Skip to content

Frameworks and Assessments

Map your organisation's cyber posture against recognised global standards, and translate findings into prioritised remediation and demonstrable compliance.

DCC and ASSURE-accredited
PCI QSA-certified
UK-based, security-cleared consultants

One of the UK's leading providers for accredited cyber expertise

Holding the broadest accreditation portfolio in the UK cyber sector, CSA Cyber offers assurance built on independently validated expertise, giving organisations confidence that their protection meets the highest industry benchmarks.
ISO-IEC 42001 1
ISO 27001 1
ISO 9001 1
accred-ccoe
accred-microsoft-1
MISA Member badge_white background_MS Security logo-1
CE-Cert-Body
CE-Plus-Cert-Body
accred-octwf-1
CHECK Penetration Testing (Dark Logo)
62e468cf-a2e6-4271-840c-ba22fd7cd710
accreds-pciqsa-1
accred-caa-1
certs-part3_0003_PT-1
certs-part3_0001_STAR-1
certs-part3_0000_va-1
certs-part3_0002_SOC-1
certs-part3_0004_IR-1
comptia logo
AG-Distributor
AG-mssp

Our services

From preparing for certification, to responding to regulatory requirements and assessing cyber maturity, our consultants help organisations identify security gaps, define remediation priorities and deliver technical improvements to meet a range of recognised standards and frameworks.

ISO 27001: Information Security

Independent assessment of information security governance, controls and evidence against ISO 27001 requirements, supported by practical remediation and certification guidance.

This service supports:

  • Clear understanding of the controls, evidence and governance required for certification.
  • Demonstrable alignment between information security risk and organisational controls.
  • A structured route to achieving and maintaining ISO 27001 certification.
Explore service →

PCI DSS

Assessment, validation and QSA-certified advisory support for organisations that store, process or transmit cardholder data, from initial scoping to ongoing PCI DSS compliance.

This service supports:

  • Stronger protection of cardholder data across your environment.
  • A defensible route from scoping through to certification.
  • Independent, audit-ready assurance of your compliance position.
Explore service →

NIST Cyber Security Framework

Evaluation of cyber maturity across governance, controls and technology using the NIST Cyber Security Framework (CSF) to identify priorities and guide improvement.

This service supports:

  • A recognised, industry-standard reference point for cyber maturity.
  • Clearer prioritisation of security investment based on risk and exposure.
  • A shared reference point for leadership, technical teams and regulators.
Explore service →

NCSC Cyber Assessment Framework

Assessment of cyber resilience outcomes against the NCSC Cyber Assessment Framework (CAF), supporting regulatory compliance and alignment to UK best practice.

This service supports:

  • Demonstrable alignment with recognised UK cyber resilience expectations.
  • Clear visibility of where outcomes are achieved versus where gaps remain.
  • A stronger evidence base for regulators and sector oversight bodies.
Explore service →

Cyber Essentials

Independent, hands-on testing and certification support against the UK Cyber Essentials (CE) and Cyber Essentials Plus (CE+) schemes.

This service supports:

  • Government-recognised assurance of baseline security controls.
  • Removal of common attack paths before they're exploited.
  • Demonstrable compliance with the controls expected across public-sector, defence and supply-chain environments.
Explore service →

ISO 42001: Artificial Intelligence

Governance, risk and certification guidance for organisations establishing structured oversight of AI systems in line with ISO/IEC 42001.

This service supports:

  • Demonstrable, responsible governance of AI systems.
  • Alignment with emerging AI regulation and sector expectations.
  • Reduced risk of bias, misuse or uncontrolled AI deployment.
Explore service →

Defence Cyber Certification (DCC)

Readiness support and certification audits against the IASME's Defence Cyber Certification (DCC) scheme.

This service supports:

  • Clear understanding of Defence cyber requirements and certification readiness.
  • Demonstrable alignment with MOD cyber assurance expectations.
  • Improved eligibility for UK Defence supply-chain and procurement contracts.
Explore service →

ISO 22301: Business Continuity

Review, validation and certification support for organisations seeking to strengthen business continuity and align with ISO 22301 requirements.

This service supports:

  • Confidence that critical operations can withstand disruption.
  • Clear ownership and testing of continuity and recovery plans.
  • Demonstrable resilience for customers, regulators and insurers.
Explore service →

Cyber Security Assessment

End-to-end evaluation of cyber maturity across governance, controls and technology to identify material risks and prioritise improvement activity.

This service supports:

  • A clear, evidence-based view of current security posture.
  • A prioritised roadmap for closing the highest-impact gaps.
  • A stronger basis for strategic security investment decisions.
Explore service →

IEC 62443: Operational Technology

Security reviews, segmentation planning and control design for operational technology (OT) environments across manufacturing, energy, utilities and other critical industries.

This service supports:

  • Reduced risk of disruption to critical operational systems.
  • Clear separation of OT and IT environments through structured segmentation.
  • A defensible position against sector regulation and insurers.
Explore service →

SOC 2

Readiness assessment, control validation and examination support for SaaS, technology and service providers pursuing SOC 2 Type I or Type II attestation.

This service supports:

  • Independent assurance that satisfies enterprise customer due-diligence.
  • Demonstrable alignment to relevant Trust Services Criteria.
  • A smoother path through SOC 2 Type I or Type II examination.
Explore service →
ISO CERTIFICATIONs • iso 27001 • ISO 42001 • ISO 22301

Achieve and maintain certification against recognised ISO standards

Achieving certification requires more than documented policies or isolated controls. Organisations must be able to demonstrate that governance, risk management and operational processes are consistently applied, evidenced and capable of withstanding independent assessment.

We support organisations at every stage of the certification lifecycle, from gap analysis and readiness assessment through to remediation, implementation guidance and audit preparation across information security, artificial intelligence and business continuity.

Our services include:

ISO 27001: Information Security

Establish exactly where current practices fall short of ISO 27001:2022 requirements.

This can include: 

  • Review of existing controls, policies and governance arrangements against ISO 27001 requirements.
  • Identification and prioritisation of remediation activities required to address gaps.
  • Certification readiness assessments, evidence reviews and audit preparation.
Get in touch →

ISO 42001: Artificial Intelligence

Govern, manage and evidence AI risk in line with ISO/IEC 42001.

This can include:

  • Assessment of existing AI governance, accountability and risk management practices.
  • Development of policies, controls and oversight mechanisms aligned to ISO 42001.
  • Certification readiness reviews and evidence validation ahead of formal assessment.
Get in touch →

ISO 22301: Business Continuity

Define how critical operations are maintained, recovered and tested during disruption.

This can include:

  • Assessment of continuity plans, governance structures and recovery arrangements.
  • Identification of improvement opportunities across continuity and resilience capabilities.
  • Testing support, exercise facilitation and certification preparation.
Get in touch →

What to expect from our ISO services:

Outcome

An understanding of certification readiness

Assessment activities establish where current controls, processes and governance arrangements align to certification requirements, and where further work is required.

Outcome

A clear path to certification

Gap analysis, remediation planning and audit preparation provide a defined pathway towards certification, reducing uncertainty and helping organisations prioritise effort effectively.

Outcome

Foundations for long-term resilience

Controls, governance structures and operational processes become embedded across the organisation, helping security, continuity and risk management mature over time.

ISO 27001: INFORMATION SECURITY

Build an ISMS that stands up to certification and scrutiny

As customers, regulators and insurers increasingly expect independently verified security, ISO 27001 has become the reference standard for proving that information risk is properly governed rather than informally managed. Organisations without a structured ISMS often struggle to evidence ownership, consistency or continuous improvement when it matters most.

We support organisations through gap analysis, risk assessment, policy development and control implementation, building a scalable ISMS aligned to ISO 27001:2022 and preparing teams and evidence for external certification audits.

Our services include:

ISO 27001 Gap Assessment

Establish exactly where current practices fall short of ISO 27001:2022 requirements.

This can include: 

  • Review of existing policies, controls and documentation against the standard
  • Identification of priority gaps and associated remediation effort
  • A clear baseline to scope certification timelines and resourcing
Get in touch →

ISMS Design & Implementation

Build a structured, scalable Information Security Management System from the ground up.

This can include:

  • Development of core governance, security and operational policies
  • Design of risk assessment and treatment methodology
  • Definition of ownership, reporting lines and control frameworks
Get in touch →

Certification & Audit Support

Prepare teams, evidence and processes for formal certification and ongoing surveillance audits.

This can include:

  • Assembly of audit-ready documentation and evidence packs
  • Mock audits and readiness reviews ahead of certification
  • Guidance through corrective actions and continuous improvement cycles
Get in touch →

What to expect from our  ISO 27001 services:

Outcome

A defensible, independently verifiable ISMS

Security governance is structured, documented and mapped directly to ISO 27001:2022, giving auditors and stakeholders confidence that risk is actively managed rather than assumed.

Outcome

Faster, smoother path to certification

By resolving gaps and building evidence ahead of assessment, certification timelines shorten and the likelihood of major non-conformities at audit falls significantly.

Outcome

Reduced exposure to information security incidents

Controls are implemented consistently across the organisation, closing the gaps that attackers and internal errors most commonly exploit.

PCI DSS

Protect cardholder data and demonstrate payment security assurance

Organisations handling payment card data need a clear view of what sits in scope, which controls apply and what evidence is required to demonstrate compliance. For merchants, processors, acquirers, issuers and service providers, PCI DSS is not simply an assessment exercise; it is a way to validate how payment environments are protected across storage, processing and transmission.

Delivered by PCI QSA-certified consultants, this service provides structured scoping, gap analysis, evidence review, control validation and formal assessment, giving organisations a defensible route to PCI DSS compliance and stronger protection of cardholder data.

Our services include:

Scope Validation & Gap Analysis

Clarify the boundaries of your cardholder data environment and identify gaps before formal assessment begins.

This can include:

  • Identification of systems, processes and third parties that fall within PCI DSS scope.
  • Assessment of existing controls against PCI DSS requirements.
  • Prioritisation of remediation actions by risk and audit impact.
Get in touch →

ROC / SAQ Assessment

Validate required controls and evidence through formal Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ) review.

This can include:

  • Validation of assessment scope, evidence requirements and reporting obligations.
  • Testing of network segmentation, access management and encryption controls.
  • Verification of evidence and documentation against PCI DSS requirements.
Get in touch →

QSA Advisory & Ongoing Support

Interpret PCI DSS requirements in context and maintain compliance between assessment cycles.

This can include:

  • Review of evidence, artefacts and remediation progress.
  • Guidance on applying PCI DSS requirements to new systems, services and business changes.
  • Ongoing compliance support.
Get in touch →

What to expect from our PCI DSS services:

Outcome

Enhanced cardholder data protection

Controls across storage, processing and transmission are reviewed and validated, reducing exposure across the payment environment.

Outcome

A defensible compliance position


Evidence, documentation and control records are structured to withstand scrutiny from acquirers, card schemes and assessors.

Outcome

Independent assurance from a PCI QSA-certified practice

Assessment findings are backed by objective QSA-certified validation, giving organisations more than internal interpretation alone.

NIST CYBER SECURITY FRAMEWORK

Turn cyber maturity into a prioritised improvement plan

Many organisations have individual controls, tools and processes in place, but lack a structured view of how these capabilities combine into overall cyber maturity. Without that view, security investment can be driven by urgency, assumption or isolated findings rather than business risk.

Our assessment maps governance, controls, processes and technology against the NIST Cyber Security Framework (CSF), translating findings into maturity scoring, risk context and a prioritised roadmap for improvement.

Our services include:

NIST Cyber Security Framework (CSF) Assessment

Benchmark cybermaturity across the NIST CSF functions to understand how governance, protection, detection, response and recovery capabilities are performing in practice.

This can include:

  • Scoring of maturity levels against defined benchmarks.
  • Identification of capability gaps that create the greatest operational or security risk.
  • Analysis of improvement priorities.
Get in touch →

Risk Prioritisation & Roadmap Design

Translate maturity findings into a sequenced improvement plan shaped by risk, impact and available resource.

This can include:

  • Evaluation of the risks and capability gaps that require the earliest attention.
  • Development of a phased improvement roadmap with clear milestones and dependencies.
  • Alignment of recommendations to organisational priorities, budget and resource.
Get in touch →

Ongoing Maturity Tracking


Track progress against the framework as priorities, risks and organisational requirements change.

This can include:

  • Periodic reassessment against NIST CSF maturity levels.
  • Updated reporting for leadership and board oversight.
  • Refinement of priorities as new risks and requirements emerge.
Get in touch →

What to expect from our NIST CSF services:

Outcome

An evidence-based view of maturity

Strengths and weaknesses are mapped across governance, process and technology, creating a clearer picture of overall security capability.

Outcome

A roadmap for improving cyber maturity

Findings are translated into prioritised actions, helping organisations strengthen capability in the areas that will have the greatest impact.

Outcome

A common language for security decision-making

The NIST CSF established a shared framework for discussing security posture, investment priorities and progress across technical and leadership teams.

NCSC CYBER ASSESSMENT FRAMEWORK

Evidence cyber resilience against a recognised UK standard

For organisations operating essential services across sectors such as energy, healthcare, transport, digital infrastructure and government, the NCSC Cyber Assessment Framework (CAF) provides a recognised approach to assessing and evidencing cyber resilience. It is also a valuable benchmark for organisations outside direct regulatory scope that want to align to UK best practice and understand how their resilience would stand up to structured review.

We assess current practices against the CAF objectives, principles and expected outcomes, identifying what is achieved, partially achieved or not yet evidenced, and defining the actions required to strengthen resilience and regulatory readiness.

Our services include:

CAF Readiness Assessment

Establish current standing against the CAF's four objectives and underpinning principles.

This can include:

  • Evaluation of achieved, partially achieved and unmet CAF outcomes.
  • Identification of evidence already available versus evidence still required.
  • Comparison against regulator or sector-specific expectations.
Get in touch →

Evidence & Documentation Support

Build the evidence base needed to substantiate CAF outcomes.

This can include:

  • Development of documentation to support "achieved" and "partially achieved" ratings.
  • Structuring of evidence for regulator submission or review.
  • Guidance on closing outstanding gaps between assessment cycles.
Get in touch →

Ongoing Regulatory Liaison Support

Maintain readiness as CAF expectations, evidence requirements and sector oversight evolve.

This can include:

  • Preparation ahead of scheduled regulator reviews.
  • Updates to evidence as systems, suppliers or processes change.
  • Advisory input on emerging CAF guidance and sector requirements.
Get in touch →

What to expect from our NCSC CAF services:

Outcome

Clear standing against a recognised UK cyber framework

Practices are mapped transparently against CAF outcomes, giving organisations a defensible position ahead of internal review or regulatory engagement.

Outcome

Reduced risk of adverse regulatory findings

Gaps are identified and addressed proactively, rather than surfacing for the first time during a formal review.

Outcome

A stronger evidence base for oversight bodies

Documentation is structured to demonstrate how resilience outcomes are achieved, maintained and improved over time.

ON-DEMAND WEBINAR

Securing AI: How to enable innovation while mitigating risk

Explore the risks introduced by AI and LLMs, and how to manage them through structured governance, security-driven testing and informed decision-making, in this on-demand session from our offensive security and risk consultancy specialists.

CYBER ESSENTIALS

Validate security baseline controls for contracts, supply chains and assurance

Cyber Essentials (CE) and Cyber Essentials Plus (CE+) provide recognised validation that core technical controls are in place to defend against common cyber attacks. For organisations bidding into public-sector, defence-related or supply-chain contracts, certification can also be a practical requirement for demonstrating baseline assurance.

Our certified assessors support Cyber Essentials self-assessment and deliver hands-on technical auditing for Cyber Essentials Plus, validating controls across configuration, patching, malware protection, access management and internet-facing assets.

Our services include:

Cyber Essentials Self-Assessment Support

Guidance through the Cyber Essentials questionnaire and control requirements.

This can include:

  • Review of firewall, configuration, access, patching and malware controls.
  • Support completing and validating the self-assessment questionnaire.
  • Remediation guidance ahead of formal submission.
Get in touch →

Cyber Essentials Plus Technical Audit

Independent, hands-on testing to validate technical compliance for CE+.

This can include:

  • External vulnerability testing of internet-facing assets.
  • Internal testing of patching, hardening and access controls.
  • Assessment of malware protection, email security and web-based attack resilience.
Get in touch →

Certification Audit


Formal assessment by a certified CE+ auditor through to certification.

This can include:

  • Full independent audit against Cyber Essentials Plus requirements.
  • Resolution support for any findings ahead of sign-off.
  • Certification issued on successful completion.
Get in touch →

What to expect from our Cyber Essentials services:

Outcome

Government-recognised assurance of baseline controls

Certification provides official validation that core technical defences meet UK-mandated security expectations.

Outcome

Reduced exposure to common attack paths

Testing and remediation reduce weaknesses in configuration, patching, malware protection and access control.

Outcome

Eligibility for contracts requiring certification

Many public-sector and supply-chain contracts specify Cyber Essentials or CE+ as a minimum requirement, and certification satisfies that condition directly.

ISO 42001: ARTIFICIAL INTELLIGENCE 

Govern AI systems responsibly and demonstrably

As AI is adopted across systems, processes and decision-making, the associated risks extend beyond traditional security models into questions of bias, transparency and accountability that few existing governance frameworks address directly.

We help organisations build, implement and maintain an Artificial Intelligence Management System (AIMS) aligned to ISO/IEC 42001, covering governance, risk management and lifecycle controls through to certification readiness.

Our services include:

AI Governance Gap Assessment

Evaluate existing AI practices and documentation against ISO 42001 requirements.

This can include:

  • Review of current AI policies, controls and governance structures
  • Identification of maturity gaps against ISO/IEC 42001:2023
  • Stakeholder interviews to validate operational readiness
Get in touch →

AIMS Design & Control Implementation

Build the management system and controls required to govern AI responsibly.

This can include:

  • Design of AI risk and impact assessment processes
  • Definition of accountability structures and decision-making roles
  • Implementation of governance, security and operational controls across the AI lifecycle
Get in touch →

Certification Preparation

Prepare evidence and processes ahead of ISO 42001 certification.

This can include:

  • Assembly of audit-ready documentation and control evidence
  • Readiness reviews ahead of formal certification assessment
  • Guidance through corrective actions following audit findings
Get in touch →

What to expect from our  ISO 42001 services:

Outcome

Demonstrable, responsible AI governance

AI systems are designed, deployed and operated within clearly defined policies and oversight, rather than managed informally.

Outcome

Alignment with emerging AI regulation

Governance is structured to meet ISO 42001 and to adapt as AI-specific regulation continues to develop across jurisdictions.

Outcome

Reduced risk of bias or uncontrolled AI use

Lifecycle controls and risk assessments catch ethical, technical and operational issues before they affect users or decisions.

DEFENCE CYBER CERTIFICATION (DCC) 

Meet Defence cyber assurance requirements for supply-chain eligibility

Organisations supplying into the Defence sector, or preparing to pursue MOD contracts, must be able to evidence cyber assurance against Defence-specific requirements. Gaps identified late in the process can affect eligibility, delay opportunities or introduce remediation pressure when timelines are already constrained.

As a DCC certifying body, CSA Cyber supports readiness assessment, evidence preparation, remediation and certification audit activity, helping organisations understand what is required and address gaps before formal review.

Our services include:

DCC Readiness Assessment

Review current security posture against Defence cyber requirements.

This can include:

  • Mapping of in-scope systems, processes and suppliers to applicable controls.
  • Review of existing policies against MOD expectations.
  • Identification of technical and governance gaps ahead of certification.
Get in touch →

Evidence Preparation & Remediation

Prepare audit-ready evidence and patch policy, governance or technical gaps ahead of certification.

This can include:

  • Creation and validation of evidence for DCC review.
  • Development of Defence-aligned risk registers and treatment plans.
  • Remediation of technical and policy gaps ahead of formal audit.
Get in touch →

Certification Audit

Complete certification audit activity through CSA Cyber as a DCC certifying body where scope permits.

This can include:

  • Independent audit against Defence Cyber Certification requirements.
  • Resolution support for any findings raised during audit.
  • Certification issued on successful completion.
Get in touch →

What to expect from our DCC services:

Outcome

Clear readiness against Defence cyber requirements

Security posture is assessed against the requirements needed for Defence supply-chain participation.

Outcome

Demonstrable alignment with MOD cyber assurance expectations

Security controls, governance arrangements and supporting evidence are assessed against Defence cyber requirements, creating a clearer view of readiness and compliance.

Outcome

Stronger eligibility for Defence supply-chain contracts

Certification demonstrates the assured security posture increasingly required to participate in MOD procurement.

ISO 22301: BUSINESS CONTINUITY

Build resilience that holds up under real disruption

Disruption from cyber incidents, supplier failure or infrastructure loss is no longer a rare event, yet many continuity plans exist as static documents that have never been tested against a realistic scenario.

We support organisations in designing, implementing and testing a Business Continuity Management System aligned to ISO 22301, ensuring plans reflect how the organisation actually operates and recovers.

Our services include:

BCMS Gap Assessment

Assess current continuity arrangements against ISO 22301 requirements.

This can include:

  • Review of existing business continuity and disaster recovery plans
  • Identification of gaps in governance, testing and recovery capability
  • Benchmarking against ISO 22301 clauses and best practice
Get in touch →

BCMS Design & Plan Development

Build a structured continuity management system and supporting plans.

This can include:

  • Business impact analysis across critical functions and dependencies
  • Development of continuity, recovery and crisis communication plans
  • Definition of roles, escalation paths and governance structures
Get in touch →

Testing & Certification Support

Validate plans through exercising and prepare for certification.

This can include:

  • Design and facilitation of continuity exercises and scenario tests
  • Refinement of plans based on exercise outcomes
  • Preparation of evidence and documentation for ISO 22301 certification
Get in touch →

What to expect from our  ISO  22301 services:

Outcome

Confidence that critical operations can withstand disruption

Continuity plans are built around real dependencies and tested through exercising, rather than left untested until an actual incident.

Outcome

Clear ownership across recovery and crisis response

Roles, escalation paths and decision-making authority are defined in advance, reducing confusion when plans need to be activated.

Outcome

Demonstrable resilience for customers, regulators and insurers

A certified BCMS provides independently verifiable evidence that continuity risk is actively managed.

CYBER SECURITY ASSESSMENT

Bring governance, control and technology into one view of cyber maturity

Point-in-time findings from tools or isolated tests rarely show how governance, process and technology combine to shape an organisation’s overall maturity. Without that wider view, it becomes difficult to understand where risk is most material or where investment should be focused first.

This structured assessment evaluates governance, controls, processes and technology against the NIST Cyber Security Framework, translating findings into maturity scoring, risk-ranked priorities and a practical improvement roadmap.

Our services include:

NIST CSF Governance Review

Evaluate whether security governance, ownership and reporting support effective oversight.

This can include:

  • Review of security policies, ownership and reporting structures.
  • Assessment of strategic alignment between security and business objectives.
  • Identification of gaps in oversight and decision-making authority.
Get in touch →

Controls, Process & Architecture Evaluation

Assess how operational controls, processes and architecture contribute to cyber maturity.

This can include:

  • Evaluation of how security controls are implemented, governed and applied across the organisation.
  • Review of configurations and architecture for weaknesses and missing defence-in-depth.
  • Identification of misconfigurations and unmanaged risk.
Get in touch →

Roadmap & Prioritisation

Translate findings into a sequenced, actionable improvement plan.

This can include:

  • Mapping of findings to NIST CSF maturity levels.
  • Risk-driven prioritisation of remediation activity.
  • Development of a targeted uplift roadmap with measurable outcomes.
Get in touch →

What to expect from our Cyber Security Assessment services:

Outcome

A single view of cyber maturity

Strengths and gaps across governance, process and technology are captured in a single, structured view.

Outcome

An actionable improvement plan

Findings are prioritised by impact and likelihood, giving leadership a clear basis for investment and remediation.

Outcome

Greater confidence in security decision-making

Recommendations are grounded in independent assessment and recognised framework analysis, providing a stronger basis for investment and remediation decisions.

IEC 62443: OPERATIONAL TECHNOLOGY

Secure OT environments without disrupting operations

Operational technology (OT) underpins critical processes across manufacturing, energy, utilities, transport, logistics and other industrial environments. These systems were often designed for availability and safety rather than cyber security, yet growing connectivity between OT and IT has expanded the routes through which disruption can occur.

We assess and advise against IEC 62443, helping organisations define zones, conduits and control requirements that reduce cyber risk while respecting the constraints of live operational environments.

Our services include:

OT Security Assessment

Assess current OT+ and Industrial Control Systems (ICS) security posture against IEC 62443 requirements.

This can include:

  • Identification of assets, zones and conduits across the OT environment.
  • Assessment of segmentation between OT and IT networks.
  • Evaluation of controls against relevant IEC 62443 security levels.
Get in touch →

Zone & Conduit Design

Define the segmentation model required to contain risk across OT systems.

This can include:

  • Design of security zones and conduits aligned to operational requirements.
  • Definition of target security levels for each zone.
  • Development of a phased implementation plan that minimises operational disruption.
Get in touch →

Control Implementation Support

Support the rollout of controls in a way that protects uptime, safety and resilience.

This can include:

  • Guidance on implementing monitoring, access and segmentation controls.
  • Validation of controls against defined security levels.
  • Support for vendor and integrator coordination during rollout.
Get in touch →

What to expect from our Operational Technology services:

Outcome

Reduced risk to critical operational systems

Segmentation and targeted controls limit the potential for an IT-originated incident to disrupt industrial processes.

Outcome

Clear, defensible security zoning

Zones, conduits and security levels are documented and aligned to IEC 62443, providing a structured basis for ongoing control decisions.

Outcome

Security implemented around operational constraints

Controls are designed and sequenced around live system requirements, improving resilience without compromising uptime.

SOC 2

Meet customer assurance expectations with evidenced controls

For Software as a Service (SaaS), cloud, managed service, data platform and technology providers, enterprise customers increasingly expect independent evidence that security and operational controls are designed and operating effectively. SOC 2 provides that assurance by assessing controls against relevant Trust Services Criteria, such as Security, Availability, Confidentiality, Processing Integrity and Privacy.

We support organisations through readiness assessment, control design and evidence preparation ahead of SOC 2 Type I or Type II examination, helping reduce friction during customer due diligence and formal auditor review.

Our services include:

SOC 2 Readiness Assessment

Assess current controls and evidence against the Trust Services Criteria relevant to your business.

This can include:

  • Gap analysis against applicable Trust Services Criteria.
  • Review of existing controls, policies and evidence against SOC 2 expectations.
  • Prioritisation of gaps ahead of formal examination.
Get in touch →

Control Design & Implementation

Build the control descriptions, ownership and evidence processes needed for examination.

This can include:

  • Development of policies and control descriptions aligned to selected criteria.
  • Establishment of evidence collection and monitoring processes.
  • Assignment of control ownership and accountability across relevant teams.
Get in touch →

Examination Support

Support evidence preparation and auditor engagement through Type I and Type II examination cycles.

This can include:

  • Validation of evidence completeness and audit readiness.
  • Support responding to auditor queries during examination.
  • Guidance maintaining control operation between examination periods.
Get in touch →

What to expect from our SOC 2 services:

Outcome

Customer assurance supported by independent evidence

A SOC 2 report gives customers verifiable evidence of control effectiveness, satisfying due-diligence requirements without lengthy bespoke questionnaires.

Outcome

Stronger controls across selected Trust Services Criteria

Preparation strengthens the control environment around the criteria most relevant to your service and customer expectations.

Outcome

A smoother, better-evidenced examination

Structured evidence and clearly assigned ownership reduce friction and delay during the auditor's examination process.

WHY CSA CYBER?

Your organisation’s trusted partner in layered cyber resilience

With proven experience across critical sectors and a complete suite of accredited cyber services, CSA Cyber offers a single, trusted partner for protection, validation and continuous improvement. 

One partner, multi-layered cyber resilience

A premium suite of accredited services shaped by deep heritage in securing critical sectors and high-profile clients.  

Leading the UK for cyber excellence

 Our UK-based, security-cleared teams are trusted by clients and validated by recognised industry bodies across the globe.  

Engineered for high-security delivery

Our practice is deliberately scaled to combine major-provider capability with specialist-level precision and trust.  

Complete cyber assurance starts here

Talk to a specialist about how our ASSURE-accredited, PCI SCC-approved consultancy services can help manage your risk exposure and gain a clear view of your security and compliance position.