Access to cloud production environments should require security clearance vetting. Production systems hold live data and applications, and the consequences of compromise are direct.

UK clearance levels

LevelWhat it coversChecks included
BPSSPre-employment screening for government asset accessIdentity, employment history, immigration status, unspent criminal record
ACUnescorted access to UK airport security areasIdentity, employment history, criminal record, government agency records
CTC / Level 1BUK OFFICIAL assets, occasional SECRET accessIdentity, employment, criminal record, financial situation, personal circumstances
SCSubstantial unsupervised SECRET accessEverything in CTC plus credit reference and MI5 record checks
DVSubstantial unsupervised TOP SECRET accessEverything in SC plus detailed interview and referee enquiries

The process

You need a sponsor — usually HR or a company security controller. They confirm your role requires vetting and that BPSS checks are complete (unless you’re doing AC). You then fill out a security questionnaire online covering personal details, employment history, finances, criminal record, foreign travel, and contacts.

After submission you may be interviewed by a vetting officer. They assess reliability, trustworthiness, and loyalty. The risk owner (usually your sponsor or line manager) makes the final decision based on the gathered information.

If granted, you must report changes in personal circumstances and undergo regular reviews. If refused, you can appeal within 28 days through the NSVS Appeals Team.

Ongoing responsibilities

Clearance is not a one-time event. All clearances are kept under review. Report any incidents or changes that could affect your suitability. Act professionally and report security concerns to your sponsor or security controller.