Skip to main content
RCDEN
SystemsServicesPartnersNewsAboutAssuranceContactInvestor information
Start a project ↗
RCDEN // NavigationMobile / Active
←Back to RCDEN
01Systems↗02Services↗03Partners↗04News↗05About↗06Assurance↗07Contact↗08Investor information↗
Start a project↗
  1. Home
  2. Policies
  3. Supplier guide
  4. 04 Current cyber assurance

Supplier registration

Your guide to the form.

—Before you start01Start the registration02Company details and ownership03Security contact and clearances04Current cyber assurance05Information handling and secure design06Export controls and sanctions07Ethics and statutory statements08Insurance and financial standing09Quality and sub-tier duties10Data protection11Exceptions and evidence12RCDEN’s registration review13Agreement and signaturesAWork-specific addendum

Use the copy issued to your company. This website provides guidance; supplier documents are supplied directly by RCDEN.

Choose a section +
—Before you start01Start the registration02Company details and ownership03Security contact and clearances04Current cyber assurance05Information handling and secure design06Export controls and sanctions07Ethics and statutory statements08Insurance and financial standing09Quality and sub-tier duties10Data protection11Exceptions and evidence12RCDEN’s registration review13Agreement and signaturesAWork-specific addendum

Section 04 / Supplier completes

Issued form · page 3

Current cyber assurance

Record certifications you actually hold. Detailed defence cyber assessment follows the requirements of the relevant work.

When this applies

Initial registration records status, not a universal demand for CE+, DCC or a completed project questionnaire.

Help with this section

Open a question for help. The numbers match the printed questions and agreement clauses.

4.1

Certification table

+

What to enter

For each row enter Held, Pending or Not held. If held, provide a current certificate or verification reference that identifies the entity, scope and validity. Include the level for Defence Cyber Certification (DCC). A parent’s certificate does not automatically cover a subsidiary.

Evidence to provide or reference

  • Evidence only for certificates claimed. Pending certification must not be described as held.

Where to find it / what to do next

  1. Check your certificate, certification email or the records held by your IT provider. Identify the legal entity, scope, level and expiry date.
  2. Use the certificate search below for Cyber Essentials or Cyber Essentials Plus. For DCC, use the evidence from the issuing certification body and record the level.
  3. If you hold no certificate, enter Not held. If an assessment is underway, use Pending and explain any material issue in 11.1.

Useful external help

Opens in a new tab so you can keep this question open.

  • Look up a Cyber Essentials certificate ↗ (opens in a new tab)IASME

    Search by company name or certificate number and check the level and dates. Confirm a missing or unexpected result with the certificate issuer.

  • Practical cyber security for small organisations ↗ (opens in a new tab)NCSC

    Plain-English steps for email, accounts, devices, backups and spotting attacks. Useful even if you have not started certification.

If you are still unsure

Ask the issuer to confirm a missing search result or unclear scope. Do not buy a certification just to fill this table; first establish whether the relevant work requires it.

Link to question 4.1 ↗Your issued form · page 3

If more detail is needed

For the relevant work only. These are not extra questions in the initial registration.

When defence cyber requirements apply+

The addendum or accepted contract identifies the Cyber Security Model version and allocated level, Risk Assessment Reference, DEFSTAN 05-138 issue, Supplier Assurance Questionnaire (SAQ) and any accepted Cyber Improvement Plan. These may be required with a tender, before an order exists.

CSMv4 uses levels 0–3. It requires Cyber Essentials across the levels and CE+ at levels 2 and 3. Valid DCC at the required or higher level is accepted for the corresponding control evidence; other contractual assurance steps still apply.

Under the current 05-138 scope, assess resilience of business-critical operations across the supplier legal entity, including relevant third-party dependencies. Relevant sub-tier work needs its own risk assessment and assurance.

These details are requested only for affected work, by its actual deadline. None of these statements makes every certification a condition of baseline registration.

How to use the addendum →
Before you move on

Use Not held honestly. If a certificate is required for particular work, the requirement or an authorised accepted plan must be resolved by the relevant deadline.

Have these ready

  • Current certificates or verification links, if held.
  • The certified entity, scope and validity shown by that evidence.

Further reading

Start with the practical help beside each question. These official sources explain the underlying rules if you need more detail.

MODCyber Security Model and SAQ process↗ (opens in a new tab)NCSCCyber Essentials explained↗ (opens in a new tab)IASMEDefence Cyber Certification↗ (opens in a new tab)MODAccepting DCC evidence — ISN 2026/02 (PDF)↗ (opens in a new tab)MODAssessment scope — ISN 2026/01 (PDF)↗ (opens in a new tab)

The signed agreement and identified work-specific schedules determine the obligations. Official guidance explains their legal or contractual basis.

When to use an addendum →
← Previous03 Security contact and clearancesNext →05 Information handling and secure design

This guide explains form v2.0. It does not amend the issued requirements or approve work, exceptions or information release. Use the external help to find records and understand the rules. For questions about RCDEN's requirements or the proposed work, use the contact in Section 1.2 and quote the question number.

RCDEN

RCDEN | INTELLIGENT UNMANNED SYSTEMS

sales@rcden.co.uk ↗
Follow RCDENLinkedIn ↗ (opens in a new tab)Facebook ↗ (opens in a new tab)
THE RC DEN LTDRegistered in England and Wales · Company no. 14639255Customer-facing workshop: Unit 8, Blackwood Court, Teal Park, North Hykeham, Lincoln, LN6 3AERegistered office: Unit 8 Blackwood Court, Lincoln, England, LN6 3AE
HomeServicesTechnology partnersAboutAssuranceNewsEngineering resourcesRSS updatesPoliciesContactInvestor informationBrand guidePrivacy & cookies

Supplier guidance · Form v2.0 · Reviewed 08 September 2026

© 2026 THE RC DEN LTD