Skip to content

Cyber Essentials glossary

CRP

An abbreviation for Cyber Risk Profile, the buyer-assigned level in the MOD Cyber Security Model. Current CSMv4 profiles are numbered 0 to 3. Obtain the assigned profile and Risk Assessment Reference from your customer, and use the full Cyber Risk Profile explanation when planning certification. Do not convert a legacy verbal risk band into a current level yourself.

Why this term matters for defence suppliers

The MOD buyer assigns a numeric Cyber Risk Profile and contract-specific assurance requirements. Check the current contract version and Risk Assessment Reference before choosing a Defence Cyber Certification level. Legacy verbal risk bands do not determine a current numeric level.

A supplier asked for Level 1 should confirm the written requirement, map the essential organisational services and current Cyber Essentials prerequisite, then plan the appropriate independent assessment. A DCC certificate does not replace the contract-specific Supplier Assurance Questionnaire.

How Fig Group uses this term

Fig Group uses CRP as part of a practical Cyber Essentials and compliance vocabulary. The purpose is to make assessment decisions easier to verify: what the term means, where it appears in evidence, which control it supports, and which buyer or assessor question it helps answer.

If this term affects your DCC assessment, treat it as an evidence question rather than a definition question. Document the relevant owner, system, configuration, policy, or workflow so an assessor can see how the control works in your environment.

Official sources and related guidance

For scheme interpretation, verify against official MOD and IASME material. Fig Group's glossary is designed to translate those concepts into implementation language for UK organisations, MSPs, and procurement teams.