Why Your Clients are About to Ask for Your Cyber Essentials Certificate

Close-up of hands typing on a laptop displaying cybersecurity graphics, illuminated by purple light.Daly Whyte, founder of Solusec, explains how new government and defence initiatives are turning cyber security into a commercial requirement for recruitment agencies.

Recruitment agencies sit on some of the most valuable data a criminal could want. Passports and right-to-work documents, CVs full of personal histories, National Insurance numbers, bank details for contractor payroll: it is all there, spread across an applicant tracking system, a shared inbox and a handful of cloud tools. Add a steady flow of invoices and payments, and an agency is an ideal target for data theft and invoice fraud.

For a long time, the question of how secure an agency was stayed largely internal. That is changing, and it is changing because of the agencies’ clients.

The Cyber Resilience Pledge

This year, the UK government launched the Cyber Resilience Pledge, a voluntary commitment aimed mainly at medium and large organisations. Signatories agree to three things:

  1. Make cyber security a board-level responsibility, with board members completing the NCSC’s Cyber Governance Training.
  2. Register for the NCSC’s free Early Warning service.
  3. Take a risk-based approach to requiring Cyber Essentials across their supply chain, including auditing supplier coverage with a new Cyber Essentials Supplier Check Tool.

The third commitment is the one that matters for recruiters. When a large employer signs the Pledge, it commits to reviewing whether its suppliers hold Cyber Essentials. “Risk-based” means it will look first at suppliers that handle sensitive data or connect to its systems.

A recruitment agency placing staff with that employer handles candidate identity documents, may process contractor payroll, and often has access to client portals or hiring systems. That puts agencies near the top of any sensible risk-based list.

The Pledge is voluntary, but the pressure it creates is commercial. When a client’s procurement team asks “do you hold Cyber Essentials?”, “we take cyber security seriously” will not be an acceptable answer. They are likely to ask for the certificate number. Agencies without one may face additional scrutiny, and could find it harder to meet the requirements of clients that expect certification, particularly at tender or renewal.

Defence: a firm deadline

For agencies that place staff in defence, there is a harder date. The Ministry of Defence has asked all defence industry partners to reach Defence Cyber Certification (DCC) Level 0 by 31 December 2026, and expects the requirement to flow down the supply chain, with suppliers encouraged to set appropriate timescales for their own subcontractors.

Level 0 is the entry point of the scheme. It requires a current Cyber Essentials certificate covering the organisation’s business-critical systems, along with evidence of basic data protection and business resilience arrangements. If your agency supplies contractors or permanent staff to defence primes, or to their supply chains, expect to be asked about DCC. You can’t get DCC without Cyber Essentials first.

What Cyber Essentials actually involves

Cyber Essentials is the government-backed certification covering five technical controls: firewalls, secure configuration, security updates, user access control and malware protection. These controls defend against the majority of common, opportunistic attacks. For most small and medium agencies, the certification is affordable and achievable in weeks rather than months, provided the groundwork is done first.

 

Three points catch agencies out:

  • Certification has to cover the systems the business actually runs on. That includes the laptops and phones consultants use for email and the ATS, and it includes cloud services. A certificate covering only part of the business may not satisfy a client, and for DCC a mismatched scope is a straightforward fail.
  • Personal devices. Consultants checking email or messaging candidates on their own phones bring those devices into scope. Decide on a policy before you start the assessment, not during it.
  • The requirement usually arrives with a deadline attached, such as a tender, an onboarding pack or a contract renewal. Agencies that certify before being asked are in a much stronger position than those racing a closing date. If it has been left late, some certification bodies offer fast-track routes such as Fast Cyber Essentials, but the controls still need to be in place, so it pays to start early.

For agencies whose clients expect more, Cyber Essentials Plus adds an independent technical audit of those same controls. That is also the level DCC requires from Level 2 upwards.

What to do now

  • Ask your largest clients whether they have signed the Cyber Resilience Pledge, or whether they plan to review supplier certifications.
  • If you place staff in defence, check what your clients will require of you before 31 December 2026.
  • Map where candidate and client data lives. That map becomes your Cyber Essentials scope.
  • Certify before a tender forces you to. It is far easier to plan than to rush.

Cyber security is fast becoming part of what clients buy when they choose a recruitment partner. Agencies that can show they protect candidate and client data will be better prepared for the procurement checks more clients are starting to carry out.

Daly Whyte is the founder of Solusec, a CREST-accredited cyber security company and IASME Certification Body for Cyber Essentials, IASME Cyber Assurance and Defence Cyber Certification. He has more than 25 years in IT and security and is a Recognised Practitioner of Cyber Security from the UK Cyber Security Council.

Our Partners

Blog Categories

Related Posts