Governance and Audit / get ready

Compliance readiness

Cyber Essentials, ISO 27001, GDPR and the rules your sector enforces, in one prioritised path with the policies and evidence behind it. Guided by a team certified for ISO 27001 and ISO 9001 by a UKAS-accredited certification body, and appointed as a Cyber Essentials certification body.

Governance and Audit / 01 · What readiness means

What compliance readiness covers

Compliance readiness is the work that comes before any assessment. We establish which standards and obligations apply, measure where you stand against them, and put the controls, policies and evidence in place, so the proof is in order when an auditor, insurer or prime contractor asks. We do not guarantee you pass: that decision belongs to the assessor.

Governance and Audit / 02 · What we get you ready for

The standards most of our clients need

01Baseline

Cyber Essentials

The UK government backed scheme covering five technical control areas, which closes off the most common opportunistic attacks. It is recognised by insurers and buyers, and it is the usual place to start.

See Cyber Essentials
02System

ISO 27001

The international standard for an information security management system: the proof larger clients and regulators look for, built and run over time rather than achieved once. We hold it ourselves, certified by a UKAS-accredited certification body.

See ISO 27001
03Data

GDPR and UK data protection

The obligations every organisation handling personal data carries. We assess where you stand, put the policies and technical measures in place, and make sure you can answer a subject access request.

04Sector

Sector and industry rules

The rules your own regulator enforces: FCA systems and controls, the SRA, the CQC, the NHS Data Security and Protection Toolkit, and PCI DSS where you handle card payments.

See the sectors we serve
Governance and Audit / 03 · Which one

How to work out which standard you need

Most of the difficulty in compliance is not the work, it is knowing which work is yours. The starting point is the contract, the regulator or the insurer asking the question.

  • A contract or supply chain names a standard. Read the clause precisely. If it says Cyber Essentials, that is the floor, and Cyber Essentials Plus is sometimes specified. If it names ISO 27001, check whether it means certified or aligned: the two are materially different and an auditor will know.
  • You handle sensitive data at volume, or sell to enterprise and the public sector. ISO 27001 is likely on your horizon, because buyers at that level want to see security governed, not configured once.
  • You handle personal data, which is almost everyone. GDPR and the UK data protection regime apply regardless, so readiness here is a baseline rather than a choice.

The work compounds: the technical basics behind Cyber Essentials feed into ISO 27001, and the policies you build for one standard support the others. On the Cyber Essentials versus ISO 27001 question, our guide on which one your business needs goes through it in detail.

Governance and Audit / 04 · How we work

From gap analysis to assessment

01

Gap analysis

A readiness assessment of where you stand against the standards that apply, with the starting position recorded.

02

Prioritise

A ranked plan that closes the highest-risk gaps first, scoped to you rather than a generic template.

03

Policies and controls

We develop the policies and procedures, put the technical controls in place and operate them, documenting what was done.

04

Evidence and submit

We package the evidence mapped to the certification or framework and support you through the assessment, whether that is a Cyber Essentials submission or an ISO 27001 audit.

Governance and Audit / 05 · How this fits

Where readiness sits in what we do

Compliance readiness is part of our governance and audit work. Once you are certified, audit and assurance keeps the evidence current, and if the Cyber Assessment Framework is one of your obligations, CAF alignment maps your position against it. Regulated organisations, including those in the defence and aerospace supply chain, often need several together.

FAQ

Common questions

How do I know which standards apply to my business?

Start with what is being asked of you. A contract, a regulator, or an insurer usually names the standard, and GDPR applies to anyone handling personal data. We run a short readiness assessment that maps your obligations to your sector and your contracts, so you are not getting ready for things that do not apply to you, or missing things that do.

Do I need Cyber Essentials?

It is not always mandatory, but it is increasingly expected, and many professional indemnity insurers now ask for it. It is also a sensible baseline in its own right, because it closes off the most common attacks. For most organisations it is the right first step, and the work behind it feeds into ISO 27001 later if you need that too.

What is the difference between being certified and being aligned?

Certified means an accredited body has audited you and issued a certificate. Aligned, or equivalent, means you work to the standard without holding the certificate. The distinction matters, because a contract that asks for ISO 27001 certified is asking for something different from one that accepts alignment. We help you answer the question that was actually asked, and never claim certification you do not hold.

What happens when my regulator asks how I protect data?

You should have documented evidence ready: your policies, your security configurations, your audit logs, and your certification evidence. The whole point of readiness is that the proof exists before the question is asked. We help you assemble and maintain that evidence so a regulator's enquiry is a matter of producing a pack, not starting a project.

Can you get us ready and also run the controls afterwards?

Yes. We can take you from gap analysis to being ready for assessment, then run and secure the technology behind it as part of our cyber security and managed services. One team operates the controls and assembles the evidence, so the proof stays accurate between audits.

Talk to us about compliance readiness

Tell us what you are being asked to demonstrate, and we will tell you which standards apply, what it takes and where to start.

Reading, Berkshire  /  ISO 27001 and 9001 certified via a UKAS-accredited body  /  reply within one working day