Skip to content
Industry

CJSM, Common Platform, and Criminal Chambers: The Digital Security Baseline for 2026

CJSM is a transport-level network, not end-to-end encrypted email. Common Platform is the HMCTS case system. Neither is a substitute for the baseline cybersecurity controls that CE asks for. This guide covers how to think about these systems alongside Cyber Essentials in a UK criminal chambers context.

church between mirror-curtain buildings

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

11 min read

Share

Section 01

CJSM, Common Platform, and Criminal Chambers: The Digital Security Baseline for 2026

A criminal chambers in London, Manchester, or Birmingham in 2026 operates across three distinct digital layers. The first is the chambers’ own infrastructure - email, document management, case management, the clerks’ systems. The second is the government-provided digital tooling that connects chambers to the prosecuting authorities and the courts - CJSM, the CPS Digital Case System, the HMCTS Common Platform. The third is the barristers’ own personal digital estate, which varies massively across a set and which is often the weakest link in the chain from a security perspective.

Cyber Essentials is primarily concerned with the first layer. But the second layer - the CJSM and Common Platform tooling - interacts with the first in ways that matter, and in ways that are often misunderstood in chambers. This guide clarifies what CJSM and Common Platform actually provide, where their security guarantees end, and how a chambers’ CE posture needs to account for them.

The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements.

Section 02

What CJSM actually is (and is not)

CJSM - the Criminal Justice Secure Mail service - is an email service provided by the Ministry of Justice for communication between authorised criminal justice system participants: police forces, CPS, HMCTS, prisons, probation, defence solicitors and barristers, and selected other government and public-sector organisations.

What CJSM provides:

  • A private network environment where messages between CJSM accounts pass through the gov.uk infrastructure, not the public internet
  • Strict membership controls - only approved criminal justice participants can hold CJSM addresses
  • Transport-layer security between CJSM servers
  • A shared trust model that allows bulk case communications to move through a single controlled channel

What CJSM does not provide:

Not end-to-end encrypted

The messages themselves are not encrypted once they reach a CJSM mailbox. An attacker who compromises a CJSM account can, in most cases, read everything in the inbox in plain text.

No non-repudiation or message signing

CJSM does not add cryptographic signatures to messages. A received message appears to be from the sender address but that address relies on the sender's own account security.

No post-delivery protection

Once a message is delivered to a CJSM mailbox, CJSM's protections do not apply to what happens next - including copies sent to non-CJSM addresses, attachments downloaded to unmanaged devices, or screen captures.

This is not a criticism of CJSM. CJSM is doing what it was designed to do - provide a restricted transport channel for CJS participants. The mistake chambers sometimes make is treating CJSM as equivalent to cryptographic end-to-end encryption, when it is not.

The practical implication: the security of CJSM-delivered material depends almost entirely on the security of the recipient chambers’ infrastructure and endpoint security - which is exactly what Cyber Essentials covers.

Section 03

The Common Platform context

Common Platform is HMCTS’s digital case system for criminal cases. It has been rolled out progressively across magistrates’ and Crown courts over the last several years. For chambers and barristers, Common Platform provides:

  • Access to case information in a unified digital interface
  • Digital service of documents
  • Case listing, hearing information, and court diary visibility
  • Integration with CPS and defence systems where authorised

Access to Common Platform is gated by Common Platform Professional User accounts. Each user logs in individually. For chambers:

  • Every barrister and delegated staff member with Common Platform access has their own credentials
  • These accounts need MFA-level protection under v3.3
  • Leaver processes need to reach Common Platform when someone moves chambers or retires
  • The devices used to access Common Platform are in scope for CE if they access chambers case data through that channel

The HMCTS Digital Case System (DCS) is a separate but related system for prosecution case materials. Defence access to CPS DCS is granted on a case-by-case basis. The same access control principles apply - individual accounts, MFA, proper deprovisioning.

Section 04

Where chambers CE posture intersects with these systems

Several specific points where chambers' CE controls directly affect the security of CJSM, Common Platform, and DCS material:

Endpoint security on CJSM inbox devices

Because CJSM does not encrypt messages at rest, endpoint security on the device reading the messages is load-bearing. A barrister reading CJSM email on a personal laptop with no disk encryption, no software firewall, and no current anti-malware is exposing CJSM material in a way CJSM itself cannot defend against.

MFA on the receiving email account

CJSM accounts typically route through chambers-hosted email (or a dedicated CJSM account with chambers delivery). Either way, the email account that receives the CJSM message needs MFA. An attacker with the email password can read the CJSM messages on delivery, regardless of how secure the CJSM transport was.

Device management for Common Platform

For Common Platform access, apply the actual ownership and relationship rules: employee BYOD used for work is generally included; a third-party barrister’s own endpoint is excluded under v3.3, while organisational accounts remain in scope. A chambers-owned device loaned to a barrister is included. Meet the applicable endpoint and cloud-user authentication controls; a portal does not itself exempt an employee device.

Document retention after download

When a barrister downloads an attachment from a CJSM message, that document now lives on the barrister's device. Its security is the device's security. Endpoint safeguards - encryption where appropriate, plus applicable malware protection and patching - are what protect the document going forward.

Section 05

Case management systems and CJSM integration

Most criminal chambers use a case management system: LEX Chambers, Advocate Chambers, Athena, MeridianLaw, or bespoke setups. Many of these integrate with CJSM - ingesting CJSM messages into the case management system, linking documents to matter records, and allowing clerks and barristers to work within a unified interface rather than across separate email and case management screens.

For Cyber Essentials purposes, the case management system itself is in scope. It holds organisational data (case matters, client information, document indices). Applicable scheme controls and additional recommended safeguards to distinguish in preparation:

  • MFA on every user account - barristers, clerks, administrators
  • Integration with chambers identity (SSO where available)
  • Audit logging of access to sensitive matters
  • Role-based access - not every clerk needs access to every case
  • Proper leaver deprovisioning
  • Desktop vulnerability fixes. Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update.

For cloud-hosted case management systems, the vendor handles the infrastructure. For on-premise or self-hosted systems, the chambers handles the infrastructure, and the underlying servers, databases, and network components are all in CE scope.

Section 06

The BYOD question for chambers - specifically for barristers

Self-employed barristers often work across multiple devices: a chambers-issued laptop for chambers work, a personal laptop for wider legal practice, a personal iPad for brief-reading, a personal phone for CJSM email, a home desktop for paperwork. From a chambers CE perspective, this is a scoping question.

The options:

Option A - Scope to chambers-managed devices only

Apply v3.3 ownership rules rather than excluding everything unmanaged. Agree the assessment boundary with the Certification Body. Include organisational end-user devices, employee BYOD used for work, and cloud services hosting organisational data or services, including production hosting. Under v3.3, third-party-owned end-user devices are excluded, but their organisational accounts remain in scope; organisation-owned devices loaned to third parties are included. A virtual desktop, browser-only access or Conditional Access does not itself exempt employee BYOD. Any separately managed subset needs a justified technical boundary accepted by the assessor.

Option B - Mandatory MDM for personal devices

Chambers requires MDM enrolment of any personal device used to access chambers systems or CJSM-linked email. More comprehensive but requires member buy-in. Increasingly common for newer chambers and for chambers with larger corporate lay client practices.

Option C - Chambers-issued devices only

Chambers provides issued devices for members and requires their exclusive use for chambers-related work. The cleanest solution from a CE perspective, but operationally expensive for chambers.

Most London criminal chambers operate at some point along a continuum between A and B. The key is consistency between the scope declared and the reality of how work is done.

Section 07

Security of paper briefs and transfer between digital and physical

Criminal practice still involves significant paper. Briefs are sometimes delivered in hard copy. CPS bundles are often printed for court use. Judges still refer to paper bundles at the Old Bailey and Crown Courts. Cyber Essentials does not directly cover paper - it is a cybersecurity scheme, not an information security management system - but the transition between digital and physical forms a boundary where material leaves the controlled environment.

For CE purposes, the relevant controls are around the digital side: the chambers printer, the document management system’s print history, and the devices that generate the printed output. All of those are in scope.

A practical preparation checklist is:

  • A managed print environment where the printer itself is managed (firmware patched, default credentials changed, access controlled)
  • An explicit policy on printing sensitive material - retrieve immediately, no leaving documents on the shared printer
  • Secure disposal - shredding bins, cross-cut shredding of sensitive material

These are more information governance than CE, but they arise during Plus technical audits when the assessor looks at the printer network configuration and sees a multi-function device with a WAN-accessible admin page and default credentials.

Section 08

The annual CE renewal for a criminal chambers

At annual renewal, verify the current controls and scope instead of reusing last year’s answers unchanged. Review changes such as:

  • New members joining chambers - accounts provisioned, devices brought into management
  • Members leaving chambers - accounts deprovisioned across all in-scope systems
  • Cloud service changes - new case management system, new document platform, new video conferencing tool
  • Chambers-level infrastructure changes - office move, new wifi, new firewall
  • Personnel changes in the clerking team

Each of these needs to be reflected in the updated CE submission. Chambers that run a living document of their CE scope and controls, updated quarterly rather than annually, find renewal much easier than chambers that treat it as a once-a-year scramble.

Section 09

Bottom line

CJSM and the HMCTS Common Platform are important components of the criminal chambers digital environment, but they are not substitutes for the baseline cybersecurity controls that Cyber Essentials asks for. CJSM’s transport security does not encrypt messages at rest. Common Platform’s access controls do not manage the device a barrister uses to log in. Both systems rely on the recipient chambers’ CE-level posture to actually protect the material.

For a London criminal chambers in 2026, the realistic posture is Cyber Essentials (or Plus) as the baseline, with CJSM and Common Platform used on top of that baseline rather than as a replacement for it. Keep the certificate scope and the separate justice-system controls clear when answering instructing solicitors, clients and insurers; neither transport security nor certification guarantees a security outcome.

Check your readiness | View pricing | Talk to an assessor

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Ready to get certified?

Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.