Compliance programme

Track every control across Cyber Essentials, ISO 27001 and the Defence Cyber Certification from one programme.

Most small suppliers run their compliance programme across a controls spreadsheet, a policy folder, an email thread with the assessor and somebody's memory. It works right up to the week before an audit, which is when everyone discovers which parts of it went stale.

The compliance module replaces all four. Every control across every framework you have enabled lives in one programme, with an owner, a status, the evidence that satisfies it and a record of who last checked. Controls that appear in more than one standard are mapped once, so meeting a Cyber Essentials requirement moves your ISO 27001 and Defence Cyber Certification positions at the same time.

One programme, every framework

Every Cyber Essentials control with owner, status, evidence and last review — the audit answer before the auditor asks.

Control programme in Apexward Assure

A control you can actually answer for

One control end to end: requirement, owner, linked evidence, review history and notes.

Control detail in Apexward Assure

Evidence mapped to the controls it satisfies

Files and links, checksummed, mapped to the controls they satisfy, with expiry tracked so nothing silently goes stale.

Evidence vault in Apexward Assure

Policies people have actually signed

Versioned policies with publication state, recipient lists and signature progress tracked per person.

Policy library in Apexward Assure

Version history an assessor can follow

The published policy as staff see it, with version history and the signature roll-up.

Policy detail in Apexward Assure

A risk register that links to controls

Inherent and residual scoring, treatment plans, review cadence and the controls each risk actually relies on.

Risk register in Apexward Assure

Self-assessments without the rebuild

Self-assessment against each adopted framework, with the answer set that produced the score.

Framework assessments in Apexward Assure

Scope the programme once

Scope the programme: frameworks, boundaries and the questions that drive control selection.

Programme setup in Apexward Assure

The management system around the controls

A structured register builder for the records a certification body expects — without leaving the platform for a spreadsheet.

Management system in Apexward Assure

Registers for everything the standard asks you to track

A register in full: typed columns, live rows and the change history behind them.

Register in Apexward Assure

Compliance

Questions about compliance

Cyber Essentials, Cyber Essentials Plus, ISO 27001 and the Defence Cyber Certification at Level 2. Controls shared between them are mapped once, so evidence you gather for one counts towards the others.

Start free. No card, no expiry.

Scope your programme this afternoon, connect what you already run, and see the controls you can evidence today alongside the ones you cannot.