Choose a section
Section 04 / Supplier completes
Issued form · page 3Current cyber assurance
Record certifications you actually hold. Detailed defence cyber assessment follows the requirements of the relevant work.
When this applies
Initial registration records status, not a universal demand for CE+, DCC or a completed project questionnaire.
Help with this section
Open a question for help. The numbers match the printed questions and agreement clauses.
4.1Certification table
What to enter
For each row enter Held, Pending or Not held. If held, provide a current certificate or verification reference that identifies the entity, scope and validity. Include the level for Defence Cyber Certification (DCC). A parent’s certificate does not automatically cover a subsidiary.
Evidence to provide or reference
- Evidence only for certificates claimed. Pending certification must not be described as held.
Where to find it / what to do next
- Check your certificate, certification email or the records held by your IT provider. Identify the legal entity, scope, level and expiry date.
- Use the certificate search below for Cyber Essentials or Cyber Essentials Plus. For DCC, use the evidence from the issuing certification body and record the level.
- If you hold no certificate, enter Not held. If an assessment is underway, use Pending and explain any material issue in 11.1.
Useful external help
Opens in a new tab so you can keep this question open.
- Look up a Cyber Essentials certificate (opens in a new tab)IASME
Search by company name or certificate number and check the level and dates. Confirm a missing or unexpected result with the certificate issuer.
- Practical cyber security for small organisations (opens in a new tab)NCSC
Plain-English steps for email, accounts, devices, backups and spotting attacks. Useful even if you have not started certification.
Ask the issuer to confirm a missing search result or unclear scope. Do not buy a certification just to fill this table; first establish whether the relevant work requires it.
If more detail is needed
For the relevant work only. These are not extra questions in the initial registration.
When defence cyber requirements apply
The addendum or accepted contract identifies the Cyber Security Model version and allocated level, Risk Assessment Reference, DEFSTAN 05-138 issue, Supplier Assurance Questionnaire (SAQ) and any accepted Cyber Improvement Plan. These may be required with a tender, before an order exists.
CSMv4 uses levels 0–3. It requires Cyber Essentials across the levels and CE+ at levels 2 and 3. Valid DCC at the required or higher level is accepted for the corresponding control evidence; other contractual assurance steps still apply.
Under the current 05-138 scope, assess resilience of business-critical operations across the supplier legal entity, including relevant third-party dependencies. Relevant sub-tier work needs its own risk assessment and assurance.
These details are requested only for affected work, by its actual deadline. None of these statements makes every certification a condition of baseline registration.
How to use the addendum →This guide explains form v2.0. It does not amend the issued requirements or approve work, exceptions or information release. Use the external help to find records and understand the rules. For questions about RCDEN's requirements or the proposed work, use the contact in Section 1.2 and quote the question number.
