Governance and Audit / prove it

Meet your obligations. Then prove it.

We help regulated and serious organisations meet their obligations and evidence them, with documented proof ready before the regulator, insurer, or prime contractor asks. Audit and assurance, Cyber Essentials, ISO 27001 support, CAF alignment, and compliance readiness, from a team that is itself a Cyber Essentials certification body and UKAS accredited.

AccreditedUKAS ISO 27001
Certification bodyCyber Essentials
OutputAudit ready evidence
Verified
ISO 27001 & 9001UKAS accredited Cyber EssentialsCertification body Cyber Essentials PlusCertified MicrosoftCertified Expert 5.0Google rating
Governance and Audit / 01 · The proposition

Compliance is your obligation. The evidence is our job.

Regulated and serious organisations have to meet a growing set of obligations, and then show they have. We help you do both: put the right controls in place, run the technology behind them, and produce the documented evidence an auditor, insurer, or prime contractor will accept. We do not guarantee you pass, because no honest partner can. We make sure that when you are assessed, the proof is already in order.

01AssessAn honest baseline of where you stand against the standards that apply to you.
02CertifyCyber Essentials and ISO 27001, guided by people who hold and assess them.
03AlignCAF alignment and GDPR readiness mapped to your sector's rules.
04EvidenceAudit ready documentation, packaged the way assessors actually want it.
Governance and Audit / 02 · What we do

Everything you need to meet and prove your obligations.

Six related services under one accountable team. Start with an audit to see where you stand, or go straight to the certification or framework your clients and regulators expect.

01Assess

Audit and assurance

A clear eyed review of your IT, your spend, your security, and your efficiency. We find the money and the risk others miss, then hand you a plain English report and a prioritised plan. It is the natural front door to everything else here.

IT auditCost and spendSecurity assessmentEfficiency review
Explore the audit
02Certify

Cyber Essentials and Cyber Essentials Plus

The baseline a demanding supply chain expects, achieved without the pain. We get you cleanly through both the self assessed certification and the audited Plus tier, and keep you there at each annual renewal.

Readiness reviewControls in placePlus auditAnnual renewal
See Cyber Security
03Issue

Cyber Essentials certification

A distinct service. We are appointed as a Cyber Essentials certification body, so we can certify other organisations against the standard, not merely hold it ourselves. If you assess and certify suppliers, or want certification handled by a body that also does the engineering, this is for you.

Certify other organisationsAssessor ledSupplier assurance
Talk to us about certification
04Assure

ISO 27001 support

A full information security management system, the proof larger clients and regulators look for. We run ISO 27001 ourselves and are UKAS accredited, so we guide you from gap analysis to a certificate that genuinely holds up under scrutiny.

Gap analysisISMS buildInternal auditCertification support
See ISO 27001
05Align

CAF alignment

Alignment to the Cyber Assessment Framework for organisations in scope of the NIS Regulations and the wider essential services remit. We map your position across the framework's outcomes and show you, in order, what closes each gap.

CAF objectives A to DNIS RegulationsGap to outcome mapping
Talk to us about CAF
06Comply

Compliance readiness

Get ready for what applies to you, from GDPR and the UK data protection regime through to the sector rules your regulator enforces. We turn a daunting checklist into a clear, prioritised path, with the policies and evidence to back it up.

GDPR readinessSector rulesPolicy frameworksEvidence
Talk to us about readiness
Governance and Audit / 03 · A distinct service

We do not just hold Cyber Essentials. We can certify it.

Dead Simple Computing, a Cyber Essentials Certification Body

Most providers hold Cyber Essentials. We are appointed as a certification body, which means we can assess and certify other organisations against the standard. That is a distinct service from getting your own business certified, and it matters in two ways. If you need to certify your suppliers, we can do it. And if you want your own certification handled, you are working with the people who assess against the standard every day, so the controls we put in place are the ones we know stand up.

01A certification body, not a holder. We are appointed to assess organisations against Cyber Essentials, a distinct service from holding the certificate ourselves.
02We certify other organisations. If you run a supply chain or assess third parties, we can certify suppliers against the standard.
03Built by people who assess it. When we secure your business, the controls come from the people who certify against the standard, not from a checklist.
Governance and Audit / 04 · The evidence

How we make you audit ready.

Evidence is not a folder you scramble together the week before an assessment. It is a by product of doing the work properly and recording it as you go. Here is how the proof comes together.

01

Establish the baseline

We assess where you stand against the standards that apply, and record the starting position so progress is demonstrable later.

02

Put controls in place

We implement and operate the controls, documenting what was done, by whom, and when, as part of running the technology, not after.

03

Log and retain

Monitoring, change records, and policy evidence are captured and retained continuously, so the trail is there when an assessor asks.

04

Package for assessment

We assemble it into a clear, plain English pack mapped to the certification or framework, ready for the auditor, insurer, or client.

The same rigour we hold ourselves to. The discipline behind our UKAS ISO 27001 certification and our Cyber Essentials certification body status is the discipline we apply to your evidence.
Governance and Audit / 05 · The difference

We run the technology and prove it. Compliance platforms only do the second part.

A compliance platform can give you a policy template and a dashboard. It cannot patch a server, contain an incident, or stand behind the control it is asking you to tick. We do both: we run and secure the technology, and we produce the evidence that it is compliant. So the proof reflects what is actually in place, and there is one accountable team behind both, with nobody to point at when the two do not match.

Run and proveOne team, both halvesWe operate the controls and evidence them, so the proof matches reality.
AccreditedWe hold it ourselvesUKAS accredited for ISO 27001 and a Cyber Essentials certification body.
AccountableNobody to point atWhen running it and proving it sit together, the gaps close.

Meet it, and prove it.

Book a consultation or start with an audit. We reply within one working day, and you will speak to an engineer, not a salesperson.

Reading, Berkshire  /  reply within one working day