There are requirements SECCOM is the wrong answer to. Saying so before a bid costs everyone less than discovering it afterwards.
Across the nine solutions there are capabilities delivered on method, measurement and evidence rather than on an accreditation: penetration testing, data sanitisation and data centre facility certification among them. Where a tender requires an empanelled tester, an accredited sanitisation provider, or the accrediting authority for the facility itself, that is not SECCOM, and the page for each capability says so where a buyer reads it. Where a requirement needs a credential SECCOM does not hold, the answer comes before the bid rather than after it.
There are also good reasons to keep what you already own. Where a survey shows existing cabling passes certification, the recommendation is to keep it, and the quote comes back smaller. An OEM's name is never used to cover a gap SECCOM has.
Questions Worth Taking Forward
- Which parts of this need a credential, and who actually holds it?
- What in the current estate is worth keeping?
- Where does the responsibility end, and is that written down?
- What would make us the wrong choice here?
