iso27001partnersUK certification, costed Get a cost estimate

Legal aid and Cyber Essentials: the LAA requirement, equivalents and ISO 27001

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 2 October 2026
By the iso27001partners.co.uk editorial team · Published 2 October 2026 · Last reviewed 2 October 2026 · 9 min read
5 primary sources cited on this page. How we check what is on this site
Clause 16.19 Cyber Essentials, or an agreed equivalent

A “valid and current Cyber Essentials Certificate or an equivalent certification as may be agreed with us” — 2025 Standard Crime Contract, Standard Terms.

Since the 2025 Standard Crime Contract, legal aid firms doing criminal work have a contractual security certification requirement: Cyber Essentials. The contract and the LAA's own guidance also provide for an equivalent, and name a UKAS-accredited ISO 27001 certificate covering the whole firm as highly likely to count. This page quotes the documents.

What the contract says

Clause 16.19 of the standard terms: “You shall (and shall ensure that all Approved Third Parties) have, maintain throughout the term of the Contract and demonstrate upon request a valid and current Cyber Essentials Certificate or an equivalent certification as may be agreed with us. You shall provide a copy of your Cyber Essentials Certificate or equivalent certification to the LAA at least four (4) weeks prior to any applicable Audit. You shall deliver to us evidence of renewal of the Cyber Essentials Certificate or the equivalent certification on each anniversary of the first applicable certificate obtained by you.”

Which certificate

The contract defines the certificate it means as the Cyber Essentials Basic Certificate: “the certificate awarded on the basis of the self-assessment, verified by an independent certification body, under the Cyber Essentials Scheme and is the basic level of assurance”. Cyber Essentials Plus is not required by the contract.

The term

The contract runs from 1 October 2025 to 30 September 2035. The certificate has to be held throughout and renewal evidenced on each anniversary; the LAA's welcome pack notes “Cyber Essentials Certification is valid for 12 months”.

Approved Third Parties

The clause binds the firm to ensure Approved Third Parties hold it too. They are defined as “an individual or organisation engaged by you to undertake non-legal work ancillary to Contract Work, including experts and translators but excluding Agents and Counsel”. An interpreter or expert engaged on legal aid work is inside that definition — our reading of the plain words.

The Data Security Requirements v5

Clause 16.5: “You must at all times for the duration of this Contract comply with the Data Security Requirements and have regard to the Data Security Guidance and any guidance issued by the Information Commissioner’s Office.” Which version applies depends on the contract: “Version 5 of the Data Security Requirements and Guidance apply to all contracts coming into force on or after 1st October 2025.” Earlier contracts follow earlier versions: “Version 4 of the Data Security Requirements and Guidance apply to all contracts coming into force on or after 1st September 2024 and before 1st October 2025”.

Cyber Essentials replaced the LAA's own technical list

“From version 5 of these requirements, LAA’s own technical requirements have been replaced by alignment to Cyber Essentials.” “All providers are required to hold Cyber Essentials certification at the point their contract comes into force, and for the duration that they undertake contract work.”

The mandatory requirements

LAA Data Security Requirements v5: mandatory requirements (titles from the requirements table)
No.Requirement
01Register as a Data Controller
02Appoint a Data Protection Supervisor
04Maintain a level of staff awareness
05aHave a coherent set of policies
06Undertake an annual review
07Have in place an Incident Management Policy
10Conduct Data Protection Impact Assessments
11Conduct staff screening
13Maintain access records
14Maintain adequate physical security
15Implement controlled disposal of records
16aSecure disposal
19aCyber Essentials
20Ensure Business Continuity
LAA Data Security Requirements v5: recommended requirements
No.Requirement
03Foster a culture that values and protects information
05bHave a coherent set of policies
08Monitor and Report
09Implement a ‘whistle-blowing’ procedure
12Control access to personal data
16bSecure disposal
17Conduct formal, documented risk assessments
18Apply appropriate controls
19bCyber Essentials Plus

Requirement 18, recommended, points at ISO 27001 directly: “Controls and control objectives for risk treatment should be selected from Annex A to ISO 27001, additional controls and control objectives may also be selected.”

Equivalents, and where ISO 27001 fits

“Equivalent standards will be considered by LAA on a case-by-case basis as alternatives to Cyber Essentials.” “A standard will be considered equivalent where it has been assessed by a UKAS accredited assessor and allows organisations to demonstrate compliance with technical controls in the areas of:”

The five technical areas the LAA's equivalence test names (verbatim)
Area
Secure configuration
User access control
Malware protection
Security update management
Firewalls

They are the same five control themes the NCSC's Cyber Essentials requirements set out (Firewalls, Secure Configuration, Security Update Management, User Access Control, Malware Protection). Then the guidance names ISO 27001:

“There is no defined list of equivalent standards, but it is highly likely that ISO27001 accreditation, where that accreditation has been assessed by a UKAS accredited assessor and where the scope of the accreditation covers the whole organisation and includes the 5 technical areas noted above will be considered equivalent.”

What that means for an ISO 27001 certificate (our reading)

The LAA's conditions for ISO 27001 as an equivalent, and what to check on your certificate
ConditionLAA wordingCheck
UKAS-accredited“assessed by a UKAS accredited assessor”Your certificate is from a UKAS-accredited certification body
Whole organisation“the scope of the accreditation covers the whole organisation”The scope line names the whole firm, not one office or one service
Five technical areas“includes the 5 technical areas noted above”Controls for secure configuration, access, malware, updates and firewalls are in the Statement of Applicability
Agreed with the LAA“as may be agreed with us” (clause 16.19)Equivalence is the LAA's decision, case by case — not the firm's

Check the scope first

A certificate scoped to one office, one practice area or one IT service does not cover “the whole organisation”. Read the scope line before relying on it. See certificate verification.

ISO 27001 itself is not required

“Providers are not required to be certified to this standard, however they must provide written confirmation that any information assets as identified in section 2.4 are managed in line with best practice as detailed in this standard.” Among what provider policies must do: “Conform to ISO 27001 and ISO 27002 good security practices.” — good practice, not certification.

Cyber Essentials or ISO 27001: which to hold (our reading)

A firm with neither

Cyber Essentials is what the contract names. ISO 27001 is a whole management system; it is worth weighing only if clients or other contracts also ask for it. The difference is on ISO 27001 vs Cyber Essentials.

A firm with ISO 27001 already

If the certificate is UKAS-accredited, covers the whole firm and includes the five areas, ask the LAA to agree it as the equivalent under clause 16.19 — in writing, before the date the certificate would be due.

Before an LAA audit

Clause 16.19 asks for a copy of the certificate, or the agreed equivalent, at least four weeks before any applicable audit. Keep the renewal evidence for each anniversary with it.

We do not give legal advice, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The requirements are quoted from the LAA's published contract and guidance; the check columns are our reading.

Where this fits

Common questions

Do legal aid firms need Cyber Essentials?

Under the 2025 Standard Crime Contract, yes, or an equivalent the LAA agrees. Clause 16.19 requires a valid and current Cyber Essentials Certificate “or an equivalent certification as may be agreed with us”, and the LAA's Data Security Requirements v5 make it mandatory: “To hold Cyber Essentials certification for the life of the contract, or an equivalent standard.”

When did the Cyber Essentials requirement start?

With the contract. The standard terms are effective from 1 October 2025, and “Version 5 of the Data Security Requirements and Guidance apply to all contracts coming into force on or after 1st October 2025.” The guidance: “All providers are required to hold Cyber Essentials certification at the point their contract comes into force, and for the duration that they undertake contract work.”

Can ISO 27001 be used instead of Cyber Essentials for legal aid?

Possibly, if the LAA agrees. “Equivalent standards will be considered by LAA on a case-by-case basis as alternatives to Cyber Essentials.” And: “There is no defined list of equivalent standards, but it is highly likely that ISO27001 accreditation, where that accreditation has been assessed by a UKAS accredited assessor and where the scope of the accreditation covers the whole organisation and includes the 5 technical areas noted above will be considered equivalent.”

Is Cyber Essentials Plus required?

Recommended, not mandatory. Requirement 19b: “To hold Cyber Essentials Plus certification and renew / maintain as required, or an equivalent standard.” “LAA continues to recommend Cyber Essentials Plus.”

Do experts and translators need Cyber Essentials too?

Clause 16.19 applies to the provider “and shall ensure that all Approved Third Parties”, defined as “an individual or organisation engaged by you to undertake non-legal work ancillary to Contract Work, including experts and translators but excluding Agents and Counsel”.

Do legal aid firms need ISO 27001?

No. The LAA's guidance on ISO 27001 and ISO 27002: “Providers are not required to be certified to this standard, however they must provide written confirmation that any information assets as identified in section 2.4 are managed in line with best practice as detailed in this standard.”

How often does the certificate need renewing?

The LAA's welcome pack: “Cyber Essentials Certification is valid for 12 months”. Clause 16.19 requires evidence of renewal on each anniversary, and a copy at least four weeks before any applicable audit.

Sources cited on this page

  1. Legal Aid Agency, 2025 Standard Crime Contract — Standard Terms, version 1 (effective 1 October 2025)
  2. Legal Aid Agency, Provider Data Security Requirements v5 (October 2025)
  3. Legal Aid Agency, Provider Data Security Guidance v5 (October 2025)
  4. Legal Aid Agency, Welcome Pack for Previous Providers — Crime Contract 2025
  5. NCSC, Cyber Essentials overview

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Say your size, your contract type and whether you hold either already.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now