Skip to main content

    Team Safety Snapshot now live, 10 founding partner spots at £39. Claim yours →

    CyberSafe Coach+
    Something happening right now?Digital 999

    Compliance Support

    Keep your team safer online made simple

    Whether you've been asked to meet a security standard or you simply want your people to be more aware, this is a good place to start.

    Most online risks come down to everyday habits, clicking links, sharing passwords, not knowing what to look out for.

    We help you understand where your team might be vulnerable and what to do about it. If you also need to meet a security standard, we can help with that too.

    Compliance Frameworks We Cover

    Tap each framework to learn more

    Filter by sector
    Showing 14 of 14 frameworks

    Filter by the sectors you work in. Pick more than one — for example a charity that also runs youth work.

    It usually starts with one moment.

    Someone on your team opens an email that looks real. They click a link. They enter a password. By the time anyone notices, the damage is done.

    It's not because they were careless. It's because nobody showed them what to look out for.

    That's what the Team Overview is for.

    • See where your team's awareness gaps are, before they become problems
    • Give each person their own safety check, so they know what to watch for
    • Track progress over time, so you can see improvement, not just hope for it
    • No technical knowledge needed. If you can send an email, you can use this

    You don't need a security team. You just need your people to know what good looks like.

    Ready to check where you stand?

    Our free assessment maps to frameworks like Cyber Essentials and DSPT / NHS data requirements. Takes about 10 minutes.

    Free Compliance Checklist

    A simple printable checklist covering all four frameworks

    or

    Get it emailed to you instead (optional)

    Common questions

    Do I need Cyber Essentials certification by law?
    Cyber Essentials is not a legal requirement for most businesses. However, it is mandatory if you bid for UK government contracts that involve handling sensitive or personal data. Even without that requirement, certification demonstrates good security practice to customers and insurers.
    What's the difference between Cyber Essentials and Cyber Essentials Plus?
    Cyber Essentials is a self-assessment questionnaire verified by an assessor. Cyber Essentials Plus includes all of that, plus a hands-on technical audit where an assessor tests your systems directly. Plus offers stronger assurance but costs more and takes longer.
    Does GDPR apply to small businesses and charities?
    Yes. GDPR applies to any organisation that processes personal data of individuals in the UK or EU, regardless of size. This includes names, email addresses, health records, and financial information. Charities handling beneficiary or donor data must comply.
    How long does compliance typically take for a small organisation?
    It depends on your starting point. Many small businesses can achieve Cyber Essentials readiness in 2–4 weeks with focused effort. DSPT submissions typically take longer due to the evidence requirements. Our assessment helps you prioritise so you don't waste time on things that don't matter yet.
    Can your assessment certify my organisation?
    No. Our assessment is a readiness check, not a formal certification. It helps you understand where you stand and what to fix before you go through the official certification process. For Cyber Essentials, you'll need to apply through an accredited body like IASME.
    Is ISO 27001 relevant for small businesses?
    Yes. While ISO 27001 is often associated with larger organisations, it's increasingly relevant for SMEs, especially those working with enterprise clients, government, or regulated industries. Many contracts now require or prefer ISO 27001 certification. The standard is scalable and can be implemented proportionally to your size and risk.
    What's the difference between ISO 27001 and Cyber Essentials?
    Cyber Essentials focuses on five specific technical controls and is a relatively quick self-assessment. ISO 27001 is a comprehensive information security management system covering policies, processes, people, and technology across your entire organisation. Cyber Essentials is a good starting point; ISO 27001 demonstrates a more mature, systematic approach to security.
    How long does ISO 27001 certification take?
    For a small organisation, expect 3–6 months of preparation to establish your information security management system, followed by a two-stage audit by an accredited certification body. The timeline depends on your starting point and the complexity of your operations. Our readiness check helps you understand how far along you already are.

    If you think you've been scammed or something has just happened:

    Open Digital Emergency Service