Skip to content

Compliance

Compliance in 786 Cyber isn’t a one‑off form — it’s a living score you can improve. Pick a framework, answer a guided wizard, and get a score plus a gap analysis that tells you exactly what’s missing and where to fix it.

  1. Go to Policy & Process → Compliance/CCM.
  2. Choose a framework — the launch set is Cyber Essentials Plus, NCA ECC and SAMA CSF, with more in the catalogue.
  3. Work through the wizard, answering each control Yes / Partial / No.
  4. Get your compliance score and gap analysis.

As you answer, inline AI validation can review your responses and evidence and offer a finding and recommendation — helping you answer honestly and consistently. (AI is used to validate and verify, not to invent answers for you.)

Your compliance score is the share of controls met, where a Partial counts as half. It updates as you answer more controls and close gaps — so progress on your dashboard and in your assessments moves together.

The Compliance Vault stores your assessments and tracks progress over time, so you can pause and resume, compare against a previous run, and show how you’ve improved.

Browse the full catalogue of compliance frameworks and threat models under Policy & Process → Framework catalogue. Every framework in the catalogue is included in your plan — there’s no per‑framework purchase, so you can explore or start an assessment against any of them. Each framework shows:

  • its domains and controls, and
  • cross‑mappings to other frameworks.

Cross‑mapping is the time‑saver — but it shows you the overlap rather than scoring it for you. One control you’ve satisfied often corresponds to controls in many other frameworks, so the work you did for Cyber Essentials is usually most of the work for ISO 27001, NCA ECC or SAMA CSF. What that saves you is the thinking and the evidence‑gathering: you can reuse the same evidence and answer the mapped control quickly, with the mapping telling you exactly where to look.

It does not auto‑tick anything. Each framework’s assessment is scored only on the answers you give in that assessment — answering a control in one framework doesn’t silently mark the mapped control complete in another. That’s deliberate: an assessor asks what you attested to for that framework, and a score built partly from inferred answers wouldn’t survive the question.

Where a control needs proof, you can attach evidence and link it to your answers, building an audit‑ready trail as you go.

Everything you attach collects in the Evidence Vault (Policy & Process → Evidence Vault) — one org‑wide library of every document, link and reference you’ve gathered, rather than evidence buried inside whichever assessment you happened to be doing at the time.

  • Five kinds of item: an uploaded File, an external Link, a storage Bucket, or a Policy or Control you already hold in the platform.
  • Filter by type to find things quickly, and tag items with your own labels.
  • Each item shows what it actually proves — the controls it’s attached to — so an item proving nothing yet is visible rather than hidden.

Enter once, reuse everywhere it genuinely applies. You store an item once, against a single question — then tag it and reuse it to satisfy the same requirement wherever it comes up again, in any framework. A single penetration test report or asset register stays one item in the vault, rather than the same PDF re‑uploaded into every assessment that asks for it.

What it doesn’t do is propagate on its own: reusing an item is a deliberate step, not something applied silently to every mapped control. That’s the same principle the rest of Compliance follows — cross‑mapped controls are surfaced for your review, never quietly marked as met, because you should be able to say why every piece of evidence sits where it does.

Third‑party reports — a manual penetration test, an external audit — belong here too, alongside the scans you run in the platform. See Reports.

See Policies & controls for how controls and evidence fit together.

From Compliance/CCM you can open the Security Universe — a galaxy‑style visualisation of the full catalogue of frameworks, controls and cross‑mappings, showing your own coverage mapped onto it. It’s a way to see the shape of the whole catalogue at once, not just the frameworks you’ve started.

For everyday security: a framework is a ready‑made checklist of good practice. Even if no one’s asking you to certify, working an assessment tells you where your real gaps are.

For compliance: this is the heart of proving yourself to customers and regulators — a defensible score, a documented gap analysis, evidence linked to controls, and cross‑mapping that shows you where one piece of work answers the same question in several frameworks.


Next: Security capabilities →