- Report A Mistake
Procurement Fairness and Framework Review
Help us improve fairness, transparency and professional recognition across cyber security procurement.
As the cyber security profession continues to evolve, procurement frameworks should reflect current standards, recognised assurance routes and professional practice. Unfortunately, some frameworks continue to reference outdated organisations or accreditation route in circumstances where equivalent NCSC-approved pathways and professional title-based assurance models have succeeded these.
The Cyber Scheme is committed to supporting fair and open practices. If you identify procurement framework wording that appears to unfairly restrict supplier participation or is counter to public policy, then we would like to hear from you.
When Should You Report an Issue?
You may wish to submit a report if a procurement framework:
- References (including but not exclusively CREST, CISSP etc) as the sole indicator of supplier capability where equivalent routes exist.
- Specifies requirements that may unintentionally exclude organisations using recognised alternative assurance pathways.
- Does not appear to reflect current NCSC requirements or UK Cyber Security Council professional title requirements.
- Creates barriers to market access without a clearly justified technical or regulatory reason.
Â
Our aim is not to criticise framework owners, but to encourage procurement wording that accurately reflects government policy, industry best practices and the current professional standards for skills and capability.
Submit a Framework Issue Report
Reports can be submitted by accredited companies, suppliers, professionals or other stakeholders.
Anonymous reporting is available.
"Restrictive accreditation requirements are only one example of how procurement wording can unintentionally disadvantage capable suppliers. The cyber security industry also faces challenges around unrealistic reference requirements, despite the confidential nature of security testing work, and poorly defined scopes that make it difficult for buyers to compare suppliers on a genuine like-for-like basis. Fair procurement depends on clear requirements, proportionate evaluation criteria and recognition of the different routes through which organisations can demonstrate competence and capability."
Andy Swift, Cyber Security Assurance Technical Director, Six Degrees Group
The reporting form will ask for:
- Name of procurement framework owner.
- Name of procurement framework.
- The wording, text or link that you are concerned about.
- Contact details for the framework owner.
- An explanation of why you believe the wording may not reflect fair procurement practices.
- Any supporting information you would like us to consider.
Reporter name and organisation details are optional.
What Happens After You Submit a Report?
Step 1 – Review and Validation
The Cyber Scheme will review the information provided and validate that:
- The framework contains the wording identified.
- The concern relates to current professional standards, accreditation routes or procurement fairness.
- Sufficient information has been provided for us to engage with the framework owner.
Step 2 – Initial Contact with the Framework Owner
Where appropriate, The Cyber Scheme will contact the procurement framework owner to request a review of the wording.
The purpose of this correspondence is to:
- Highlight current NCSC/DCMS/UK Cyber Security Council requirements where relevant.
- Explain the availability of recognised alternative assurance routes, and the necessity to include these.
- Encourage wording that recognises equivalent professional title-based and accreditation-based approaches.
- Seek clarification where the rationale for the wording is unclear.
Framework owners will normally be asked to respond within 10 working days.
Step 3 – Follow-Up
If no response is received, a follow-up request will be issued asking for a response within a further 5 working days.
The follow-up will again seek clarification and encourage consideration of equivalent assurance routes and professional standards.
Step 4 – Escalation
Where repeated attempts to engage are unsuccessful, The Cyber Scheme may consider escalating the matter to a senior procurement or commercial decision-maker within the organisation.
For public sector organisations, any escalation will focus on ensuring procurement wording supports fair supplier access and appropriately recognises current professional standards and assurance routes.
our approach
The Cyber Scheme believes procurement frameworks should:
- Support fair and open competition.
- Recognise current industry standards and professional requirements.
- Avoid unintentionally creating monopolistic outcomes.
- Enable buyers to identify competent suppliers through a range of recognised assurance mechanisms.
- Reflect the growing importance of UK Cyber Security Council professional titles as an independent measure of competence.
All reports are reviewed objectively and professionally. Our role is to encourage constructive dialogue, promote accurate procurement terminology and support fair recognition of all legitimate routes to demonstrating cyber security capability.
Please note, we encourage reporting of issues you find outside of this scope, including misuse of our certifications or brand, non-ethical behaviour or sharing of assessment materials. Please contact us if you wish to let us know of practices which concern you.