Market pack
United Kingdom
An outcomes-based regulatory culture rather than a control-checklist one. The platform is used differently here: less about proving a control exists, more about evidencing that a service stays inside its impact tolerance.
- PRIMARY AUTHORITIES
- NCSC, ICO, FCA and PRA
- INSTRUMENTS IN THIS PACK
- 7 national and sector, plus 13 international standards
- CONTRACTING
- Registered UK entity. UK clients contract in the United Kingdom.
Regulatory register
What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.
| Authority or instrument | What it is | Who it applies to | What the platform does |
|---|---|---|---|
| Information Commissioner's Office | UK GDPR and the Data Protection Act 2018, as amended; ICO accountability framework | Controllers and processors | Records of processing, DPIA workflow, rights handling with statutory clocks, transfer risk assessment, 72-hour breach workflow |
| National Cyber Security Centre | Cyber Assessment Framework | Operators of essential services and organisations adopting the CAF voluntarily | Outcome-based mapping across the four CAF objectives, with contributing outcomes evidenced rather than asserted |
| National Cyber Security Centre | Cyber Essentials and Cyber Essentials Plus | Organisations seeking baseline certification, including for public sector supply | Readiness position and evidence maintained between annual cycles |
| NIS Regulations 2018 | Network and information systems security duties | Operators of essential services and relevant digital service providers | Duties mapped to the control set, with incident notification workflow |
| FCA and PRA | Operational resilience — PS21/3 and SS1/21; outsourcing and third-party risk expectations | Authorised firms | Important business services, impact tolerances, dependency mapping, severe but plausible scenario testing and self-assessment evidence |
| Bank of England, FCA and PRA | Critical third parties regime | Designated critical third parties and the firms that rely on them | Concentration and dependency analysis, and the supplier-side evidence firms increasingly ask for |
| Telecommunications (Security) Act 2021 | Security duties and code of practice | Public telecoms providers | Sector control pack mapped to the same library |
| Standard | Scope | How it is used |
|---|---|---|
| ISO/IEC 27001:2022 and 27002 | Information security management system and control set | Certification readiness, live Statement of Applicability, continuous gap position |
| ISO/IEC 27701 | Privacy information management | Extends the ISMS control set with privacy-specific controls and DPO workflow |
| ISO/IEC 27017 and 27018 | Cloud security and cloud personal data | Applied where the estate is cloud-hosted or cloud-delivered |
| ISO 22301 | Business continuity management | BIA, recovery objectives, plan currency and exercise evidence |
| ISO/IEC 42001:2023 | AI management system | AI inventory, impact assessment and model governance |
| NIST CSF 2.0 | Cybersecurity framework | Used as the neutral spine when several national regimes apply at once |
| NIST SP 800-53 Rev. 5 | Control catalogue | Depth mapping where a client's control set is US-derived |
| CIS Controls v8 | Prioritised technical control set | Common baseline for technology teams |
| COBIT 2019 | Technology governance | Used in the Govern pillar for IT and digital governance structures |
| SOC 2 | Service organisation controls | Trust services criteria for clients who serve enterprise customers |
| PCI DSS 4.0 | Payment card security | Applied where card data is in scope |
| IEC 62443 | Industrial automation and control systems | Applied to OT estates alongside the national OT controls |
| Open FAIR | Risk quantification taxonomy | The quantification method used throughout the Anticipate pillar |
Hosting and contracting
Settle residency before tenant design. It is the item most often left until too late.
Data residency
UK hosting is available. Firms with EU operations should also settle their position on EU processing and, where in scope, the EU digital operational resilience regime.
Contracting entity
Registered UK entity. UK clients contract in the United Kingdom.