The evidence CYBER SECURITY · COMPLIANCE

Cyber Essentials Plus implementation. Then ISO 27001 if the buyer asks.

Say yes to AI, safely. Walk into the insurance renewal with a pack they can read.

Cyber Essentials and Cyber Essentials Plus for the form that keeps coming back. ISO 27001 when you sell to enterprise, PE, or the public sector. We implement the controls. An accredited assessor certifies.

From 26 April 2026 the scheme gets harder. MFA on every cloud service. Critical patches inside 14 days. Renewing on last year's answers stops working.

CE+ readiness from £2,950, fixed · ISO 27001 from £15,000
EVIDENCE CONTROLS IMPLEMENTED · EVIDENCE AN INSURER CAN READ
01

Who this is for

The form that keeps coming back
The reader of the pack

You need a pack the insurer can read.

Finance directors and managing directors who have become the IT department. Professional services of 50-200. South West wealth, IFA, and SIPP firms. PE-backed businesses that need evidence in the data room.

Why now

The insurer's proposal form, the buyer's questionnaire, and the scheme change of 26 April 2026 all point the same way: the answers need documents behind them, with owners and dates.

The sprint builds that pack once, properly, so the next form is an afternoon rather than a quarter.

From 26 April 2026certificates renew against the tightened scheme. What passed last year can fail this year. This sprint closes that gap.
The insurance renewalasks for MFA, patching, backups and access control on the proposal form. The answers move the premium.
The buyer's questionnaireasks for CE+, and at the top end for ISO 27001. The firm that answers with a certificate stops writing essays.
02

What we do

The work before the assessor
The work

We implement. We do not certify.

  • Scope the estate. What is in. What is out. Who owns each control.
  • Cyber Essentials and CE+ control work. Patching, access, MFA, backups, the boring things insurers actually ask for.
  • ISO 27001 when the buyer or the fund requires it. Policy, risk, evidence, the management system (the ISMS) an assessor can walk through.
  • An insurance cyber questionnaire answered with documents rather than adjectives.

PCI DSS appears in our proof because it was implemented in a live estate, in twelve months, alongside ISO 27001. The assurance we sell here is CE, CE+, and ISO 27001.

03

The AI angle

Say yes to AI, safely
AI enablement

The evidence pack is what lets the firm say yes to AI safely.

Everyone tells firms to adopt AI. AI fails on estates where security and data are ungoverned: a Copilot rollout or a production agent sits on the same access, MFA, patching and data handling this sprint puts in writing. Build the controls once and the board's AI question gets the same kind of answer as the insurer's: documents, owners, dates.

If a buyer or regulator asks how your AI use is governed, ISO 42001 (the AI management standard) is the answer in writing: readiness from £6,500, standalone or scoped into the same ISO engagement. We implement. An accredited assessor certifies.

04

How it runs

Diagnose. Deliver. Decide.
01

Diagnose

We sit with the people who actually run the estate. We read the last insurer form, the last buyer questionnaire, and the last "we will do that next quarter".

02

Deliver

Board-readable outcome: a control pack, a gap list that has been closed or owned, and a date with an accredited assessor if you are ready.

03

Decide

Someone has to keep the pack alive. That is the fractional Head of IT seat. Or we leave the place stronger and you run the cycle yourselves.

05

What you leave with

Documents, owners, dates
The pack

A pack an insurer, a PE house, or an enterprise buyer can read.

Controls implemented, with owners.

A path to CE, CE+, or ISO 27001 certification through an accredited assessor. We are not that assessor.

Fewer questions that bounce to the FD.

06

The price

Fixed, in writing, before anything starts
CE+ readiness

Cyber Essentials Plus readiness and remediation

From £2,950, fixed

The control work, the remediation, and the evidence, ready for the assessment.

The assessor's certification fee is separate and paid to the certification body.

ISO 27001

ISO 27001 implementation

From £15,000

Scoped at the diagnose stage. Policy, risk, evidence, the ISMS an assessor can walk through.

The UKAS-accredited audit is separate and paid to the auditor.

ISO 42001

ISO 42001 readiness

From £6,500

The AI management standard. Your AI use mapped, the gaps closed, the documentation prepared. Standalone, or scoped into the ISO 27001 engagement.

An accredited assessor certifies, when you choose to go that far.

Fixed pieces of work, priced in writing before anything starts, with the assessor and audit fees itemised separately. The total is visible before you commit.

07

FAQs

The questions the FD asks first

Do you certify Cyber Essentials or ISO 27001?

No. The Technology Framework is not a certification body. We implement the controls. An accredited assessor certifies CE, CE+, and ISO 27001.

What is the difference between Cyber Essentials and CE+?

Cyber Essentials is the self-assessed baseline most insurers now expect. CE+ adds a hands-on technical test by an assessor. If the renewal or the buyer asks for Plus, plan for Plus.

When do we need ISO 27001 as well?

When you sell to enterprise, PE, or the public sector, and they ask for it in the contract or the data room. We implement. The assessor certifies.

Will this help with the insurance cyber questionnaire?

That is the point of the sprint. The renewal pack is documents, owners, and dates, in place of a paragraph of intent.

Can this run while we keep our MSP?

Yes. You keep the MSP if it works. We sit above it and make the controls real. The MSP often does the tickets that the controls create.

Do you sell a separate vCISO product?

No. Board cyber sits inside the Head of IT seat and this sprint. We do not sell a standalone vCISO line.

What changes in April 2026?

The Cyber Essentials scheme gets harder on 26 April 2026: MFA on every cloud service, and critical patches inside 14 days. If your certificate renews after that date, the gap between passing last year and passing now is exactly what this sprint closes.

What is ISO 42001, and do we need it?

ISO 42001 is the management-system standard for AI: the AI equivalent of ISO 27001. Buyers and regulated clients are starting to ask about it wherever AI touches the service. Our readiness work maps your AI use, closes the gaps, and prepares the documentation. An accredited assessor certifies, when you choose to go that far.

What does it cost?

CE+ readiness from £2,950, fixed. ISO 27001 implementation from £15,000, scoped at diagnose. ISO 42001 readiness from £6,500. Assessor and audit fees are separate, paid to the accredited bodies.

09

Start the conversation

Bring the insurer form
Contact

Start the conversation.

The first conversation costs nothing and changes what happens next. Bring the insurer form, the buyer questionnaire, or the renewal date.

Call 0117 456 5486. The voice that answers is our own AI call agent, in production, on our own line. We run our practice on what we sell. Hear it running.

Or talk to the agent in the corner of this page. It takes the detail, and a named senior calls you back.

Talk to us