Resources
Plain-English guides to the standards UK suppliers are asked to meet, and to the parts of a compliance programme that are more work than anyone admits.
Choosing a standard
- What is the Defence Cyber Certification? A plain-English guide for UK defence suppliersA plain-English guide to the Defence Cyber Certification for UK defence suppliers: what it asks for, how the levels work, and how it relates to Cyber Essentials.
- Cyber Essentials vs ISO 27001: which first, and where the controls overlapWhich to do first, what each actually asks of you, and where the controls overlap enough that evidence gathered for one counts towards the other.
Running the programme
- Building an evidence library that does not go staleWhy compliance evidence rots between audits, and how to structure a library with ownership, expiry and control mapping so it stays true.
- Continuous compliance monitoring: what to check between annual assessmentsWhat to check between annual assessments, how often, and which controls drift fastest in a small organisation.
- The risk register your auditor wants to seeThe fields that matter, how to score without inventing precision, and why linking risks to controls is what turns a register into evidence.
- Access reviews for SMEs: a quarterly process that stands up to an auditorA quarterly access review process that is proportionate for a small team and still stands up to an assessor.
Proving it to other people
- Supplier security questionnaires without the spreadsheetWhy questionnaire spreadsheets stall, and how login-free supplier portals get you evidenced answers instead of a chase.
- What is a Trust Centre - and does a small supplier need one?What a Trust Centre publishes, why buyers increasingly ask for one, and whether a small supplier actually needs it.