Skip to main content
20% off — first 20 customers. See the offer →

Modules

28 frameworks, one set of controls

Everything below is available now. £2,000 a year each, or any three for £5,000 on Starter and Business; Scale and Enterprise include every module. Nothing is retired or coming soon on this page — if it is listed, it is in the product.

In the core — no module needed

ISO 27001 and UK / EU GDPR essentials are included at every tier, along with the registers and reporting that make them auditable.

ISO 27001 management system

Included

The whole standard, not a checklist.

UK / EU GDPR essentials

Included

Included in every tier, not sold as an add-on.

Evidence vault

Included

Every claim in your ISMS points at a file.

People and HR

Included

Joiners, movers and leavers with the evidence an auditor asks for.

Suppliers and third parties

Included

Due diligence that does not live in your inbox.

Assets, physical and continuity

Included

The registers Annex A actually asks for.

Reporting and assurance

Included

What you show the board, the customer and the auditor.

Bolt-on framework modules

£2,000 a year each, or any three for £5,000. Included at no extra cost on Scale and Enterprise. Modules are always at list price — the founding-customer rate applies to the tier price only.

ModuleWhat it gives youStarter / BusinessScale / Enterprise
SOC 2 (Type I & II)~65% inherited from ISO 27001Trust Services Criteria, system description, audit periods and guest auditor access for US enterprise deals.£2,000 / yearIncluded
ISO 27701 (privacy)~85% inheritedPrivacy information management as an extension of your ISMS, with controller and processor split.£2,000 / yearIncluded
ISO 42001 (AI management)~45% inheritedAI management system: clauses, Annex A AI controls, AI system register and impact assessments.£2,000 / yearIncluded
EU AI Act~50% inheritedRisk classification, Article 9–15 obligations and conformity evidence for AI providers and deployers.£2,000 / yearIncluded
ISO 9001 (quality)~80% inheritedQuality management system with shared management review and quality records.£2,000 / yearIncluded
DORA~70% inheritedFive pillars, register of information and 24h / 72h / 1 month reporting clocks for EU financial entities.£2,000 / yearIncluded
NIS2~70% inheritedArticle 21 measures, management accountability records and incident reporting timers.£2,000 / yearIncluded
NCSC CAF v3.2~65% inheritedObjectives A–D, 39 contributing outcomes and profile-based scoring for UK OES and GovAssure.£2,000 / yearIncluded
NIST CSF 2.0 / 800-53~75% inheritedCSF functions with an 800-53 Rev 5 crosswalk and evidence reuse.£2,000 / yearIncluded
NIST 800-171 / CMMC 2.0~70% inheritedRequirement families and CMMC level guidance for US defence supply chains.£2,000 / yearIncluded
Cyber Essentials~60% inheritedThe five technical control areas with a self-assessment scaffold and evidence pack.£2,000 / yearIncluded
Cyber Essentials PlusAssessor verification records, sampling and certificate register on top of Cyber Essentials.£2,000 / yearIncluded
Defence Cyber CertificationTwelve capability areas across Levels 1–3 for MOD suppliers, mapped to your Annex A controls.£2,000 / yearIncluded
PCI DSS v4.0.1Requirements, SAQ guidance and readiness summaries for card data environments.£2,000 / yearIncluded
TISAX / VDA ISA 6Information security, prototype protection and data protection assessment groups for automotive.£2,000 / yearIncluded
ISO 22301 (continuity)Business continuity management using your BIA, continuity plans and restore tests.£2,000 / yearIncluded
HIPAASecurity, Privacy and Breach Notification rules with BAA tracking for health data.£2,000 / yearIncluded
NHS DSPT~70% inheritedStandards, assertions and a submission-ready export for NHS providers and their sub-processors.£2,000 / yearIncluded
UK Cyber Security and Resilience BillDuties tracked against your existing controls so you are ready before it commences.£2,000 / yearIncluded
ISO 27017 / 27018 (cloud)Cloud security and cloud PII extensions with shared-responsibility guidance.£2,000 / yearIncluded
CSA STAR (CCM v4 / CAIQ)Cloud Controls Matrix domains, STAR level guidance and a CAIQ-style coverage export.£2,000 / yearIncluded
ISO 27036 (supplier security)Supplier security across plan, agree, operate and exit, driven by your supplier register.£2,000 / yearIncluded
EU Cyber Resilience ActEssential product requirements, vulnerability handling duties and reporting deadlines.£2,000 / yearIncluded
FCA / PRA operational resilienceImportant business services, impact tolerances, scenario testing and SS2/21 outsourcing duties.£2,000 / yearIncluded
ISO 37002 (whistleblowing)Confidential reporting channels, impartial investigation, protection from retaliation and trend reporting to the board.£2,000 / yearIncluded
ISO 20000-1 (service management)~60% inheritedService catalogue, service levels, capacity, availability, change, incident, problem and release management.£2,000 / yearIncluded
PECR & cookie consent records~70% inheritedCookie and tracker inventory, consent before non-essential cookies, marketing rules and demonstrable consent records.£2,000 / yearIncluded
Modern Slavery & ESGSection 54 transparency statement, supply chain due diligence beyond tier one, labour standards and ESG governance.£2,000 / yearIncluded

Modules are £2,000 a year each, or any three for £5,000 a year. Scale and Enterprise include every module at no extra cost. Plain-English guides to the major standards are on the frameworks and regulations page.

See pricingWhat the platform doesFramework guides