Modules
28 frameworks, one set of controls
Everything below is available now. £2,000 a year each, or any three for £5,000 on Starter and Business; Scale and Enterprise include every module. Nothing is retired or coming soon on this page — if it is listed, it is in the product.
In the core — no module needed
ISO 27001 and UK / EU GDPR essentials are included at every tier, along with the registers and reporting that make them auditable.
ISO 27001 management system
IncludedThe whole standard, not a checklist.
UK / EU GDPR essentials
IncludedIncluded in every tier, not sold as an add-on.
Evidence vault
IncludedEvery claim in your ISMS points at a file.
People and HR
IncludedJoiners, movers and leavers with the evidence an auditor asks for.
Suppliers and third parties
IncludedDue diligence that does not live in your inbox.
Assets, physical and continuity
IncludedThe registers Annex A actually asks for.
Reporting and assurance
IncludedWhat you show the board, the customer and the auditor.
Bolt-on framework modules
£2,000 a year each, or any three for £5,000. Included at no extra cost on Scale and Enterprise. Modules are always at list price — the founding-customer rate applies to the tier price only.
| Module | What it gives you | Starter / Business | Scale / Enterprise |
|---|---|---|---|
| SOC 2 (Type I & II)~65% inherited from ISO 27001 | Trust Services Criteria, system description, audit periods and guest auditor access for US enterprise deals. | £2,000 / year | Included |
| ISO 27701 (privacy)~85% inherited | Privacy information management as an extension of your ISMS, with controller and processor split. | £2,000 / year | Included |
| ISO 42001 (AI management)~45% inherited | AI management system: clauses, Annex A AI controls, AI system register and impact assessments. | £2,000 / year | Included |
| EU AI Act~50% inherited | Risk classification, Article 9–15 obligations and conformity evidence for AI providers and deployers. | £2,000 / year | Included |
| ISO 9001 (quality)~80% inherited | Quality management system with shared management review and quality records. | £2,000 / year | Included |
| DORA~70% inherited | Five pillars, register of information and 24h / 72h / 1 month reporting clocks for EU financial entities. | £2,000 / year | Included |
| NIS2~70% inherited | Article 21 measures, management accountability records and incident reporting timers. | £2,000 / year | Included |
| NCSC CAF v3.2~65% inherited | Objectives A–D, 39 contributing outcomes and profile-based scoring for UK OES and GovAssure. | £2,000 / year | Included |
| NIST CSF 2.0 / 800-53~75% inherited | CSF functions with an 800-53 Rev 5 crosswalk and evidence reuse. | £2,000 / year | Included |
| NIST 800-171 / CMMC 2.0~70% inherited | Requirement families and CMMC level guidance for US defence supply chains. | £2,000 / year | Included |
| Cyber Essentials~60% inherited | The five technical control areas with a self-assessment scaffold and evidence pack. | £2,000 / year | Included |
| Cyber Essentials Plus | Assessor verification records, sampling and certificate register on top of Cyber Essentials. | £2,000 / year | Included |
| Defence Cyber Certification | Twelve capability areas across Levels 1–3 for MOD suppliers, mapped to your Annex A controls. | £2,000 / year | Included |
| PCI DSS v4.0.1 | Requirements, SAQ guidance and readiness summaries for card data environments. | £2,000 / year | Included |
| TISAX / VDA ISA 6 | Information security, prototype protection and data protection assessment groups for automotive. | £2,000 / year | Included |
| ISO 22301 (continuity) | Business continuity management using your BIA, continuity plans and restore tests. | £2,000 / year | Included |
| HIPAA | Security, Privacy and Breach Notification rules with BAA tracking for health data. | £2,000 / year | Included |
| NHS DSPT~70% inherited | Standards, assertions and a submission-ready export for NHS providers and their sub-processors. | £2,000 / year | Included |
| UK Cyber Security and Resilience Bill | Duties tracked against your existing controls so you are ready before it commences. | £2,000 / year | Included |
| ISO 27017 / 27018 (cloud) | Cloud security and cloud PII extensions with shared-responsibility guidance. | £2,000 / year | Included |
| CSA STAR (CCM v4 / CAIQ) | Cloud Controls Matrix domains, STAR level guidance and a CAIQ-style coverage export. | £2,000 / year | Included |
| ISO 27036 (supplier security) | Supplier security across plan, agree, operate and exit, driven by your supplier register. | £2,000 / year | Included |
| EU Cyber Resilience Act | Essential product requirements, vulnerability handling duties and reporting deadlines. | £2,000 / year | Included |
| FCA / PRA operational resilience | Important business services, impact tolerances, scenario testing and SS2/21 outsourcing duties. | £2,000 / year | Included |
| ISO 37002 (whistleblowing) | Confidential reporting channels, impartial investigation, protection from retaliation and trend reporting to the board. | £2,000 / year | Included |
| ISO 20000-1 (service management)~60% inherited | Service catalogue, service levels, capacity, availability, change, incident, problem and release management. | £2,000 / year | Included |
| PECR & cookie consent records~70% inherited | Cookie and tracker inventory, consent before non-essential cookies, marketing rules and demonstrable consent records. | £2,000 / year | Included |
| Modern Slavery & ESG | Section 54 transparency statement, supply chain due diligence beyond tier one, labour standards and ESG governance. | £2,000 / year | Included |
Modules are £2,000 a year each, or any three for £5,000 a year. Scale and Enterprise include every module at no extra cost. Plain-English guides to the major standards are on the frameworks and regulations page.