Cyber Essentials for Recruitment Agencies: A Practical Guide
Recruitment agencies handle large volumes of personal data - CVs, right-to-work documents, payroll data - and are increasingly required to hold Cyber Essentials by PSLs, MSP agreements, and public-sector frameworks. This guide covers how the controls apply to typical agency infrastructure.

Section 01
Cyber Essentials for Recruitment Agencies: A Practical Guide
Recruitment agencies are a personal-data-heavy business. CVs, right-to-work documents, bank details for payroll, addresses, passport numbers, client contracts, candidate notes - the volume and sensitivity of personal data in a typical agency's CRM is high. That is why PSLs (preferred supplier lists), MSP agreements, and public-sector frameworks increasingly require Cyber Essentials from the agencies they work with.
This guide covers what certification means for a UK recruitment agency, how the controls map to typical agency infrastructure (CRM, payroll, timesheet platforms), and the specific compliance gaps that most often fail agency submissions.
Section 02
Why recruitment agencies need Cyber Essentials
Three drivers push CE into recruitment:
PSL and MSP agreements. Larger clients, particularly in financial services, professional services, and government, frequently require their recruitment suppliers to hold Cyber Essentials before being onboarded to the PSL. Some go further and require Cyber Essentials Plus.
Public-sector frameworks. Agencies bidding on Crown Commercial Service frameworks (RM6277, RM6288, and similar) or local authority frameworks routinely see Cyber Essentials listed as a minimum requirement under PPN 014.
GDPR posture. The ICO does not require Cyber Essentials but cites it as evidence of "appropriate technical measures" under Article 32 of the UK GDPR. For a sector that handles as much personal data as recruitment, being able to point to CE certification is useful during any regulatory engagement.
Candidate and client expectations. Professional services and finance candidates increasingly ask whether the agency representing them has CE. It is becoming a differentiator in how agencies are perceived on the candidate side as well as the client side.
Section 03
What agency infrastructure looks like
The NCSC v3.3 requirements define the scheme controls. MDM can help demonstrate consistent controls, but Cyber Essentials does not mandate a particular product or an MDM subscription. Verify the required configuration, firewall, updates, access and malware controls on every in-scope device; documented manual management can also meet the requirements. Encryption, backup, logging and sector-specific information handling may be valuable or separately required; distinguish those from the five scheme controls.
A typical UK recruitment agency runs some combination of:
- Email on Microsoft 365 or Google Workspace
- A specialist recruitment CRM (Bullhorn, Vincere, JobAdder, Mercury, Access RDB, Lever, Greenhouse, Workable)
- A timesheet / payroll integration (Access, Sage, PayWorks, Employer of Record via Velocity Global / Remote)
- A candidate sourcing platform (LinkedIn Recruiter, Indeed, CV-Library, Reed, Zoho Recruit)
- A document signing tool (DocuSign, Adobe Sign, Juro, SignNow)
- Office-based laptops and often home-based or hybrid laptops
- A public-facing website with a candidate application portal
- WhatsApp Business or SMS integration for candidate communication
Every item on that list is in scope for Cyber Essentials if it holds or processes organisational data - and recruitment data is all organisational data.
Section 04
The five controls, applied to a recruitment agency
Firewalls and internet gateways. Standard requirements. Office firewall if you have one, software firewalls on laptops, boundary protection on any cloud infrastructure that hosts candidate data (most agencies use SaaS CRMs, so this is usually satisfied by the vendor's own controls).
Secure configuration. The area where agencies most commonly have quiet gaps. Recruiter laptops often have local admin rights because "they need to install tools". Former consultants' accounts sometimes remain active on the CRM for months after they leave. The document signing tool may have been set up with a shared company-wide admin account. Fix these before submitting.
Security update management. Confirm the SaaS provider/customer responsibility split. Apply vendor-approved vulnerability fixes within 14 days of release when the vendor rates the vulnerability critical or high, its CVSS v3 score is 7 or higher, or the vendor provides no severity details. This includes supported in-scope operating systems, applications, extensions and firmware; it is not a deadline for every routine update. Check recruiters’ browsers, connectors and candidate-sourcing plugins as well as the operating system.
User access control. Every user account accessing in-scope cloud services needs MFA, including temporary consultants and administrators. Non-interactive integration identities, such as a website-to-CRM service account, need their own supported authentication and credential controls; do not assume a human MFA flow applies to every machine identity.
Malware protection. Use a supported scheme-permitted anti-malware or application allow-listing approach on Windows and macOS, with the required configuration and updates. Mobile devices have their applicable approved-app-store and application-signing route. Tamper protection and EDR can add safeguards but are not universal scheme products. Review malicious-file handling for candidate attachments.
Section 05
The CV download problem
Recruiters download hundreds of CVs. They come from LinkedIn, from job board applications, from candidate emails, from partner agencies. Every one of those files is a potential delivery mechanism for malware - macro-enabled Word documents, PDF exploits, zip files with surprising executables inside.
Most CRMs handle this reasonably by rendering CVs in a sandboxed preview rather than requiring download, but consultants regularly pull the source file. Check applicable malware protection and safe file handling. The following are additional recommended handling safeguards, not universal Cyber Essentials product requirements:
- Real-time malware scanning is active on every laptop
- Macros are disabled by policy in Microsoft Office (Intune baseline setting)
- Consider attachment sandboxing where available, such as Microsoft Defender for Office 365 or equivalent; this is additional defence rather than a mandated scheme product
- Users cannot disable real-time protection on their own devices
Agencies that have been targeted by "candidate impersonation" phishing - where attackers send fake CVs as malicious attachments - are especially exposed without these controls.
Section 06
How to handle payroll data and right-to-work documents
Right-to-work documents (passport scans, visa documents, share codes), bank details for payroll, and National Insurance numbers are among the most sensitive categories of personal data any agency holds. Cyber Essentials does not prescribe specific encryption for this data at the scheme level, but assessors will probe how this data is stored and transmitted.
The posture assessors expect:
- Right-to-work and payroll data stored inside the CRM or a dedicated secure platform, not on consultants' local drives
- Email-based transmission of passport scans and bank details either avoided entirely or done via encrypted email links (OneDrive/SharePoint with expiring links, or equivalent)
- Access restricted to staff who actually need it - the compliance or payroll team, not every consultant
- Deletion policies in place so old candidate data is not retained indefinitely
Section 07
Contractors vs employees - whose MFA matters?
In recruitment it is common to have contractors, temps, or freelance consultants with access to the CRM on a flexible basis. Every one of these users is in scope. Their accounts need MFA, they need proper leaver processes when the engagement ends, and they should not share credentials with permanent staff.
A failure pattern to check: a temporary login is reused by successive contractors with no individual accountability or enforced cloud-user MFA. Review authorised users, access ownership and leaver control. A shared physical workstation is not itself forbidden; account and access controls still need to meet the requirements.
Section 08
Five recruitment-agency failure patterns to check
1. Shared accounts on secondary platforms. The agency CRM has individual accounts but the document signing tool, the timesheet platform, or the job-posting platform has a shared account used by the whole team.
2. Departed consultants still in the CRM. Leaver process covers email but not the sector-specific tools. Someone left six months ago and their Bullhorn account is still active.
3. Local admin on every recruiter laptop. "They need to install the CRM's browser plugin" becomes "they have unrestricted local admin". Use controlled installation and appropriate privileges; an approved catalogue or MDM is one implementation option.
4. No MFA on the candidate-sourcing platforms. LinkedIn Recruiter, CV-Library, Reed - often still using password-only access because "only one consultant uses it".
5. Candidate data on consultants’ personal devices. Classify employees and third parties correctly, establish device ownership and include organisational accounts. For in-scope devices, demonstrate the applicable controls; MDM is an option rather than a universal requirement.
Section 09
Practical path to certification for an agency
If you run a recruitment agency with 5-50 staff, the path typically looks like:
1. Enumerate every SaaS tool. List every platform that holds candidate or client data. Every one is in scope.
2. Enforce MFA on every one of them. This is usually the single biggest remediation task.
3. Run a leaver reconciliation. Compare your current staff list against active accounts on every in-scope platform. Disable anything that should not be there.
4. Verify device controls. Use MDM or another evidenced management approach to meet the five scheme controls; employee BYOD accessing work data is generally included, while access restrictions must be implemented in practice.
5. Document scope. Permanent staff, contractors, any directors or back-office users.
6. Submit. CE micro (1-9 staff) from £299.99 + VAT; small (10-49) from £399.99 + VAT; medium (50-249) from £449.99 + VAT.
Section 10
Bottom line
Recruitment is a sector where Cyber Essentials is genuinely useful beyond the compliance checkbox. Use preparation to verify authorised access, prompt leaver handling and cloud-user MFA. These controls address relevant account and malicious-file risks; certification alone does not establish a measured improvement in an agency’s outcomes.
The certification is also a commercial unlock. PSL admission, public-sector framework access, and larger client onboarding all increasingly depend on it. Agencies that hold CE are in the conversation for those engagements; agencies that do not are often filtered out before they reach a shortlist.
About the author

Jay Hopkins
Managing Director, Fig Group
Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.
Next step
Ready to get certified?
Get Cyber Essentials Basic certified with Fig Group from £299.99 + VAT. Our guarantee is within six working hours of receiving a complete, compliant submission before midday UK time on a UK Business Day, subject to our certification terms.
Related solutions
Continue exploring Fig Group
Related guides
Continue reading
Industry
Cyber Essentials for Construction Companies and Contractors
Construction firms bidding for government infrastructure work, MOD contracts, or public-sector framework places are increasingly required to hold Cyber Essentials. This guide covers how the controls apply to construction-specific infrastructure, including site laptops, tablets, and BIM platforms.
Read articleIndustry
Cyber Essentials for Charities: A Practical Guide for UK Nonprofit Organisations
Some grant funders and institutional donors require Cyber Essentials; the Charity Commission does not impose a universal certificate requirement. This guide covers what the certification means for a UK charity, how the controls map to typical nonprofit infrastructure, and how to certify on a limited budget.
Read articleIndustry
Cyber Essentials for Estate Agents, Letting Agents, and Property Firms
Estate agents handle large volumes of personal data - IDs, bank details, AML documentation - and need appropriate safeguards. HMRC AML supervision depends on the activities and applicable legal scope. This guide covers how Cyber Essentials applies to property firms of all sizes and how it supports AML and client data compliance.
Read article

