RESOURCES
Find out where you stand.
Six free tools, the reference library behind them, and the practitioner writing that explains what your buyers are asking for. No account needed to see your result.
Answer a few questions and get a position you can act on. No signup.
ISO 27001 Cost Calculator
A price band for the route that fits, plus a separate estimate of what your certification body will charge.
4 questions
OpenTOOLISO 27001 Readiness Check
A maturity profile across foundation, documentation, implementation, operational effectiveness and continual improvement.
12 questions, 5 minutes
OpenTOOLAI Governance Readiness Check
A score across six dimensions, showing which are most exposed to EU AI Act high risk enforcement.
12 questions, 5 minutes
OpenTOOLDefence Cyber Readiness Check
An indicative Def Stan 05-138 profile, a six domain scorecard and the frameworks your position calls for.
12 questions, 5 minutes
OpenTOOLISO 27001 to 42001 Bridge
Bridge feasibility, an expected duration range and the risks specific to your AI systems.
6 questions, 5 minutes
OpenTOOLMicrosoft Sensitive Use Classifier
Whether your AI system falls inside Microsoft's Sensitive Use definition, and what follows if it does.
6 questions
OpenReference material on the standards and what each one asks of you.
Practitioner writing on the decision in front of you.
ISO 27001 and ISO 42001 govern different things
Why holding one does not answer a buyer asking about the other.
OpenARTICLEISO 27001 or Cyber Essentials Plus
Which one your customer is actually asking for, and what each proves.
OpenARTICLEDCC and Cyber Essentials are not alternatives
Where the defence requirement goes beyond the baseline scheme.
OpenARTICLEReadiness assessment, internal audit, certification audit
Three different pieces of work, and when each one is the right buy.
OpenARTICLECan the consultancy that built your AIMS audit it
What ISO 19011 says about independence, and what auditors look for.
OpenARTICLEWhat ISO 42001 costs in the UK
The published figures, the variables, and what sits outside the fee.
OpenARTICLEWho can issue an ISO 42001 certificate in the UK
Accreditation status, and how to check a certificate is worth something.
OpenARTICLEThe four DCC levels, and what each asks
The control expectations at each level of Defence Cyber Certification.
OpenARTICLEWhat DCC Level 2 requires that Level 1 does not
The step up in evidence between the two lower levels.
OpenARTICLEChoosing a DCC certification body
What to ask before you appoint, and what the body cannot do for you.
OpenARTICLEDCC and JOSCAR are different things
Two defence supply chain requirements that are often confused.
OpenARTICLEDEFCON 658 explained
What the clause obliges Tier 2 and Tier 3 suppliers to do.
OpenNot sure where to start?
A free 45 minute diagnostic establishes which standards your buyers, regulator or supply chain actually require. No sales pitch.
