1. Introduction

These Terms of Service (“Terms”) govern the end to end process of consultancy, gap analysis, assessment or certification in relation to IASME approved Cyber Essentials / Cyber Essentials Plus Certification as a Service, [for the sake of brevity hereinafter referred to as ‘Services’] delivered by V4One (“we”, “us”, “our”) to the Client (“you”, “your”).

By engaging with our Services, you agree to be bound by these Terms.

These Terms are drafted in alignment with the IASME Governance Standard, Cyber Essentials / Cyber Essentials Plus, and UK cybersecurity best practices.

2. Definitions

"Client" means the business entity engaging V4One for certification services.

"Services" refers to Cyber Essentials and Cyber Essentials Plus certification facilitation provided by V4One via an IASME-accredited certification body.

"Certification Body" refers to an IASME approved Certification Body authorised to issue Cyber Essentials and Cyber Essentials Plus certifications.

"Confidential Information" includes any non-public, proprietary or sensitive information disclosed during service delivery.

"Force Majeure Event" means an unforeseeable situation beyond reasonable control, such as natural disaster, cyberattack, pandemic , Act of God , or government order.

3. Scope of Services

  • V4One will provide support and coordination for the Client’s certification journey, including readiness assessments, documentation review, submission and liaison with the Certification Body.
  • The Client acknowledges that their Cyber Essentials self-assessment must be completed within six (6) months of being set up on the certification portal, as per Certification Body guidelines.
  • The Client acknowledges that Cyber Essentials Plus should be accomplished within three months post the base-level Cyber Essentials certification. Failing at this level might revoke the primary certification.

Any work outside the defined scope requires a separate Scope of Work (SoW) or written approval.

4. Client Responsibilities

To ensure service integrity and IASME-aligned compliance, the Client agrees to:

1. Provide accurate and complete information required for certification. The client acknowledges that providing inaccurate information or not cooperating with V4One may result in failed certification.

2. Maintain secure access to systems, accounts, and credentials

3. Co-operate fully with V4One and any third-party auditors.

4. Ensure endpoints and infrastructure remain updated, patched, and protected.

5. Follow security best practices advised by V4One and IASME guidelines.

6. Comply with all reasonable directions made by V4One or IASME during the Cyber Essential services and during the period of Cyber Essentials Certification if successfully achieved.

7. Use certification marks only as permitted by IASME.

8. Not use the Marks or claim to be certified unless you are in receipt of a current, valid Scheme Certificate duly issued by the Cyber Essentials/IASME Governance Partner or a certification body.

9. Notify V4One promptly of any security incident, suspected breach, or critical change in infrastructure.

10.Ensure that any administrative access requested for assessments is granted securely and revoked when instructed.

Failure to fulfil these responsibilities may impact service outcomes, certifications, and timelines.

5. V4One Responsibilities

We commit to:

  • Deliver services with reasonable skill, due care, and industry-compliant security practices.
  • Maintain confidentiality and integrity of client information in accordance with IASME and UK GDPR.
  • Provide timely updates, assessment findings, recommendations, and reports.
  • Ensure that any subcontractors (e.g., Endpoint Security, Firewall, MDR, etc.) operate under equivalent security standards. (only applicable if managed by V4One or part of Order Agreement)

6. Security, Data Protection and Confidentiality

Both parties shall adhere strictly to IASME Guidelines, UK GDPR and Data Protection Act 2018 requirements.

6.1 Data Handling

  • All client information is processed securely and only for the purpose of delivering services.
  • Data is stored only in approved, secure locations (e.g., UK-based infrastructure or Data Center).
  • Role-based access control is applied for all documentation and systems.

6.2 Confidentiality

Each party agrees to maintain strictest confidentiality of the other party’s Confidential Information. Neither party shall use the other party’s confidential information for any purpose other than to exercise its rights and perform its obligations under or in connection with these Terms.

  • All data shared will remain confidential unless disclosure is required by law or regulatory standards.
  • V4One enforces strict access control principles, encryption practices, and secure communication channels.
  • This obligation will continue for five (5) years after termination of this agreement.

7. Cyber Essentials & IASME Aligned Requirements

During certification support:

  • The Client must ensure that the changes required for compliance are implemented.
  • V4One provides advisory and technical guidance but cannot guarantee certification unless all controls are fulfilled.
  • For CE/CE+ assessments, evidence must be provided in the required format and within deadlines.

8. Service Availability & Limitations

  • Services may include the use of third-party tools as well as vulnerability scanning as per agreed scope of work.
  • V4One is not liable for outages resulting from third-party service failures, cloud provider issues, or vendor system downtime.
  • Recommendations provided by V4One depend on the accuracy of client-supplied information.

9. Limitation of Liability

9.1 We do not accept any liability to you resulting from any security breach or vulnerability in your systems or processes.

9.2 Without prejudice to the generality of clause 9.1, we shall not be liable to you whether in contract, tort (including negligence) for breach of statutory duty or otherwise arising under or in connection with this agreement for:-

(a) loss of profits;

(b) loss of sales or business;

(c) loss of agreements or contracts;

(d) loss of anticipated savings;

(e) loss of or damage to goodwill;

(f) loss of use or corruption of software, data or information;

(g) any indirect or consequential loss.

9.3 The terms implied by sections 3 to 5 of the Supply of Goods and Services Act 1982 are, to the fullest extent permitted by law, excluded from this agreement.

9.4 The limitations and exclusions on liability in this section will not apply to any liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation or for any other liability that cannot lawfully be excluded or limited.

9.5 Subject to clause 9.4, the total limit of our liability to you whether in contract or tort shall not exceed the monthly order value (for avoidance of ambiguity, 1x monthly order value related to only software & services part of the order agreement) of the specific service contract under which the claim arose.

10. Incident Reporting & Response

In the event of a suspected incident:

1. The Client must inform V4One immediately.

2. V4One will assist with containment guidance, investigation support, and remediation actions within the defined scope if part of the Order Agreement.

3. Formal incident response services beyond advisory are subject to separate agreements.

11. Validity

Both Cyber Essentials and Cyber Essentials Plus certifications remain valid for one year post issuance.

12. Payment Terms

  • Payments must be made in accordance with the agreed invoice terms.
  • All payments are due in advance unless agreed otherwise in writing.
  • Fees are non-refundable once certification has commenced, including in the case of failure to achieve certification.
  • Delays in payment may result in temporary suspension of services.
  • Certification-related assessments must be paid before submission.
  • Client must pay the Renewal Fee and be reassessed at each anniversary of the issue of the original certificate. Non-payment of the Renewal Fee or non-compliance at the reassessment will result in the certificate becoming invalid.

13. Indemnity

The Client shall indemnify and hold V4One, CE/CE+ Certification Body and IASME harmless from any claims, damages or penalties arising from:

  • Breach of these Terms;
  • Misuse of certification;
  • Failure to meet security standards resulting in damages to third parties.

14. IASME- Branding Guidelines

The client shall adhere to the Branding Guidelines provided by IASME. As such, the client shall not:

  • Modify the logo — the tick and logotype must always appear together in a fixed format.
  • Place the logo on backgrounds such as busy photographs that don’t provide enough contrast for readability.
  • Alter the proportions of the logo (distort or stretch the logo).
  • Trim, crop, or bleed the logo off the edge of the page.
  • Place the logo at an angle.
  • Add any filter or effect.
  • Change the typeface.
  • Change the color of the typeface.
  • Use the logo as a watermark.

15. Inadequacy of Damages

15.1 The parties acknowledge that a breach of confidentiality or Branding Guidelines obligations may cause irreparable harm not compensable by monetary damages alone.

15.2 Either party may seek injunctive relief.

16. Term and Termination

This Agreement shall be valid as per the tenure of the Original Order Agreement in place between Client and V4One.

V4One may terminate services by providing 30 days’ written notice.

V4One may terminate immediately if:

  • The Client engages in misuse, unlawful activity, or breaches of security requirements.
  • Payment obligations remain unmet after repeated reminders.
  • Breach of the terms of this agreement.
  • Material breach
  • Insolvency, or
  • Unlawful use of certification.
  • There has been a material breach of V4One Terms of Business Terms of Business | V4One.

Upon termination:

  • Outstanding payments become due immediately.
  • Use of V4One and Certification body materials must cease.
  • All access and shared credentials must be revoked or returned.
  • Confidential information must be returned or securely destroyed.
  • A certificate must be provided on request ensuring that the confidential information has been securely returned or deleted as the case may be.
  • Termination or expiry of the Contract shall not affect any rights, remedies, obligations or liabilities of the parties that have accrued up to the date of termination or expiry, including the right to claim damages in respect of any breach of the Contract which existed at or before the date of termination or expiry.

17. Warranty Disclaimer

V4One provides recommendations aligned with best practice, but:

  • We cannot guarantee absolute security, zero vulnerabilities, or immunity from cyber-attacks.
  • Certification outcomes depend on client implementation and evidence of accuracy.
  • In accordance with IASME’s terms, the client acknowledge that the Cyber Essentials Scheme is intended to reflect the fact that certified organisations have established the

Security Controls only and that receipt of Cyber Essentials or Cyber Essentials Plus Certification does not indicate or certify or guarantee that your organisation is free from cyber security vulnerabilities.

18. Intellectual Property

All methodologies, templates, and proprietary materials supplied by V4One remain in our intellectual property unless explicitly transferred.

Clients are granted a non-exclusive right to use such materials only for internal purposes.

19. Changes to Terms

V4One may update these Terms to remain aligned with IASME requirements, regulatory changes, and service improvements.

The client must notify us of any material changes on their side ideally as early as possible but no later than 7x days of the change having taken place.

20. No Rights for Third Parties

These Terms do not give rise to any rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any term of this Agreement.

21. Force Majeure

21.1 Neither party shall be liable for delays or failure to perform due to a Force Majeure Event.

21.2 The affected party must notify the other party in writing within 5 days of the event.

22. Dispute Resolution

22.1 The parties shall first attempt to resolve disputes amicably through senior management discussion.

22.2 If unresolved, the dispute shall be referred to the Dispute Handling Policy provided by V4One. For more details, please visit to Dispute Handling Policy | V4One.

22.3 If still unresolved, the courts of England and Wales shall have exclusive jurisdiction.

23. Governing Law

These Terms shall be governed by and interpreted under the laws of England and Wales

24. Entire Agreement (Certification Services Only)

This Terms of Service constitutes the entire agreement between the Parties solely in relation to the Cyber Essentials and/or Cyber Essentials Plus certification services provided under this Agreement and supersedes all prior communications, representations, or understandings, whether written or oral, relating only to such certification services. For the avoidance of doubt, this Terms of Service does not apply to, amend, or replace any separate agreements, scope of work, or arrangements governing other services provided by V4One, which shall remain subject to their own applicable terms and conditions.