Meet the IT compliance and regulatory standards your firm is judged on
Regulatory demands keep growing. We map our technology straight to the frameworks you are assessed against, so your evidence pack is current when the auditor asks for it.
Frameworks
The framework you are being assessed against
Each one ties a technology control straight to the regulation behind it.
DORA Compliance
Digital Operational Resilience Act readiness for financial entities. ICT risk management, incident reporting, and resilience testing.
Learn moreCyber Essentials Plus
UK Government-backed certification. We handle the technical controls and guide you through assessment.
Learn moreDefence Cyber Certification (DCC)
Readiness for MOD suppliers against DEF STAN 05-138 Issue 4. Gap assessment, remediation and an evidence pack for DCC Levels 0 to 3.
Learn moreFCA Operational Resilience
Meeting FCA requirements for important business services, impact tolerances, and self-assessment.
Learn moreDSPT (NHS Data Security)
Data Security and Protection Toolkit v8 readiness for NHS suppliers, GP practices, dental practices, and London healthcare organisations.
Learn moreISO 27001
Information security management system certification support. Gap analysis through to successful audit.
Learn moreCyber Insurance Readiness
Meeting insurer requirements, reducing premiums, and making sure claims are not denied.
Learn moreStart here
Which framework applies to you
Six short answers, each with the deadline, the scope and the cost where there is one. Follow the link for the detail.
Who does DORA apply to, and what is the deadline?
The Digital Operational Resilience Act became enforceable on 17 January 2025, and the European Supervisory Authorities have been supervising against it since that date. It applies directly to specified financial entities in the EU. A UK firm is not pulled into direct scope simply because it has EU clients — scope depends on entity type, authorisations, establishment and operating model. UK firms do still meet DORA second-hand, through contractual demands from an in-scope EU customer, and separately through FCA and PRA resilience rules. The reporting clock is the part firms underestimate: a major ICT incident needs an initial report within four hours of classification and no later than 24 hours after awareness. Read the DORA detail.
What does Cyber Essentials cost, and is it worth paying for help?
Cyber Essentials is the UK government-backed baseline built on five technical controls. Certificates last 12 months and current applications use the v3.3 requirements. The NCSC's self-led route starts at £320 + VAT depending on organisation size, and if your controls are already in place that is genuinely the cheaper option — we would rather say so than sell help you do not need. Our packages start at £795 + VAT for a certification review, £1,495 + VAT for guided readiness and certification, and £2,995 + VAT for Cyber Essentials Plus at 1–9 users. Plus pricing rises with size and complexity, so the fixed price is confirmed after a free readiness call. See the Cyber Essentials packages.
What changed in DSPT v8, and when is it due?
The Data Security and Protection Toolkit runs on an annual cycle, and version 8 covers the 2025-26 toolkit year. It spans the 10 National Data Guardian standards and must be completed and published by 30 June. Three changes matter most in v8: a named senior individual has to actively own the organisation's security approach with documented discussions behind it; a digital asset register of all hardware and software is mandatory under evidence item 7.1.1, and is new for GP practices this version; and the toolkit now aligns with version 3.4 of the NCSC Cyber Assessment Framework. Each toolkit year has its own version, so check requirements against the year you are submitting for rather than last year's guidance. Read the DSPT detail.
How many controls are in ISO 27001:2022?
The 2022 revision restructured Annex A from 14 domains and 114 controls into four themes and 93 controls — organisational, people, physical and technological. It added 11 new controls covering threat intelligence (A.5.7), cloud security (A.5.23), ICT readiness for business continuity (A.5.30) and monitoring activities (A.8.16). The core management-system requirements in clauses 4 to 10 changed only for clarity. Certification hinges on the Statement of Applicability: a document recording which controls you implement, which you exclude, and the reasoning for each. Organisations still certified to the 2013 version had until 31 October 2025 to transition. Read the ISO 27001 detail.
What does FCA operational resilience actually require?
For firms inside SYSC 15A, the requirement runs in three steps. First, identify your important business services — the ones whose failure would cause intolerable harm to clients or to market integrity. Second, set an impact tolerance for each one, stated as a hard time limit rather than an aspiration: a trading platform restored within two hours, for example. Third, prove it, through scenario testing and a self-assessment the regulator can read. The technology consequence is the part firms tend to discover late — your infrastructure has to be designed to meet the tolerance you published, and the evidence trail has to exist before anyone asks for it. Read the FCA resilience detail.
What do cyber insurers ask for at renewal?
Questionnaires vary between insurers, but the core set is remarkably consistent, so preparing for one prepares you for most. Underwriters ask about multi-factor authentication and how widely it is enforced; endpoint detection and response and its coverage; backups, including when you last actually restored from one; how quickly critical updates get applied; security awareness training records; and a documented incident response plan with a date against its last exercise. Note what that list has in common: every item is about coverage and evidence, not whether a product is switched on somewhere. A tenant-wide report showing which accounts are enrolled beats a licence count. We cannot set your premium — the underwriter does that — but we can make the picture in front of them complete. Read the cyber insurance detail.
Evidence, assembled as we build
Walk into the audit with the evidence already assembled
Compliance work fails when the evidence gets assembled the week before the assessment. We map controls to the framework as we build them, so the documentation falls out of the engineering rather than a scramble.
You get the same approach whether you face an FCA operational resilience review, a DORA deadline, an ISO 27001 surveillance visit or an insurer's renewal questionnaire.
Find out where you stand today
Book a compliance review. We assess your readiness against the current requirements and give you a priority order for closing the gaps.
- No callout fees
- No-obligation assessment