Skip to main content
RCDEN
SystemsServicesPartnersNewsAboutAssuranceContactInvestor information
Start a project ↗
RCDEN // NavigationMobile / Active
←Back to RCDEN
01Systems↗02Services↗03Partners↗04News↗05About↗06Assurance↗07Contact↗08Investor information↗
Start a project↗
  1. Home
  2. Policies
  3. Supplier guide
  4. 05 Information handling and secure design

Supplier registration

Your guide to the form.

—Before you start01Start the registration02Company details and ownership03Security contact and clearances04Current cyber assurance05Information handling and secure design06Export controls and sanctions07Ethics and statutory statements08Insurance and financial standing09Quality and sub-tier duties10Data protection11Exceptions and evidence12RCDEN’s registration review13Agreement and signaturesAWork-specific addendum

Use the copy issued to your company. This website provides guidance; supplier documents are supplied directly by RCDEN.

Choose a section +
—Before you start01Start the registration02Company details and ownership03Security contact and clearances04Current cyber assurance05Information handling and secure design06Export controls and sanctions07Ethics and statutory statements08Insurance and financial standing09Quality and sub-tier duties10Data protection11Exceptions and evidence12RCDEN’s registration review13Agreement and signaturesAWork-specific addendum

Section 05 / Supplier completes

Issued form · page 3

Information handling and secure design

Flag likely government information or security-related design work so the right requirements can be agreed.

When this applies

The initial form asks one screening question. Standing handling duties are in 13.5–13.7; detailed controls are requested through the addendum when relevant.

Help with this section

Open a question for help. The numbers match the printed questions and agreement clauses.

5.1

Anticipated information or design work

+

What to enter

Select Yes, No currently identified or Not yet determined. This is a trigger for follow-up, not a declaration that an unspecified system is approved. Disclose any inability to meet the standing undertakings in 11.1.

Where to find it / what to do next

  1. Look at the proposed brief and any information-handling instructions supplied by RCDEN. Check what information or design work you would actually receive.
  2. If that is not yet clear, choose Not yet determined. Working with a defence business does not by itself identify which government information or design requirements apply.

Useful external help

Opens in a new tab so you can keep this question open.

  • Understand government information markings ↗ (opens in a new tab)Cabinet Office

    Explains classifications, the SENSITIVE marking and handling instructions. The actual owner and contract determine which requirements apply to your work.

  • Practical cyber security for small organisations ↗ (opens in a new tab)NCSC

    Plain-English steps for email, accounts, devices, backups and spotting attacks. Useful even if you have not started certification.

If you are still unsure

RCDEN must clarify the scope-specific information boundary. You can complete the other registration details while that question is being settled.

Link to question 5.1 ↗Your issued form · page 3

If more detail is needed

For the relevant work only. These are not extra questions in the initial registration.

Handling requirements in an addendum+

RCDEN identifies the information boundary, Security Aspects Letter (SAL) and security conditions where required. Need-to-know means access only for authorised people who need the information for the agreed purpose. OFFICIAL-SENSITIVE is an additional marking within OFFICIAL.

Relevant evidence may cover access, briefings, storage, transmission, encryption, sharing, retention, destruction and incidents. Cloud and support arrangements must identify processing and access countries; UK storage alone does not answer overseas-access questions.

Follow required incident routes and timescales, including direct MOD reporting where applicable. Notifying RCDEN does not replace a mandatory direct report.

Supply detailed records only through authorised routes and only where required for the scope.

How to use the addendum →
Secure by Design and DEFSTAN 05-139+

Where design or product assurance duties apply, identify the allocated security requirements, responsible owner, assurance plan and evidence for the agreed lifecycle. This may include threat assessment, design review, verification, vulnerability handling, updates and end of life.

DEFSTAN 05-139 concerns security and resilience of products, systems and services. Record the invoked edition and allocated requirements when it is required. Assess other Secure by Design duties separately; absence of 05-139 does not automatically remove them.

These are work-specific addendum matters. A CE certificate is not a product security approval.

How to use the addendum →
Before you move on

Agree the relevant boundary before access or design. The guide and form are not routes for uploading controlled information.

Have these ready

  • A brief understanding of the anticipated work.
  • Any supplied handling instructions.

Further reading

Start with the practical help beside each question. These official sources explain the underlying rules if you need more detail.

Cabinet OfficeClassifications and handling guidance↗ (opens in a new tab)MODIncident reporting — ISN 2025/03 (PDF)↗ (opens in a new tab)MODCloud security requirements — ISN 2024/06 (PDF)↗ (opens in a new tab)MODSecure by Design — ISN 2023/09 (PDF)↗ (opens in a new tab)MODProject checklist and 05-139 applicability↗ (opens in a new tab)

The signed agreement and identified work-specific schedules determine the obligations. Official guidance explains their legal or contractual basis.

When to use an addendum →
← Previous04 Current cyber assuranceNext →06 Export controls and sanctions

This guide explains form v2.0. It does not amend the issued requirements or approve work, exceptions or information release. Use the external help to find records and understand the rules. For questions about RCDEN's requirements or the proposed work, use the contact in Section 1.2 and quote the question number.

RCDEN

RCDEN | INTELLIGENT UNMANNED SYSTEMS

sales@rcden.co.uk ↗
Follow RCDENLinkedIn ↗ (opens in a new tab)Facebook ↗ (opens in a new tab)
THE RC DEN LTDRegistered in England and Wales · Company no. 14639255Customer-facing workshop: Unit 8, Blackwood Court, Teal Park, North Hykeham, Lincoln, LN6 3AERegistered office: Unit 8 Blackwood Court, Lincoln, England, LN6 3AE
HomeServicesTechnology partnersAboutAssuranceNewsEngineering resourcesRSS updatesPoliciesContactInvestor informationBrand guidePrivacy & cookies

Supplier guidance · Form v2.0 · Reviewed 08 September 2026

© 2026 THE RC DEN LTD