Build trust, assurance and resilience.
Strengthen controls, organise evidence and improve your organisation’s ability to withstand disruption. Prepare for relevant assurance requirements with clear priorities and practical progress.
From £500/month + VAT
Are the right protections in place, are they working, and can we prove it?
Clear answers about the services your business runs on and the commitments you make to customers.
Understand the starting point
Establish the risks, requirements and current controls that matter to your organisation. Identify gaps and prioritise improvements proportionate to the business and its obligations.
Strengthen controls and evidence
Clarify responsibilities and organise evidence of how controls operate. Prioritise gaps, agree who will carry out the work, track progress and verify evidence when actions are completed. Implementation is separately scoped.
Build resilience and prepare for assurance
Consider how the organisation will respond to disruption and restore important work. Prepare for the certification or assessment target included in your scope. Preparation does not guarantee certification or replace an assessor’s independent decision.
A clear, honest record of where you stand
- EVIDENCE REVIEWED
- Supplier account list and the last access review sign-off
- FINDING
- Two supplier accounts no longer in use are still active
- NEXT ACTION
- Confirm the accounts are no longer required, remove access and verify completion by the agreed deadline.
- OWNER · VERIFIER
- Operations · IT lead
- DEADLINE
- 14 days from the finding
Each finding is supported by evidence and a clear next action.
What the statuses mean
- PASS
- Evidence shows the control is in place and working.
- ATTENTION
- A finding or evidence gap needs action. The control is not yet confirmed as fully effective.
- EXCEPTION
- A known gap formally accepted by an accountable decision-maker, with a recorded reason and a date for review.
- FAIL
- Not in place or not working; remediation is needed.
- N/A
- Does not apply to your organisation or scope.
- NOT ASSESSED
- Not yet checked. Shown so nothing is assumed.
Prepare for certification. Keep the evidence working afterwards.
Where certification is your goal, Cyber Ready prepares your organisation against the agreed requirements: identifying gaps, coordinating improvements and verifying the evidence, so you approach the external assessment with a clear view of your readiness.
Cyber Ready does not issue certification or guarantee an external assessment outcome. Certification and assessment decisions remain with the relevant external body.
- 01Scope the target
- 02Close gaps and verify readiness
- 03Support assessment and maintain assurance
One control and evidence approach. Multiple frameworks.
Cyber Ready reuses relevant evidence across supported frameworks and helps you prepare for the certification or assessment your business needs. The requirements and additional work depend on your agreed target and scope.
UK technical baseline. Controls, evidence and gaps mapped to the scheme requirements.
External route
Prepares you for scheme certification. Cyber Ready does not award the certificate.
Operational security safeguards and prioritised cyber hygiene.
External route
Control alignment and assessment, not a CIS certification.
Security controls and evidence supporting your agreed information security management system scope. We identify the additional management-system work needed for certification and agree how it will be completed.
External route
Certification is decided by an independent certification body.
Security-control guidance supporting implementation and mapping.
External route
Guidance supporting alignment, not a separate organisational certification.
Outcome-based assessment of governance, protection, detection and response and resilience.
External route
Prepares you for the applicable assessment. Cyber Ready does not issue a CAF certificate.
Relevant security and resilience obligations for in-scope organisations.
External route
Applicability and supporting evidence, not certification or blanket compliance.
Applicable jurisdiction, sector and supply-chain requirements.
External route
Separate from UK NIS, and scoped against the relevant national implementation.
Payment-security overlay for relevant card-data environments.
External route
Prepares you for the applicable validation route.
Evidence and additional requirements relevant to your health or social-care organisation.
External route
Prepares you for the relevant toolkit submission and assurance route.
Technical and organisational security evidence supporting your data-protection responsibilities.
External route
Privacy obligations also need information-governance work beyond security controls.
Leadership ownership of cyber risk, strategy, response and assurance.
External route
Governance alignment and evidence, not a certification scheme.
Assurance that keeps up with your business
Onboarding sets the baseline. After that, the cycle continues as your systems, suppliers and ways of working change.
- 01Understand the business
- 02Collect evidence
- 03Investigate exceptions
- 04Track remediation
- 05Verify
- 06Review change
Automated collection can reduce repeated requests for the same evidence. People remain responsible for investigating exceptions, applying business judgement and making decisions.
Agreed with you before any paid engagement begins
Every organisation starts from a different position. We agree the scope, outcomes and investment before any paid engagement begins. Each Modern Working service can be purchased independently.
INVESTMENT
From £500/month + VAT
Agreed control and evidence review, an action and evidence register, progress and assurance reviews and preparation for the in-scope target form the service. Organisation, environments, reporting and frequency are confirmed in the proposal.
We confirm onboarding work and any separate fee, minimum commitment, billing and cancellation terms before you proceed. Remediation, security software, penetration testing, external assessment fees and specialist framework projects are separate unless expressly included. General IT support, 24/7 monitoring, SOC and incident response are not included.
What the starting assessment covers
We agree the systems and requirements in scope, establish authorised access to available evidence and assess the starting position. You receive a baseline of control status, missing evidence, gaps and exceptions, with a prioritised action plan, responsibilities and a review schedule.
What the ongoing service covers
We maintain the agreed control assessment and evidence register, review available evidence and outstanding actions, and hold regular assurance reviews. Relevant evidence is mapped to supported frameworks and assembled for your agreed assessment target.
Cyber Ready provides ongoing assurance. It is not a 24/7 security operations or incident-response service.
What is agreed separately
Remediation implementation, security software, external certification and assessment fees, penetration testing and MDR/SOC services are separate. Bespoke framework work, such as building a complete ISO management system, is scoped on its own.
Cyber Ready can be purchased independently. Its value extends across your organisation’s trust, controls, assurance and resilience, whether or not you are adopting AI.
95 controls across 13 families
The scope of what Cyber Ready looks at, not a score. Coverage is platform-neutral and proportionate to your business; particular products are implementation choices, not the definition of Cyber Ready.
Evidence is reused across applicable frameworks and refreshed as systems, requirements and circumstances change. Additional evidence or work is added where a framework requires it.
See all 13 control families
- 01Asset Management
- 02Vulnerability Management
- 03Data Protection
- 04Identity & Access
- 05Endpoint & Device Security
- 06Backup & Recovery
- 07Network Security
- 08Logging & Monitoring
- 09Security Awareness
- 10Incident Response
- 11Supplier / SaaS Security
- 12Governance & Assurance
- 13AI Security & Governance
Common questions
Yes. Cyber Ready is a standalone service. It does not require a Transformation Review, another Modern Working service or a managed IT service.
Readiness activities, priority improvements, reporting and ongoing assurance reviews within the organisation, users and environments agreed in your scope. Managed IT, monitoring and incident response are not included.
The size and complexity of your organisation, the users, sites and environments in scope, the frameworks you are working towards and your reporting needs.
We confirm onboarding work and any separate fee, minimum commitment, billing and cancellation terms before you proceed. Security products, licences and any additional work are separate unless expressly included in your proposal.
No security products or software licences are included unless your proposal expressly says so. Cyber Essentials, DSPT, PCI DSS and specialist assurance are scoped separately unless expressly included.
Book a conversation. We discuss your priorities and, if Cyber Ready fits, confirm the scope, fees and any additional costs in a written proposal. An enquiry does not commit you to a purchase.
No. Cyber Ready prepares and evidences your readiness; certification or validation follows the relevant external route. Where a scheme has additional requirements, completing the core checks alone is not enough, and we identify that additional work as part of your scope.
The applicable requirements have been addressed, the required evidence and operating records are available, and blockers are resolved or treated as the scheme permits. A business exception you accept is not automatically acceptable to an external scheme, and the independent assessor's decision remains theirs.
It depends on the framework and your goal. Some lead to certification by an independent body; others use assessment, validation or a self-assessment submission. We confirm the route for each framework when we agree the scope.
No. The ongoing service maps relevant evidence to supported frameworks and assembles it for your agreed assessment target. Readiness for several frameworks at once, management-system development and remediation are scoped separately.
No. Cyber Ready can be purchased independently. Its value extends across your organisation’s trust, controls, assurance and resilience, whether or not you are adopting AI.
Each action has an accountable owner in your organisation, and we agree who implements it and who verifies it. Remediation implementation is separate from Cyber Ready and is agreed with you before it begins.
We review available evidence and outstanding actions on an agreed schedule and hold regular assurance reviews. Where collection is automated, people still investigate exceptions and make decisions.
External certification and assessment fees are separate and are not part of Cyber Ready unless your agreement says otherwise.
No. We agree the requirements relevant to your organisation and what you want to achieve, then work to those.
No. You explain what matters to your business; the service translates that into scoped controls and evidence.
What do you need to demonstrate?
Tell us about a customer requirement, certification goal or concern about your protections. We will help define the route to readiness.
Every organisation starts from a different position. We agree the scope, outcomes and investment before any paid engagement begins. Each Modern Working service can be purchased independently.
Cyber Ready can be purchased independently. Its value extends across your organisation’s trust, controls, assurance and resilience, whether or not you are adopting AI.
AI Ready builds the capability to change how your business works.
