Choose a section
Section 05 / Supplier completes
Issued form · page 3Information handling and secure design
Flag likely government information or security-related design work so the right requirements can be agreed.
When this applies
The initial form asks one screening question. Standing handling duties are in 13.5–13.7; detailed controls are requested through the addendum when relevant.
Help with this section
Open a question for help. The numbers match the printed questions and agreement clauses.
5.1Anticipated information or design work
What to enter
Select Yes, No currently identified or Not yet determined. This is a trigger for follow-up, not a declaration that an unspecified system is approved. Disclose any inability to meet the standing undertakings in 11.1.
Where to find it / what to do next
- Look at the proposed brief and any information-handling instructions supplied by RCDEN. Check what information or design work you would actually receive.
- If that is not yet clear, choose Not yet determined. Working with a defence business does not by itself identify which government information or design requirements apply.
Useful external help
Opens in a new tab so you can keep this question open.
- Understand government information markings (opens in a new tab)Cabinet Office
Explains classifications, the SENSITIVE marking and handling instructions. The actual owner and contract determine which requirements apply to your work.
- Practical cyber security for small organisations (opens in a new tab)NCSC
Plain-English steps for email, accounts, devices, backups and spotting attacks. Useful even if you have not started certification.
RCDEN must clarify the scope-specific information boundary. You can complete the other registration details while that question is being settled.
If more detail is needed
For the relevant work only. These are not extra questions in the initial registration.
Handling requirements in an addendum
RCDEN identifies the information boundary, Security Aspects Letter (SAL) and security conditions where required. Need-to-know means access only for authorised people who need the information for the agreed purpose. OFFICIAL-SENSITIVE is an additional marking within OFFICIAL.
Relevant evidence may cover access, briefings, storage, transmission, encryption, sharing, retention, destruction and incidents. Cloud and support arrangements must identify processing and access countries; UK storage alone does not answer overseas-access questions.
Follow required incident routes and timescales, including direct MOD reporting where applicable. Notifying RCDEN does not replace a mandatory direct report.
Supply detailed records only through authorised routes and only where required for the scope.
How to use the addendum →Secure by Design and DEFSTAN 05-139
Where design or product assurance duties apply, identify the allocated security requirements, responsible owner, assurance plan and evidence for the agreed lifecycle. This may include threat assessment, design review, verification, vulnerability handling, updates and end of life.
DEFSTAN 05-139 concerns security and resilience of products, systems and services. Record the invoked edition and allocated requirements when it is required. Assess other Secure by Design duties separately; absence of 05-139 does not automatically remove them.
These are work-specific addendum matters. A CE certificate is not a product security approval.
How to use the addendum →This guide explains form v2.0. It does not amend the issued requirements or approve work, exceptions or information release. Use the external help to find records and understand the rules. For questions about RCDEN's requirements or the proposed work, use the contact in Section 1.2 and quote the question number.
