Governance
Explore our governance services
CIS
Put the CIS Critical Security Controls and CIS Benchmarks to work in your organisation. A prioritised plan, hardened systems and evidence you can reuse across audits.
Cyber Essentials Certification
Pass Cyber Essentials and Cyber Essentials Plus first time. We find the gaps, fix them and guide you through certification, then keep the controls working all year.
DORA
DORA compliance support for UK financial firms and ICT suppliers serving the EU. Gap analysis, remediation and the evidence your EU regulators and clients expect.
FCA Compliance Support
Show the FCA your firm can stay within its impact tolerances. Operational resilience and cyber evidence for authorised firms, built from real testing rather than paperwork.
GDPR Compliance Services
UK GDPR compliance you can evidence: data mapping, DPIAs, breach readiness and technical measures that stand up to ICO questions.
ISO 27001 Certification Support
Get ISO 27001 certified with an information security management system your team can run. Gap analysis, risk assessment, Statement of Applicability and audit preparation.
NIS2
NIS2 compliance support for UK organisations with EU operations or EU customers. Gap analysis, incident reporting readiness and supply chain evidence.
NIST
NIST Cybersecurity Framework 2.0 services for UK organisations. Maturity assessment, a funded roadmap and control evidence mapped to ISO 27001.
PCI-DSS
PCI DSS compliance support for UK merchants and service providers. Scoping, SAQ guidance, remediation and annual revalidation against v4.0.1.
Which frameworks apply to your organisation
The frameworks you need depend on what you do, where you operate and who you sell to. Regulated firms, suppliers to large organisations and businesses that take card payments usually have obligations under more than one framework.
Financial services firms in the UK are supervised by the FCA, which expects operational resilience and sound cyber controls. Firms with operations in the EU, and their ICT suppliers, fall under DORA. Essential and important entities in many EU sectors fall under NIS2, and that obligation also reaches the suppliers those organisations depend on. Businesses that take card payments must meet PCI DSS. Any organisation that handles personal data must meet UK GDPR.
Many organisations also choose a framework for assurance: ISO 27001 for a certified information security management system, Cyber Essentials for UK government supply chains, and NIST or CIS Controls as practical control sets. Where frameworks overlap, a single control set can often satisfy several requirements at once.
Frequently asked questions
Which framework applies to a UK financial services firm?
UK firms are supervised by the FCA, including its operational resilience rules. If you have EU operations, or you provide ICT services to EU financial entities, DORA may also apply.
Does NIS2 apply to suppliers?
NIS2 applies directly to essential and important entities in covered sectors. Those organisations must manage supply chain risk, so their suppliers are often asked to meet NIS2-aligned controls in contracts.
Do I need PCI DSS if I use a payment provider?
Possibly. Using a hosted payment page can reduce your scope, but you still need to confirm your responsibilities. We can help you work out which requirements apply.