The compliance engine
Controls, risks, assets and evidence as linked registers, sealed so nobody can quietly tidy them later. Run your own Cyber Essentials in it. Then run your customers'.
Cyber Essentials fails on spreadsheets. The register goes stale the week after certification, the evidence lives in someone's inbox, and next year's renewal starts from scratch. The usual fix is a consultant and a shared drive. That gets a certificate; it does not leave anything running.
Concorbit keeps compliance in the same system that runs the rest of your business, as registers that stay live because the work that updates them happens next to them.
Compliance fails on spreadsheets because the work that should keep the register current happens somewhere else. Here it happens next to the register.
| Concorbit | A spreadsheet | |
|---|---|---|
| Register stays current after certification | ✓ | ✕ |
| Evidence sealed and hashed at upload | ✓ | ✕ |
| A failed requirement becomes a ticket with an owner | ✓ | ✕ |
| Coverage figure the system can defend to an assessor | ✓ | a claim |
| Reviews come back on their own | ✓ | ✕ |
| Next year starts from where you left off | ✓ | from scratch |
A risk links to the controls that treat it, the assets it sits on and the parts of the business it touches. Controls map onto your scope in a matrix, cell by cell, with evidence attached to the cell. The coverage figure will not read 100% while any cell is unassessed, so the number you show an assessor is one the system can defend.
Every file is virus-scanned, hashed and sealed onto the audit chain at upload. There is no delete button: evidence is retained for at least three years, and only the retention rules can remove it after that. Integrity is re-verified every five minutes, and if that check ever fails the module says so on the page instead of quoting numbers it no longer trusts. Policies get the same discipline: versioned, approved by a named person, attested by staff with each attestation recorded.
Adopt the framework and it materialises as a working assessment, with a verdict recorded against each requirement. A failed requirement becomes a gap, and a gap becomes a helpdesk ticket or a project task with an owner, in the same system. Completing an assessment freezes what was decided and seals it onto the audit trail.
Set a review interval on any control or risk. The reminder arrives, the date appears in the calendar, and marking it reviewed can raise the next piece of work. Certifications and insurance renewals remind at 90, 30 and 7 days before expiry.
The numbers an assessor asks about are the ones the engine keeps.
Cyber Essentials requirements, mapped
starter controls, ready on adoption
minimum evidence retention
integrity re-checked, or it says so
Virus-scanned
Hashed and sealed
No delete button
Versioned policies
Your customers need Cyber Essentials, and most of them will not get there alone. That is a service, and you are the one positioned to run it.
Each customer gets their own Concorbit workspace with its own registers, its own evidence and its own audit chain; nothing pools. You provision it, and with the customer's consent you switch in and do the work: adopt the framework, build the registers, chase the reviews. The customer controls that access and can end it. What the managed service costs them is your price.
Compliance is not metered yet. When a meter ships it will be priced at cost, like email and 365 backup; you pay cost, and the margin on the service is yours.
One honest limit: today you work in each customer's workspace in turn.
One framework ships today: Cyber Essentials. The engine underneath is not CE-shaped; frameworks are data packs.
Watch the gap arrive in your helpdesk as a ticket with an owner.