DICT Launches New Accreditation Framework for “Trusted” Cybersecurity Providers

The Department of Information and Communications Technology (DICT) has officially issued Department Circular No. HRA-001, establishing a rigorous formal framework for the accreditation of DICT Trusted Assessment Providers (DTAPs).

 

The new policy aims to ensure that government agencies and Critical Information Infrastructures (CIIs) are serviced by high-caliber, ethical, and reliable cybersecurity firms. Under the circular, all national government agencies, Government-Owned and Controlled Corporations (GOCCs), and local government units (LGUs) are now mandated to engage only with DICT-accredited DTAPs for their Vulnerability Assessment and Penetration Testing (VAPT) and Information Security Management System (ISMS) requirements.

 

Strict Standards for Service Providers

 

To qualify for accreditation, applicants must meet stringent legal, financial, and technical criteria. Key requirements include:

  • Filipino Ownership: Applicants must be juridical entities with at least 60% Filipino ownership and control.
  • Professional Certification: On-site personnel must hold valid, internationally recognised professional certifications relevant to their roles, such as OSCP for VAPT specialists or ISO/IEC 27001 Lead Auditor for ISMS consultants.
  • Proven Track Record: Firms must provide performance evaluations from client engagements conducted within the last three years.
  • Adherence to Global Frameworks: Evaluation will favour applicants whose internal practices align with established frameworks like the NIST Cybersecurity Framework 2.0 or CIS Controls v8.0.

 

Accountability and Oversight

 

The Cybersecurity Bureau will oversee the accreditation process and maintain a public registry of approved DTAPs. To maintain high standards, the DICT will implement a quarterly post-assessment evaluation and a mandatory client feedback mechanism.

 

The circular warns of severe penalties for malpractice. Accreditation can be suspended or revoked for grounds such as unauthorised exploitation of discovered vulnerabilities, extortion, or material misrepresentation in applications. Any individual or entity found violating these provisions may also face criminal or administrative action under existing laws.

 

Transition Period

 

The circular, signed by Secretary Henry R. Aguda, takes effect 15 days after its official publication. It effectively discontinues the DICT’s prior recognition program for cybersecurity providers. However, a 90-day transition period has been established to allow currently recognised providers to secure accreditation under the new DTAP framework without disrupting essential services to government agencies.

 

For meritorious cases where firms require additional time to complete entity-level certifications, the Cybersecurity Bureau may issue provisional accreditation for a period not exceeding 180 days.

Post a Comment