Government-backed baseline proving core cyber hygiene controls are in place.
A structured compliance programme covering data protection, retention and subject rights.
A formal Information Security Management System (ISMS), independently certified.
Independent attestation that our controls are designed — then operated — effectively.
One control environment, four frameworks
Cyber Essentials, GDPR, ISO/IEC 27001 and SOC 2 are not four separate efforts. They share the same underlying control set — access control, encryption, incident response, vendor risk, backups, logging and security policy — built once and reused across every framework.
| Control | Cyber Essentials | GDPR | ISO 27001 | SOC 2 |
|---|---|---|---|---|
| Access control | ✓ | ✓ | ✓ | ✓ |
| Multi-factor authentication (MFA) | ✓ | ✓ | ✓ | ✓ |
| Firewalls & network security | ✓ | ✓ | ✓ | ✓ |
| Secure configuration & patch management | ✓ | ✓ | ✓ | ✓ |
| Malware protection | ✓ | ✓ | ✓ | ✓ |
| Encryption (in transit & at rest) | – | ✓ | ✓ | ✓ |
| Logging & monitoring | – | ✓ | ✓ | ✓ |
| Incident response | – | ✓ | ✓ | ✓ |
| Vendor / third-party risk management | – | ✓ | ✓ | ✓ |
| Backups & disaster recovery | – | ✓ | ✓ | ✓ |
Real, verifiable, in place today
Get our security overview, DPA, subprocessor list, policy set and current certification status — under NDA where required.
Request our Security & Compliance Pack
Prospective customers' security and procurement teams can request our current documentation directly, under NDA where required.