The compliance engine

Compliance that survives being checked.

Controls, risks, assets and evidence as linked registers, sealed so nobody can quietly tidy them later. Run your own Cyber Essentials in it. Then run your customers'.

The spreadsheet problem

Cyber Essentials fails on spreadsheets. The register goes stale the week after certification, the evidence lives in someone's inbox, and next year's renewal starts from scratch. The usual fix is a consultant and a shared drive. That gets a certificate; it does not leave anything running.

Concorbit keeps compliance in the same system that runs the rest of your business, as registers that stay live because the work that updates them happens next to them.

One set of linked registers

A risk links to the controls that treat it, the assets it sits on and the parts of the business it touches. Controls map onto your scope in a matrix, cell by cell, with evidence attached to the cell. The coverage figure will not read 100% while any cell is unassessed, so the number you show an assessor is one the system can defend.

Cyber Essentials, requirement by requirement

Adopt the framework and it materialises as a working assessment: 39 requirements, 15 starter controls already mapped to them, a verdict recorded against each. A failed requirement becomes a gap. A gap becomes a helpdesk ticket or a project task with an owner, in the same system, so remediation is scheduled work rather than a note in a document. Completing an assessment freezes what was decided and seals it onto the audit trail.

Evidence that cannot be quietly edited

Every file is virus-scanned, hashed and sealed onto the audit chain at upload. There is no delete button: evidence is retained for at least three years, and only the retention rules can remove it after that. Integrity is re-verified every five minutes, and if that check ever fails the module says so on the page instead of quoting numbers it no longer trusts. Policies get the same discipline: versioned, approved by a named person, attested by staff with each attestation recorded.

Reviews that come back on their own

Set a review interval on any control or risk. The reminder arrives, the date appears in the calendar, and marking it reviewed can raise the next piece of work. Certifications and insurance renewals remind at 90, 30 and 7 days before expiry.

Sell it as a managed service

Your customers need Cyber Essentials, and most of them will not get there alone. That is a service, and you are the one positioned to run it.

Each customer gets their own Concorbit workspace with its own registers, its own evidence and its own audit chain; nothing pools. You provision it, and with the customer's consent you switch in and do the work: adopt the framework, build the registers, chase the reviews. The customer controls that access and can end it. What the managed service costs them is your price.

Compliance module is billed per compliance module and supports being used for the parent tenant or customer's in their customer portal. This allows you to create wrap around services and co-deliver compliance at customer estates.

One framework today

One framework ships today: Cyber Essentials. The engine underneath is not CE-shaped; frameworks are data packs.

Adopt Cyber Essentials in a trial workspace and mark one requirement not met.

Watch the gap arrive in your helpdesk as a ticket with an owner.