Legal aid and Cyber Essentials: the LAA requirement, equivalents and ISO 27001
A “valid and current Cyber Essentials Certificate or an equivalent certification as may be agreed with us” — 2025 Standard Crime Contract, Standard Terms.
Since the 2025 Standard Crime Contract, legal aid firms doing criminal work have a contractual security certification requirement: Cyber Essentials. The contract and the LAA's own guidance also provide for an equivalent, and name a UKAS-accredited ISO 27001 certificate covering the whole firm as highly likely to count. This page quotes the documents.
What the contract says
Clause 16.19 of the standard terms: “You shall (and shall ensure that all Approved Third Parties) have, maintain throughout the term of the Contract and demonstrate upon request a valid and current Cyber Essentials Certificate or an equivalent certification as may be agreed with us. You shall provide a copy of your Cyber Essentials Certificate or equivalent certification to the LAA at least four (4) weeks prior to any applicable Audit. You shall deliver to us evidence of renewal of the Cyber Essentials Certificate or the equivalent certification on each anniversary of the first applicable certificate obtained by you.”
Which certificate
The contract defines the certificate it means as the Cyber Essentials Basic Certificate: “the certificate awarded on the basis of the self-assessment, verified by an independent certification body, under the Cyber Essentials Scheme and is the basic level of assurance”. Cyber Essentials Plus is not required by the contract.
The term
The contract runs from 1 October 2025 to 30 September 2035. The certificate has to be held throughout and renewal evidenced on each anniversary; the LAA's welcome pack notes “Cyber Essentials Certification is valid for 12 months”.
Approved Third Parties
The clause binds the firm to ensure Approved Third Parties hold it too. They are defined as “an individual or organisation engaged by you to undertake non-legal work ancillary to Contract Work, including experts and translators but excluding Agents and Counsel”. An interpreter or expert engaged on legal aid work is inside that definition — our reading of the plain words.
The Data Security Requirements v5
Clause 16.5: “You must at all times for the duration of this Contract comply with the Data Security Requirements and have regard to the Data Security Guidance and any guidance issued by the Information Commissioner’s Office.” Which version applies depends on the contract: “Version 5 of the Data Security Requirements and Guidance apply to all contracts coming into force on or after 1st October 2025.” Earlier contracts follow earlier versions: “Version 4 of the Data Security Requirements and Guidance apply to all contracts coming into force on or after 1st September 2024 and before 1st October 2025”.
Cyber Essentials replaced the LAA's own technical list
“From version 5 of these requirements, LAA’s own technical requirements have been replaced by alignment to Cyber Essentials.” “All providers are required to hold Cyber Essentials certification at the point their contract comes into force, and for the duration that they undertake contract work.”
The mandatory requirements
| No. | Requirement |
|---|---|
| 01 | Register as a Data Controller |
| 02 | Appoint a Data Protection Supervisor |
| 04 | Maintain a level of staff awareness |
| 05a | Have a coherent set of policies |
| 06 | Undertake an annual review |
| 07 | Have in place an Incident Management Policy |
| 10 | Conduct Data Protection Impact Assessments |
| 11 | Conduct staff screening |
| 13 | Maintain access records |
| 14 | Maintain adequate physical security |
| 15 | Implement controlled disposal of records |
| 16a | Secure disposal |
| 19a | Cyber Essentials |
| 20 | Ensure Business Continuity |
The recommended requirements
| No. | Requirement |
|---|---|
| 03 | Foster a culture that values and protects information |
| 05b | Have a coherent set of policies |
| 08 | Monitor and Report |
| 09 | Implement a ‘whistle-blowing’ procedure |
| 12 | Control access to personal data |
| 16b | Secure disposal |
| 17 | Conduct formal, documented risk assessments |
| 18 | Apply appropriate controls |
| 19b | Cyber Essentials Plus |
Requirement 18, recommended, points at ISO 27001 directly: “Controls and control objectives for risk treatment should be selected from Annex A to ISO 27001, additional controls and control objectives may also be selected.”
Equivalents, and where ISO 27001 fits
“Equivalent standards will be considered by LAA on a case-by-case basis as alternatives to Cyber Essentials.” “A standard will be considered equivalent where it has been assessed by a UKAS accredited assessor and allows organisations to demonstrate compliance with technical controls in the areas of:”
| Area |
|---|
| Secure configuration |
| User access control |
| Malware protection |
| Security update management |
| Firewalls |
They are the same five control themes the NCSC's Cyber Essentials requirements set out (Firewalls, Secure Configuration, Security Update Management, User Access Control, Malware Protection). Then the guidance names ISO 27001:
“There is no defined list of equivalent standards, but it is highly likely that ISO27001 accreditation, where that accreditation has been assessed by a UKAS accredited assessor and where the scope of the accreditation covers the whole organisation and includes the 5 technical areas noted above will be considered equivalent.”
What that means for an ISO 27001 certificate (our reading)
| Condition | LAA wording | Check |
|---|---|---|
| UKAS-accredited | “assessed by a UKAS accredited assessor” | Your certificate is from a UKAS-accredited certification body |
| Whole organisation | “the scope of the accreditation covers the whole organisation” | The scope line names the whole firm, not one office or one service |
| Five technical areas | “includes the 5 technical areas noted above” | Controls for secure configuration, access, malware, updates and firewalls are in the Statement of Applicability |
| Agreed with the LAA | “as may be agreed with us” (clause 16.19) | Equivalence is the LAA's decision, case by case — not the firm's |
Check the scope first
A certificate scoped to one office, one practice area or one IT service does not cover “the whole organisation”. Read the scope line before relying on it. See certificate verification.
ISO 27001 itself is not required
“Providers are not required to be certified to this standard, however they must provide written confirmation that any information assets as identified in section 2.4 are managed in line with best practice as detailed in this standard.” Among what provider policies must do: “Conform to ISO 27001 and ISO 27002 good security practices.” — good practice, not certification.
Cyber Essentials or ISO 27001: which to hold (our reading)
A firm with neither
Cyber Essentials is what the contract names. ISO 27001 is a whole management system; it is worth weighing only if clients or other contracts also ask for it. The difference is on ISO 27001 vs Cyber Essentials.
A firm with ISO 27001 already
If the certificate is UKAS-accredited, covers the whole firm and includes the five areas, ask the LAA to agree it as the equivalent under clause 16.19 — in writing, before the date the certificate would be due.
Before an LAA audit
Clause 16.19 asks for a copy of the certificate, or the agreed equivalent, at least four weeks before any applicable audit. Keep the renewal evidence for each anniversary with it.
We do not give legal advice, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The requirements are quoted from the LAA's published contract and guidance; the check columns are our reading.
Where this fits
- Law firm cyber security
- ISO 27001 vs Cyber Essentials
- UKAS-accredited certification bodies
- Public sector suppliers
Common questions
Do legal aid firms need Cyber Essentials?
Under the 2025 Standard Crime Contract, yes, or an equivalent the LAA agrees. Clause 16.19 requires a valid and current Cyber Essentials Certificate “or an equivalent certification as may be agreed with us”, and the LAA's Data Security Requirements v5 make it mandatory: “To hold Cyber Essentials certification for the life of the contract, or an equivalent standard.”
When did the Cyber Essentials requirement start?
With the contract. The standard terms are effective from 1 October 2025, and “Version 5 of the Data Security Requirements and Guidance apply to all contracts coming into force on or after 1st October 2025.” The guidance: “All providers are required to hold Cyber Essentials certification at the point their contract comes into force, and for the duration that they undertake contract work.”
Can ISO 27001 be used instead of Cyber Essentials for legal aid?
Possibly, if the LAA agrees. “Equivalent standards will be considered by LAA on a case-by-case basis as alternatives to Cyber Essentials.” And: “There is no defined list of equivalent standards, but it is highly likely that ISO27001 accreditation, where that accreditation has been assessed by a UKAS accredited assessor and where the scope of the accreditation covers the whole organisation and includes the 5 technical areas noted above will be considered equivalent.”
Is Cyber Essentials Plus required?
Recommended, not mandatory. Requirement 19b: “To hold Cyber Essentials Plus certification and renew / maintain as required, or an equivalent standard.” “LAA continues to recommend Cyber Essentials Plus.”
Do experts and translators need Cyber Essentials too?
Clause 16.19 applies to the provider “and shall ensure that all Approved Third Parties”, defined as “an individual or organisation engaged by you to undertake non-legal work ancillary to Contract Work, including experts and translators but excluding Agents and Counsel”.
Do legal aid firms need ISO 27001?
No. The LAA's guidance on ISO 27001 and ISO 27002: “Providers are not required to be certified to this standard, however they must provide written confirmation that any information assets as identified in section 2.4 are managed in line with best practice as detailed in this standard.”
How often does the certificate need renewing?
The LAA's welcome pack: “Cyber Essentials Certification is valid for 12 months”. Clause 16.19 requires evidence of renewal on each anniversary, and a copy at least four weeks before any applicable audit.
Sources cited on this page
- Legal Aid Agency, 2025 Standard Crime Contract — Standard Terms, version 1 (effective 1 October 2025)
- Legal Aid Agency, Provider Data Security Requirements v5 (October 2025)
- Legal Aid Agency, Provider Data Security Guidance v5 (October 2025)
- Legal Aid Agency, Welcome Pack for Previous Providers — Crime Contract 2025
- NCSC, Cyber Essentials overview
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
A legal aid firm needing Cyber Essentials or ISO 27001?
Say your size, your contract type and whether you hold either already.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.