15 supplier hub.

    What Framework Schedule 9 asks for

    Schedule 9 is the standard GCA schedule covering the Cyber Essentials Scheme. Where it is included and marked essential, the supplier must hold a current Cyber Essentials certificate covering the IT used to deliver the contract, keep it current for the life of the agreement, and produce it on request. The certificate is checked against the public IASME register, so an expired or self-declared certificate fails.

    Scope matters more than most suppliers expect. Certifying only a subset of your estate is acceptable as long as the certified scope genuinely covers contract delivery. If in doubt, our assessors set the scope with you before you submit. See the five controls and the readiness checklist.

    Is it Cyber Essentials or Cyber Essentials Plus?

    Basic Cyber Essentials satisfies most GCA agreements at framework level. Cyber Essentials Plus, which adds a hands-on technical audit, is typically imposed at call-off or order level. That is exactly how the Digital Outcomes agreements work: joining the framework needs the baseline, while the individual buyer can specify CE Plus in the order form for higher-risk work. See Cyber Essentials for Digital Outcomes (RM1043).

    Where sensitive personal data, MoD systems or NHS clinical data are in play, plan for CE Plus and allow an extra one to two weeks for the audit.

    Consultancy suppliers: RM6309 and RM6399

    GCA promotes both Management Consultancy Framework Four and its successor, Consultancy and Professional Services, on the basis that suppliers are Cyber Essentials accredited. For consultancies, scope usually lands on laptops, mobile devices, Microsoft 365 or Google Workspace and any client-facing collaboration tooling. Full detail in Cyber Essentials for MCF4 and Consultancy and Professional Services.

    Education and recruitment suppliers: RM6376 and RM6303

    Supply Teachers and Education Recruitment (RM6376) carries Schedule 9 with Cyber Essentials marked essential, which makes sense given the volume of candidate and safeguarding data agencies handle. Learning and Development 2 (RM6303) is advertised to buyers on the basis of Cyber Essentials accredited suppliers. Read Cyber Essentials for Supply Teachers and Education Recruitment, or see our education sector page.

    Security, fuel cards and logistics: RM6257, RM6367 and RM6354

    Security Physical, Technical and Support Services (RM6257) and Fuel Cards and Associated Services VII (RM6367) both carry the Schedule 9 Cyber Essentials provisions. Courier, Distribution, Storage and Specialist Solutions (RM6354) includes a Cyber Essentials schedule that buyers can apply at their discretion, so treat certification as a competitive differentiator rather than a hard gate on that agreement. Suppliers in these sectors often run mixed estates with legacy handheld devices and telematics, which is where scope conversations pay off early.

    Cloud suppliers

    Cloud services sit on G-Cloud, which we cover separately in the G-Cloud 15 Cyber Essentials hub and the G-Cloud supplier page.

    IASME-licensed

    We review your submission and issue the certificate ourselves, no third-party handover.

    24-hour fast-track

    Built for framework submission windows and call-off deadlines, with no rush surcharge.

    Pre-submission review

    The single biggest factor in first-time pass rates across GCA supplier bids.

    Framework deadline this week?

    Tell us the RM number and your submission date. A named UK assessor will confirm within 30 minutes whether we can certify you in time.

    Frequently asked questions

    Your Certification Team

    Meet Your Assessors

    You won't deal with a faceless organisation. You'll work directly with one of our two dedicated assessors – real people who genuinely care about getting you through.

    EW

    Emma Wharram

    Cyber Essentials Assessor

    With almost 30 years of experience across data, information, and security in the public sector, Emma makes even the most complex requirements feel manageable. She holds a Master's in Cyber Security and is completing a PhD exploring how organisations build genuine security cultures. Her warm, approachable style puts everyone at ease – no jargon, no judgement, just clear guidance from start to finish.

    • Warm, approachable style that makes the process feel manageable
    • Deep public sector, healthcare, and education experience
    • Passionate about helping every organisation feel confident in their security posture
    HB

    Harpal Bilan

    Cyber Essentials Assessor

    Harpal brings a calm, reassuring approach rooted in his strong data and analytics background. With hands-on experience across data science and security frameworks, he makes the certification process feel straightforward and stress-free. No question is too small, no concern too basic – Harpal is there to guide you through every step and make sure you feel confident and supported throughout.

    • Patient, supportive style – no question is ever too basic
    • Data and analytics background bringing a detail-oriented, methodical approach
    • Dedicated to making your certification journey smooth and worry-free

    A Team That Reflects the Organisations We Serve

    Cyber security is for everyone, and our team reflects that. Whether you're a sole trader or a large enterprise, our assessors bring a welcoming, judgement-free approach. We believe the best security outcomes come when everyone feels comfortable asking questions – no matter their background or experience level.

    Related framework guides