Clarifications
There are 119 clarifications for this DPS
89. If the main bidder has Cyber Essentials and we plan to use a sub-contractor in the EU, do they also need to obtain Cyber Essentials, or can EU firms rely on ISO27001?
DPS Schedule 9 - Cyber Essentials states that 'The Supplier shall ensure that all Sub-Contracts with Subcontractors who
Process Cyber Essentials Data contain provisions no less onerous on the Subcontractors than those imposed on the Supplier under this Contract in
respect of the Cyber Essentials Scheme under Paragraph 2.1 of this Schedule. ' Please remember that any risk associated with subcontracting is responsibility of the Prime.
Answered
19/01/2024 12:47
88. We are going through the SQ process currently. Can you explain "Part 1 Professional or Trade Registers Details", where it asks "1.2.1. What is the name of the register?" - can you advise on which register this refers to?
The name refers to any professional or trade register that you may be registered with in the UK
Answered
19/01/2024 12:46
87. The bid pack makes reference to the supplier's "Data Protection Officer" in the DPS Joint Schedules (1 and 11); the Appointment Form; and DPSQ (question 78). In the Joint Schedules 11, clause 11 it appears that a DPO only needs to be appointed where required by law. The other references appear to make it mandatory to have a DPO in order to register under the DPS.
We do not have a DPO because we are not legally required to have one for the work we currently undertake. We would not apply for any work under the DPS which legally required us to have a DPO.
Please could you clarify whether it is a requirement to have a DPO in order to register with the DPS and/or whether it is necessary to enter into a contract with a buyer. If it is not mandatory we assume that we can answer DPSQ question 78 and the appointment form fields with 'N/A'.
Having a DPO is only necessary where required by legislation (as stated in Joint Schedule 11 'Processing Data'. Not having one does not preclude you from joining the DPS, however you would not be able to bid for work where a DPO was part of the requirements.
Answered
07/12/2023 11:36
86. The 'Buyer Needs' document lists several technical standards which must be complied with in order to register with the DPS. ("comply with the appropriate Standards (or equivalent)")
Please could you confirm whether the supplier must hold a certificate for each of these standards in order to register with the DPS. Please could you confirm whether the supplier must hold a certificate for each of these standards in order to enter into a contract with a buyer. The relevant standards are:- BS EN ISO 9001; BS 7858:2012; ISO 10007; BS EN ISO 14001; ISO/IEC 13066-1:2011; and ETSI TS 103 645.
You do not need to have all of these standards in place in order to join the DPS. However, you will need to have the relevant standards in place where you are bidding for work under the DPS and the customer has stated that this is a requirement of their call off.
Answered
14/12/2023 13:35
85. How can Suppliers know their specified minimum financial threshold score? Can you provide any website links for accessing this information?
Additionally, our UK entity has an annual turnover of £700,000, while our headquarters reports a turnover of £8,229,462.
You would need to contact Dun & Bradstreet with regards to your financial score.
Answered
27/11/2023 11:54
84. In the Supplier Needs document, there is a selection process that includes Pass/Fail questions concerning a specified minimum financial threshold. The supplier must satisfy this requirement. Could you kindly guide how the supplier can achieve a minimum score of 35?
Your assistance in this matter would be highly valued.
It is all to do with their Dun and Bradstreet score which is essentially a credit check using their financial information such as accounts, Companies House returns etc
Answered
06/11/2023 12:58
83. Is it possible to view Contract Notices from the previous year that pertain to contract values associated with a Dynamic Purchasing System (DPS)? Can you provide guidance on how to access this information?
Please be aware that award notices for call offs from any Crown Commercial Service framework agreements would be published on Contracts Finder and Find A Tender (the latter being only for DPS call offs). These are not located within SRS and you would need to access Contracts Finder and/or Find A Tender directly and by using the same logins you have for SRS.
Answered
11/10/2023 16:27
81. I've reviewed the DPS Supplier Needs document. Do we need to submit the Cyber Essentials certification only after being appointed as a supplier, or do we need to provide it when applying in response to the Selection question? Please confirm.
Cyber Essentials is a mandatory requirement and needs to be provided within the application stage for the DPS.
Answered
03/10/2023 13:31
80. Regarding supporting evidence documents, is it sufficient to provide only the Cyber Essentials certification, or are there any additional supporting documents required? Please clarify.
Please see the below list of insurances which are a mandatory requirement: - Employer's (Compulsory) Liability Insurance of £5,000,000.00 minimum - Public Liability Insurance of £1,000,000.00 minimum - Professional Indemnity Insurance of £1,000,000.00 minimum - Cyber Essentials or Cyber Essentials Plus
Please also review and read the Bid Pack.
Answered
03/10/2023 13:33
79. As a service-oriented organization, we intend to provide services exclusively under this contract. Is it truly necessary for us to acquire a product liability insurance certificate, or can we proceed without it?
Please see the below list of insurances which are a mandatory requirement:
- Employer's (Compulsory) Liability Insurance of £5,000,000.00 minimum
- Public Liability Insurance of £1,000,000.00 minimum
- Professional Indemnity Insurance of £1,000,000.00 minimum
- Cyber Essentials or Cyber Essentials Plus
Answered
07/09/2023 10:00
78. We have completed the standard selection questionnaire and can click on 'save and continue'. When we do we are directed to the start of another questionnaire - however it is not labelled DPSQ anywhere. In fact we are asked to give the questionnaire a name and description which doesn't sound right. Can you confirm that we should see DPSQ referenced somewhere? If this sounds like something has failed, can you advise us what we need to do to be able to access the DPSQ?
Please see the link below for the CCS Website, which has all the current DPS frameworks:
https://supplierregistration.cabinetoffice.gov.uk/dps
If you click on the header that the DPS you wish to apply for falls under, it will then open up a new page with the DPS that fall under that header. Against the required DPS, you then need to click on "Access as a supplier".
This will then take you to a log in page for Supplier Registration Service (SRS). If you have login details for Contracts Finder, then you can use these log in credentials to access SRS. If not, located in the top right hand corner, you should see "Register" - click on this and follow the onscreen instructions to register for an account on SRS.
Please also review the Bid Pack which can also be obtained from the link above, prior to submitting an application for the DPS.
Answered
01/09/2023 13:18
77. In relation to obtaining the Cyber Essentials Basic certification, we are currently certified under the ISO 27001 standard and have structured our security protocols according to the guidelines of the NIST Cybersecurity Framework. Furthermore, our ISO 27001 certification, which has been granted by a trusted third party, explicitly verifies that we fulfill all five stipulations outlined in the Cyber Essentials scheme. Is it possible for us to move forward with these existing certifications as part of our application for the Cyber Essentials Basic certification?
Your guidance and support in this matter would be highly valued.
Cyber Essentials certification is a mandatory requirement of the DPS. Please note that Cyber Essentials was developed because neither ISO27001 nor other considered standards were sufficiently prescriptive to defeat common internet based threats as per the PPN.
Answered
01/09/2023 13:15
76. Hi there, is there any scope for the Supplier to raise any deviations to the Terms & Conditions as part of our response? If so, at what point of the process between submitting the SQ+DPSQ and signing a call-off agreement with a buyer would we able to raise these? Thank you.
Core Terms & Conditions of the agreement cannot be changed. Please review the Bid Pack and also the "READ FIRST" document within the Bid Pack for further guidance.
Answered
01/09/2023 13:26
75. Good afternoon, as part of our submission we are proposing a subcontractor who does not yet have the Cyber Essentials accreditation. As per the guidelines they will certify to state that they will achieve this by award onto the DPS and they are currently in the process of completing their Cyber Essentials application. If, for example, they do not achieve certification by the required time, will this void our whole application onto the DPS Framework, or will they just be removed as a subcontractor from our application?
Cyber Essentials is a mandatory requirement for all framework suppliers (directly party to this agreement). Subcontractors need to self certify that they will have this in place as you say but it is down to yourselves as the framework supplier to manage this. Should a customer ask for the subcontractor's Cyber Essentials certification and they didn't have one then the risk would lie with yourselves.
Answered
07/09/2023 09:58
74. Hi. We have reviewed the Schedules and wanted to clarify at what point in the application would we be required to define our Special Terms to incorporate into the Appointment Form with CCS?
Core Terms & Conditions of the agreement cannot be changed. Please review the Bid Pack and also the "READ FIRST" document within the Bid Pack for further guidance.
Answered
01/09/2023 13:27
73. Are the RFP opportunities listed in DPS exclusively accessible to DPS-appointed suppliers, or are they also available through other channels?
The further competitions that are run from the DPS agreement are only open to the suppliers that are on the DPS Agreement. This list will be reduced when the customer completes their shortlisting exercise within SRS to then get a narrowed down list of supliers that can meet their requirement(s). It should not be open to any suppliers that are not on the DPS agreement or the customers shortlist.
Answered
21/08/2023 12:00
72. Regards Q9.1 Cyber essential.
Our Artificial intelligence device it is a stand-alone device (hardware and software are together) that physically connects to endoscopy devices, giving real time diagnostic support to clinician during endoscopy procedures. It does not connect to or network with any other software system. It does not collect or store data and does not transfer data to our AI device to be held for any purpose. This would appear to place us and the device out of scope of cyber essential certification, so can please discuss how we manage this with our framework submission.
Cyber Essentials is a mandatory requirement (PPN 09/14) and is assessed against the company, not the product(s)they provide.
Answered
16/08/2023 15:01
71. One of our subcontractors is based in the US and states that they do not have a Company Registration Number. Can you advise how we can answer the question where this is requested within the Supplier Questionnaire as we cannot progress without entering a number here that meets the format requested. Kind regards
Please enter an 8 digit dummy number in this field to allow you to progress with the Selection Questionnaire.
Answered
16/08/2023 11:47
70. We note in the clarification responses already published it is stated that suppliers do not need to answer question 133, 134 and 135 in regards to contract examples. Q137 relates back to these three questions, therefore how do you wish suppliers to answer or should we put not applicable? Kind regards.
Q137 states 'If you cannot provide at least one example customer contract, in no more than 500 words please provide an explanation for this e.g. your organisation is a new start-up or you have provided services in the past but not under a contract.' If you have provided contract examples you do not need to answer this question, if you have answered 'no' to questions 133,134 and 135 then you will need to provide an answer for Q137 to explain why you have not been able to provide an example in the previous questions.
Answered
16/08/2023 11:46
69. We intend to use a subcontractor that is not based in the UK however the online questionnaire will not accept the format of the postcode and will not let us progress. Can you advise what we should do in this instance please. We note the other questions that advise to use the postcode used when originally setting up an account however this question is in relation to the subcontractor postcode.
The Selection Questionnaire will not accept non-UK postcodes, therefore please enter M4 6JA as a work around and email the correct postcode to support@nqc.com who can complete this offline.
Answered
16/08/2023 11:46