Terms and conditions governing Cyber Essentials and Cyber Essentials Plus certification engagements with Vincent Cyber Defence Ltd.
Vincent Cyber Defence Limited · Company No: 16335932 · Effective: 1 July 2026
Cyber Essentials is a UK Government-backed certification scheme owned by the NCSC and administered by IASME.
Vincent Cyber Defence Limited is an IASME-licensed Certification Body authorised to deliver Cyber Essentials assessments and issue certificates under the scheme.
Two sets of terms apply when you purchase Cyber Essentials or Cyber Essentials Plus from us:
You should read both documents before purchasing. By placing an order or making payment, you confirm you have read and agree to both sets of terms.
Where these Terms and the IASME Terms conflict on a matter relating to the technical assessment, certification process, certificate validity, or use of the IASME mark, the IASME Terms shall prevail. Where they conflict on commercial matters (including fees, payment, refunds, delivery timelines, and cancellation), these Terms shall prevail.
All Cyber Essentials and Cyber Essentials Plus services are provided by Vincent Cyber Defence Limited. Your contractual relationship for those services is with Vincent Cyber Defence Limited.
1.1 In these Terms, the following definitions apply:
1.2 Clause headings do not affect interpretation. References to a person include any individual, company, or unincorporated body. Words in the singular include the plural and vice versa. A reference to a statute includes any amendment or re-enactment. Any words following "including", "such as", or "for example" are illustrative and do not limit the preceding words.
2.1 These Terms govern the provision of all Cyber Essentials and Cyber Essentials Plus services by us. They take precedence over any inconsistent terms in your purchase order, confirmation of order, or specification, or implied by law, trade custom, or course of dealing.
2.2 Your Order is formed when you make payment, tick the checkbox confirming acceptance of these Terms, or instruct us to commence Services - whichever occurs first. These Terms are incorporated into your Order by reference.
2.3 You acknowledge that the Services have not been developed to meet your individual requirements. It is your sole responsibility to ensure that the scope and nature of the Services described in your Order meet your needs before purchasing. We are not obliged to adapt, customise, or modify the Services to suit your particular circumstances unless separately agreed in writing.
2.4 Where there is any conflict between these Terms and your Order, your Order shall prevail on specific scope, fee, and delivery matters. On all other matters, these Terms prevail.
2.5 These Terms apply to your commercial relationship with us. The IASME Terms apply to your relationship with IASME as scheme owner and are incorporated by reference. Where both sets of terms apply, the precedence rules in the intro section above govern.
3.1 We will provide the Services with reasonable care and skill, in accordance with all material aspects of your Order and in compliance with the prevailing Cyber Essentials scheme requirements as published by IASME and the NCSC.
3.2 We will use reasonable endeavours to meet any performance dates specified in your Order, but any such dates are estimates only and time is not of the essence of this Agreement.
3.3 We do not warrant that the Services will be uninterrupted or error-free, or that the Deliverables will meet your individual requirements. We are not responsible for delays or failures resulting from the transfer of data over communications networks or the internet.
3.4 Whilst we will use reasonable endeavours to ensure continuity of personnel, we reserve the right to replace staff, agents, or representatives involved in your Assessment at our sole discretion, with reasonable notice to you where practicable.
3.5 We may engage subcontractors to assist in performing the Services. We remain fully responsible for the quality and delivery of the Services and ensure all subcontractors are bound by confidentiality obligations equivalent to those in these Terms.
3.6 Where we advertise a specific turnaround time guarantee for Cyber Essentials (Basic), that guarantee applies only to complete, compliant submissions received before the advertised cut-off time on a Business Day. It does not apply to Cyber Essentials Plus, incomplete or non-compliant submissions, submissions requiring clarification or remediation, delays caused by you or any third party, or events outside our reasonable control.
4.1 For all Services, you agree to:
4.2 You represent and warrant that you have all necessary rights, power, and authority to provide the Client Materials to us and to permit their use for the purposes of this Agreement.
4.3 If we are prevented or delayed in performing our obligations by any act or omission of yours or your agents, sub-contractors, or personnel, then: (a) we shall not be liable for any resulting delay or failure; (b) we shall be entitled to an extension of time equal to the period of your delay; and (c) we shall be entitled to recover from you any additional costs or expenses we reasonably incur as a result.
This section applies in addition to Clause 4 where you have purchased Cyber Essentials Plus.
5.1 In addition to your obligations under Clause 4, where you have purchased Cyber Essentials Plus you also agree to:
5.2 By purchasing Cyber Essentials Plus, you confirm that:
5.3 You acknowledge and agree that:
6.1 We provide assessment and certification services in accordance with the Cyber Essentials scheme requirements as published by IASME and the NCSC. We do not warrant or guarantee that any particular certification will be achieved, as the outcome depends on your compliance posture and the accuracy of the information you provide.
6.2 No Guaranteed Outcome. Whilst we will provide guidance, support, and best-endeavours assistance throughout the certification process, we do not guarantee that you will achieve a Cyber Essentials or Cyber Essentials Plus certificate. Certification is determined solely by whether your required technical controls are in place and compliant at the time of assessment. The responsibility for implementing, maintaining, and evidencing those controls rests entirely with you. Our role is to assess and advise - not to remediate on your behalf unless separately agreed in writing.
6.3 A Cyber Essentials or Cyber Essentials Plus certificate reflects your security posture at a specific point in time only. It does not constitute an ongoing guarantee of security and does not remain valid if your IT environment changes materially after the date of assessment. The responsibility for maintaining ongoing compliance with Cyber Essentials requirements rests solely with you.
6.4 Certification standards, requirements, and methodologies may be updated or revised by IASME or the NCSC at any time. We have no responsibility for changes to certification criteria occurring after the delivery of the Services or for ongoing compliance beyond the agreed scope.
6.5 The assessment is based solely on the information you provide. We accept no responsibility for the accuracy or completeness of information you submit, and you acknowledge that any inaccurate or incomplete information may affect the validity of the assessment outcome.
7.1 Cyber Essentials (Basic) Assessments cover a maximum of two (2) submission attempts. If your first attempt fails, you have two (2) Business Days to remediate and resubmit. A second failure or missed window requires a new Order and full fee payment, unless additional consultation has been separately agreed and invoiced.
7.2 To achieve Cyber Essentials Plus, you must hold a valid Cyber Essentials Basic certificate issued within the preceding 90 days, in line with IASME/NCSC scheme rules. If your Cyber Essentials Plus assessment is not completed and passed within 90 days of your Basic certificate's issuance date, you must pay a new Cyber Essentials Basic fee and a new Cyber Essentials Plus fee to restart the process.
7.3 You must achieve a "Pass" within 30 calendar days of the initial Cyber Essentials Plus assessment start date. If this window is missed or the assessment fails, a full re-assessment fee is payable.
7.4 Cyber Essentials Plus Sampling & Remediation:
7.5 Retesting. Where you fail a Cyber Essentials Plus Assessment, we will provide a remediation report detailing areas of non-compliance. You are responsible for implementing all remedial actions at your own cost. We accept no responsibility for any failure to achieve certification resulting from your delay in implementing remedial actions or completing the rescan within the 30-day window.
8.1 All Fees are payable in full in cleared funds before we commence work, book testing windows, or grant portal access, unless otherwise agreed in writing on your Order or Invoice.
8.2 Once a Cyber Essentials portal allocation is assigned or technical resources are allocated to an agreed testing window, the corresponding Fees become non-refundable, reflecting irreversible scheme and resource commitments we have made on your behalf.
8.3 All Fees are payable in British Pounds (GBP). You are responsible for all bank charges, intermediary fees, and currency conversion costs to ensure we receive 100% of the invoiced Fee in cleared funds.
8.4 We shall have no obligation to commence Services until payment has been received in full. No service, report, or certificate will be released until all invoices have been paid.
8.5 If you fail to pay on the due date, we reserve the right to: (a) charge interest at 8% per annum above the Bank of England base rate under the Late Payment of Commercial Debts (Interest) Act 1998, accruing daily; (b) suspend all Services without liability until payment is received; and (c) recover fixed-sum compensation and reasonable debt recovery costs permitted by that Act.
8.6 All Fees are exclusive of VAT, which shall be payable at the prevailing rate where applicable.
8.7 All payments are independent of any third-party payment schedules or "paid-when-paid" arrangements.
9.1 You may cancel or reschedule a confirmed Assessment subject to the following charges:
9.2 For the avoidance of doubt, where any portal allocation has been assigned or scheme fees committed before cancellation, those costs remain non-refundable under Clause 8.2 regardless of the notice period given.
9.3 If you fail to attend, fail to provide access, or are otherwise unable to proceed on the agreed date through no fault of ours, the full Fees are payable and a rebooking fee of 50% of the original Fees may be charged for any rescheduled date.
9.4 We reserve the right to reschedule an Assessment with reasonable notice. No cancellation or rebooking fee applies where the rescheduling is initiated by us.
9.5 If you fail to engage, provide data, or submit required information for 6 months, your project will be deemed cancelled and all associated data purged. We will issue a reminder at least 30 days before closure. To resume, you must pay a new Invoice at the then-current rate. No credits from previous invoices will apply.
10.1 You are solely responsible for obtaining express written permission from all third-party providers whose systems or infrastructure are included within the scope of your Assessment.
10.2 By purchasing Cyber Essentials Plus, you warrant that you have the legal right to authorise testing on all targets within your agreed scope. You confirm that there are no legal, contractual, or regulatory restrictions that would prevent or limit this authorisation.
10.3 You shall indemnify us against any losses, costs, or liabilities we reasonably incur as a direct result of any claim, investigation, or prosecution under the Computer Misuse Act 1990 (or equivalent legislation) arising from testing infrastructure for which you failed to secure valid legal authorisation.
11.1 The following provisions set out the entire liability of Vincent Cyber Defence Limited (including any liability for the acts or omissions of our employees, officers, agents, representatives, assessors, subcontractors, and any other person engaged by or on behalf of us) to you arising out of or in connection with this Agreement. Any reference to liability in these Terms means any liability whether in contract, tort (including negligence), misrepresentation, breach of statutory duty, or otherwise.
11.2 We will perform the Services using reasonable skill and care in accordance with generally accepted industry standards.
11.3 Nothing in these Terms excludes or limits our liability for: (a) death or personal injury caused by our negligence; or (b) fraud or fraudulent misrepresentation.
11.4 You acknowledge that: (a) the Services have not been developed to meet your individual requirements and it is your sole responsibility to ensure that the scope and nature of the Services meet your needs before purchasing; (b) we are a specialist consultancy providing fixed-price standardised certification services; (c) the Fees charged reflect the nature, scope, and risk profile of the Services; (d) you had the opportunity to seek independent legal or technical advice before entering into this Agreement; and (e) you could have obtained similar services from alternative providers. You confirm that the limitations and exclusions of liability set out in this clause are reasonable in all the circumstances and represent a fair allocation of risk between us.
11.5 Subject to Clause 11.3, all warranties, representations, conditions, and other terms implied by statute or common law are, to the fullest extent permitted by law, excluded from this Agreement, including without limitation any implied warranties of merchantability, satisfactory quality, or fitness for a particular purpose. The Services and Deliverables are provided on an "as is" basis.
11.6 We shall have no liability for any loss, damage, or liability: (a) caused by the Client Materials or any information, data, or instructions you provide to us; (b) arising from any action we take at your direction or in reliance on information you supply; (c) resulting from your failure to provide accurate, complete, or timely information, access, or cooperation; or (d) arising from your failure to implement recommendations or remedial actions identified in the Deliverables.
11.7 To the fullest extent permitted by law, we shall not be liable for any system downtime, instability, data loss, data corruption, or service interruption arising from the performance of the Services, except where caused by our failure to exercise reasonable skill and care under Clause 11.2.
11.8 We shall not be liable for: (a) any harm caused by the transmission through the Services of any computer virus, malicious code, or similar programming device; (b) any inaccuracy, error, delay, or omission in data or information entered into the Services by you or any third party; (c) any error or delay in transmission of such data; or (d) any interruption in any such data or information.
11.9 We shall not be liable for any changes to certification standards, requirements, or methodologies made by IASME or the NCSC at any time, including changes occurring after the delivery of the Services that affect the validity or standing of any certificate issued. Ongoing compliance with Cyber Essentials requirements is your sole responsibility.
11.10 We shall not be liable for any loss of profits, loss of business, loss of opportunity, loss of data, depletion of goodwill, or any indirect, special, punitive, exemplary, or consequential loss or damage, howsoever arising, even if we have been advised of the possibility of such loss.
11.11 In view of the fact that Cyber Essentials Plus involves technical testing and vulnerability scanning, you positively consent to us conducting the Services within the agreed scope and agree not to bring any action or claim against us arising from the conduct of those Services. We shall not be liable for any losses incurred as a result of such tests or audits, including losses or damage caused to your systems, documents, data, information, networks, or business, except to the extent it would be unlawful for us not to be liable.
11.12 Our total aggregate liability to you, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall in all circumstances be strictly limited to the total Fees paid under the specific Invoice to which the claim relates. You expressly acknowledge that: (a) this cap may represent a modest sum; (b) it is proportionate to the Fees charged for the Services; (c) it reflects the fact that the Services are fixed-price standardised certification services; and (d) you have accepted this cap as a fair and reasonable allocation of commercial risk having had the opportunity to seek independent advice and to obtain services elsewhere.
11.13 Your sole and exclusive remedy in respect of the Services is against Vincent Cyber Defence Limited in its corporate capacity, not against any individual employee, officer, agent, assessor, or subcontractor personally. To the fullest extent permitted by law, we shall have no liability whatsoever for any act, omission, default, negligence, error, failure, breach of duty, or misconduct of any of our employees, officers, agents, representatives, assessors, or subcontractors, howsoever arising.
11.14 Any legal action or claim arising under this Agreement must be commenced within 12 months of the date the final report is delivered or the final invoice is issued, whichever is earlier. After this period, all claims are absolutely time-barred.
12.1 You shall defend, indemnify, and hold harmless Vincent Cyber Defence Limited and its employees, officers, agents, and subcontractors against any and all claims, liabilities, losses, damages, expenses, and costs (including reasonable legal fees) arising out of or in connection with:
13.1 We retain ownership of all Intellectual Property Rights in the Services, Deliverables, and all materials we create in connection with this Agreement, including proprietary methodologies, tools, templates, scanning software, and assessment processes. Nothing in this Agreement transfers any Intellectual Property Rights from us to you.
13.2 Upon full payment, we grant you a non-exclusive, non-sublicensable, non-transferable, worldwide licence to use the Deliverables for your reasonable internal business purposes only.
13.3 You own all rights in the Client Materials you provide to us. You grant us a non-exclusive licence to use, review, and copy the Client Materials to the extent necessary to perform the Services.
13.4 Cyber Essentials reports and certificates are issued via The IASME Consortium. Their use, validity, and distribution are subject to IASME's terms and conditions. These Terms do not grant you any rights to NCSC, IASME, or Cyber Essentials branding except as permitted by those trademark owners upon successful certification.
13.5 You may share copies of Deliverables with third parties (such as regulators, auditors, or clients) on a strictly "as is" basis, provided you do not remove any copyright or disclaimer notices and you ensure recipients are aware of the limitations and exclusions of liability in these Terms. We have no liability to any third party to whom you disclose our Deliverables.
14.1 Each party agrees to keep confidential all technical, commercial, and business information disclosed by the other in connection with the Services, including security findings, reports, systems, and vulnerabilities.
14.2 Confidential Information shall not be disclosed to any third party without prior written consent, except to employees, contractors, professional advisers, or insurers bound by equivalent confidentiality obligations, or where disclosure is required by law.
14.3 This obligation does not apply to information that is publicly available (other than through breach), independently developed, or lawfully received from a third party.
14.4 These confidentiality obligations survive termination of this Agreement for five (5) years.
15.1 Both parties shall comply with all applicable data protection laws, including the UK GDPR and the Data Protection Act 2018. You are the Data Controller and we are the Data Processor in relation to any personal data processed in connection with the Services.
15.2 We will process personal data only on your documented instructions to perform the Services. All staff processing personal data are subject to confidentiality obligations and appropriate technical and organisational security measures.
15.3 We will notify you without undue delay (and in any event within 72 hours) upon becoming aware of any personal data breach or significant security incident affecting your data.
15.4 We will securely destroy all temporary technical data as soon as practicable following delivery of your final report. Your Cyber Essentials Assessment Answers and Certificate are hosted by IASME - their retention is subject to IASME's policies. We retain your final report for 12 months from issuance for download and remediation support, after which it is permanently purged. We retain a secure record of your Invoice and any associated scheme documents (including sampling forms and authorisation records) for 6 years for legal and insurance purposes.
15.5 We may appoint sub-processors without your prior consent, provided any such appointment is subject to data protection obligations no less onerous than those in these Terms. We will inform you of any intended changes to sub-processors and give you the opportunity to object.
16.1 Either party may terminate this Agreement immediately if the other: (a) fails to pay any amount due and remains in default 7 days after written notice; (b) commits a material breach that remains uncured for 14 days after written notice; or (c) becomes insolvent or unable to pay its debts as they fall due.
16.2 You may cancel your Order at any time, but all Fees paid are non-refundable upon receipt of cleared funds by us. Where phased payment was agreed, any work performed to the date of cancellation shall be invoiced immediately and becomes due within 7 days.
16.3 Upon termination: (a) all licences granted to you cease immediately; (b) all outstanding amounts become due immediately; (c) each party shall return or permanently delete the other's Confidential Information on written request, except where retention is required by law; and (d) you shall cease all use of the Deliverables and Services.
16.4 We reserve the right to suspend the Services immediately and without notice if we reasonably believe your systems or actions pose an immediate security risk, legal liability, or are being used for unauthorised or illegal activity.
17.1 Governing Law & Jurisdiction. These Terms are governed by the laws of England and Wales. The parties irrevocably agree that the courts of England and Wales have exclusive jurisdiction to settle any dispute or claim arising out of or in connection with these Terms, regardless of your country of residence, incorporation, or the location from which you access the Services.
17.2 Dispute Resolution. Before commencing court proceedings (except for urgent interim relief), the parties agree to first attempt good faith negotiation for 14 days, then mediation administered by the Centre for Effective Dispute Resolution (CEDR) for up to 30 days. If unresolved, either party may commence court proceedings.
17.3 Invoice Disputes. If you dispute any invoice, you must notify us in writing within 7 days of receipt, setting out the grounds and specific amount disputed. Failure to do so constitutes acceptance of the invoice. You must pay all undisputed amounts by the due date regardless of any dispute.
17.4 Variation. No variation to these Terms is effective unless agreed in writing and signed by both parties.
17.5 Entire Agreement. These Terms, together with your Order, constitute the entire agreement between us and supersede all prior arrangements, representations, or understandings. You confirm you have not relied on any representation or warranty not set out in these Terms.
17.6 Severability. If any provision is found unenforceable, the remaining provisions remain in full force.
17.7 Waiver. No failure or delay to exercise any right or remedy constitutes a waiver of that right or remedy.
17.8 Assignment. You may not assign or transfer your rights or obligations without our prior written consent. We may assign or transfer this Agreement at any time.
17.9 No Partnership. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between the parties.
17.10 Third Party Rights. These Terms do not confer any rights on any third party. The Contracts (Rights of Third Parties) Act 1999 does not apply to this Agreement.
17.11 Notices. Any notice under these Terms must be in writing and sent by email to the address provided in your Order. Email notices are deemed received at 9am on the next Business Day following transmission.
17.12 Non-Solicitation. You agree not to solicit, hire, or engage any of our employees or contractors involved in your Services for 12 months following completion. If you breach this clause, you shall pay us a sum equal to 50% of that individual's annual gross salary or fees as liquidated damages.
17.13 Force Majeure. Neither party is liable for delays or failures caused by events beyond their reasonable control. If such an event continues for more than 30 days, either party may terminate. You remain liable for all Fees for Services already delivered or resources already committed.
By placing an order, making payment, or ticking the acceptance checkbox on our website or order form, you confirm that:
We reserve the right to update these Terms at any time. The version in force at the date of your Order applies to that Order.
Vincent Cyber Defence Limited · Company No: 16335932 · Registered in England and Wales