Meet the IT compliance and regulatory standards your firm is judged on

Regulatory demands keep growing. We map our technology straight to the frameworks you are assessed against, so your evidence pack is current when the auditor asks for it.

Start here

Which framework applies to you

Six short answers, each with the deadline, the scope and the cost where there is one. Follow the link for the detail.

Who does DORA apply to, and what is the deadline?

The Digital Operational Resilience Act became enforceable on 17 January 2025, and the European Supervisory Authorities have been supervising against it since that date. It applies directly to specified financial entities in the EU. A UK firm is not pulled into direct scope simply because it has EU clients — scope depends on entity type, authorisations, establishment and operating model. UK firms do still meet DORA second-hand, through contractual demands from an in-scope EU customer, and separately through FCA and PRA resilience rules. The reporting clock is the part firms underestimate: a major ICT incident needs an initial report within four hours of classification and no later than 24 hours after awareness. Read the DORA detail.

What does Cyber Essentials cost, and is it worth paying for help?

Cyber Essentials is the UK government-backed baseline built on five technical controls. Certificates last 12 months and current applications use the v3.3 requirements. The NCSC's self-led route starts at £320 + VAT depending on organisation size, and if your controls are already in place that is genuinely the cheaper option — we would rather say so than sell help you do not need. Our packages start at £795 + VAT for a certification review, £1,495 + VAT for guided readiness and certification, and £2,995 + VAT for Cyber Essentials Plus at 1–9 users. Plus pricing rises with size and complexity, so the fixed price is confirmed after a free readiness call. See the Cyber Essentials packages.

What changed in DSPT v8, and when is it due?

The Data Security and Protection Toolkit runs on an annual cycle, and version 8 covers the 2025-26 toolkit year. It spans the 10 National Data Guardian standards and must be completed and published by 30 June. Three changes matter most in v8: a named senior individual has to actively own the organisation's security approach with documented discussions behind it; a digital asset register of all hardware and software is mandatory under evidence item 7.1.1, and is new for GP practices this version; and the toolkit now aligns with version 3.4 of the NCSC Cyber Assessment Framework. Each toolkit year has its own version, so check requirements against the year you are submitting for rather than last year's guidance. Read the DSPT detail.

How many controls are in ISO 27001:2022?

The 2022 revision restructured Annex A from 14 domains and 114 controls into four themes and 93 controls — organisational, people, physical and technological. It added 11 new controls covering threat intelligence (A.5.7), cloud security (A.5.23), ICT readiness for business continuity (A.5.30) and monitoring activities (A.8.16). The core management-system requirements in clauses 4 to 10 changed only for clarity. Certification hinges on the Statement of Applicability: a document recording which controls you implement, which you exclude, and the reasoning for each. Organisations still certified to the 2013 version had until 31 October 2025 to transition. Read the ISO 27001 detail.

What does FCA operational resilience actually require?

For firms inside SYSC 15A, the requirement runs in three steps. First, identify your important business services — the ones whose failure would cause intolerable harm to clients or to market integrity. Second, set an impact tolerance for each one, stated as a hard time limit rather than an aspiration: a trading platform restored within two hours, for example. Third, prove it, through scenario testing and a self-assessment the regulator can read. The technology consequence is the part firms tend to discover late — your infrastructure has to be designed to meet the tolerance you published, and the evidence trail has to exist before anyone asks for it. Read the FCA resilience detail.

What do cyber insurers ask for at renewal?

Questionnaires vary between insurers, but the core set is remarkably consistent, so preparing for one prepares you for most. Underwriters ask about multi-factor authentication and how widely it is enforced; endpoint detection and response and its coverage; backups, including when you last actually restored from one; how quickly critical updates get applied; security awareness training records; and a documented incident response plan with a date against its last exercise. Note what that list has in common: every item is about coverage and evidence, not whether a product is switched on somewhere. A tenant-wide report showing which accounts are enrolled beats a licence count. We cannot set your premium — the underwriter does that — but we can make the picture in front of them complete. Read the cyber insurance detail.

The Palace of Westminster and Big Ben at dusk, with a red London bus passing
Every framework on this page starts as legislation. We deal with what it means for your IT.

Evidence, assembled as we build

Walk into the audit with the evidence already assembled

Compliance work fails when the evidence gets assembled the week before the assessment. We map controls to the framework as we build them, so the documentation falls out of the engineering rather than a scramble.

You get the same approach whether you face an FCA operational resilience review, a DORA deadline, an ISO 27001 surveillance visit or an insurer's renewal questionnaire.

Replies the same business day

Find out where you stand today

Book a compliance review. We assess your readiness against the current requirements and give you a priority order for closing the gaps.

  • No callout fees
  • No-obligation assessment