Registered in the United Kingdom · Independent professional standards council
BIPS News

Incident evidence added to the assessment route

Candidates for BIPS Professional and above in Cyber Security must now submit a documented incident response they led, assessed alongside their portfolio and discussed in depth.

BS BIPS Standards OfficeCouncil communications 12 Aug 2026 · 5 min read

The Cyber Security standard (GCS-02) has always been clear that it certifies people who can hold a response together when something gets through. From this assessment window, that commitment becomes a formal requirement. Candidates at Level 3, BIPS Professional, and above must include documented evidence of an incident response they personally led.

Why incident evidence, and why now

The cyber employer council has argued for some time that the gap between knowing incident response and doing it is wider than in almost any other part of the discipline. Frameworks and playbooks are widely understood. Staying methodical at two in the morning, with incomplete information and senior colleagues asking for answers, is a different capability altogether.

Everyone can describe containment. The question is whether you contained something real, preserved the evidence while you did it, and kept the right people informed without making it worse.

Level 3 was chosen because it is the point at which the descriptor moves to ownership: a BIPS Professional owns the security of a system or domain and answers for its exposure. The council concluded that ownership without incident evidence is incomplete.

What the evidence should cover

Candidates will submit an incident record alongside their portfolio. It should be sanitised to protect the organisation and anyone affected, but specific enough for an assessor to follow your decisions. Assessors will look for:

  • Your role, and confirmation from a colleague or manager that you led the response.
  • A timeline of detection, containment, eradication and recovery, with the decisions you made at each point.
  • How evidence was preserved, and how that shaped what you could later establish.
  • Communication with technical teams, leadership and, where relevant, regulators or customers.
  • What changed afterwards, including controls, architecture or process.

The incident need not be dramatic. A well-handled, contained incident with a clear post-incident review is often stronger evidence than a major breach where the candidate’s role is unclear.

How it is assessed

At the evidence review stage, an assessor checks provenance and your role, as with all portfolio material. The professional discussion then spends substantial time on the incident: what you knew at each stage, what you would do differently, and how you balanced speed against evidence preservation.

At BIPS Specialist and above, the council expects the evidence to show broader leadership, such as coordinating across teams, running a forensic investigation or setting the response process others follow.

Candidates who submitted before the change will be assessed under the previous guidance, and existing holders do not need to reassess. Anyone at Level 2 planning to progress should start keeping structured notes on the incidents they support now, so the evidence is ready when they apply.

Keep reading

More from this standard