
List X Is Now Facility Security Clearance (FSC): What Changed, What Didn’t, and What It Means for Your Accreditation
Key Takeaways Introduction The term “List X” is still relevant to other parts of HMG, but
Our veteran information and cybersecurity consultants understand MOD requirements, as we have seen the challenges from both the Defence and Commercial side.
From SMEs to Global organisations, Pera Prometheus can assist you in navigating the bespoke requirements of the UK Ministry of Defence (MOD) environment.




At Pera Prometheus, our mission is to ensure your journey to compliance is seamless, transparent, and entirely stress-free. We understand that as your business grows, the regulatory landscape can feel increasingly complex.
To address the recent surge in enquiries and clear up common confusions, we’ve distilled the entire compliance journey into a Clear-Path Flowchart. This visual guide strips away the jargon and provides a step-by-step roadmap of what to expect, from initial assessment to final certification or compliance.
At Pera Prometheus, our mission is simple. We want to deliver real world security solutions that blend with your business goals. We want to understand your business and develop a security system that will allow you to safeguard your critical information assets and make informed decisions about the security of your business.
We can make information and cybersecurity threats relatable to your business and your people and, should the worst happen, we can prepare you to respond to an incident and get back to business as usual in a timeframe that is appropriate for you and your stakeholders.
We understand the critical nature of protecting your operations and assets from the increasing risk of both malicious and inadvertent information and cyber threats.
Pera Prometheus understands the world of information and cybersecurity can be overwhelming, particularly in the Government and MOD environments. Our consultants are selected for their particular abilities to deliver information security pragmatically, cost effectively and communicate technical and professional details in clear, concise everyday language that your business can relate to and act upon.
Explore some of our core services.
Cyber Essentials is the UK Government-backed certification that protects your organisation against the most common cyber threats — and is mandatory for MOD and Government contracts. At Pera Prometheus, our qualified Lead Assessors guide you through every step of the Cyber Essentials Certification and Cyber Essentials Plus Certification process in plain language, making what can feel like a complex process straightforward and well managed.
Whether you are looking for the self-assessed Cyber Essentials Certification or the independently verified Cyber Essentials Plus Certification, we support you from initial scoping right through to achieving your certificate — giving your clients, partners, and stakeholders the assurance they need.
Understand your Business Needs and the right Security Management Framework
At Pera Prometheus, our mission is to ensure that security is not only effective but aligns with your business processes to make security part of your normal business operations. Our consultants have extensive knowledge and experience with a variety of Security Management Frameworks and our first piece of work will be to understand your Business and advise you on the best framework to meet your needs.
Selecting the Right Security Management Framework for your Business
There are a whole range of Security Management Frameworks ranging from industry specific to globally applicable standards, which includes.
Engage the Service of highly experienced Information and Cyber Security Experts
Not all businesses want or need a full time CISO or Security Manager. It is also no secret that experienced security experts are in high demand and command high renumeration packages.
Find your Vulnerabilities before the real Threat Actors Do
Penetration Testing takes 2 forms; Physical Penetration Testing and Cyber Penetration Testing. Often referred to as Pen Tests they both ultimately improve security by conducting authorised simulated attacks used to identify weaknesses and vulnerabilities in an organisations security. Once identified, these vulnerabilities can by remediated to avoid them being exploited by hostile threat actors.
Hope for the Best, Plan for the Worst and Expect to be Surprised
None of us want to experience an information security incident or have to activate our Business Continuity Plans but the chances are that you will have to one day.
Navigating the specifics of UK MOD and other HMG Department Requirements
Pera Prometheus recognise that when fulfilling UK Defence and OGD requirements, information and cyber security requirements may differ somewhat from your wider commercial experience.

Key Takeaways Introduction The term “List X” is still relevant to other parts of HMG, but

Key Takeaways If your organisation supplies components, software, services, or specialist expertise into the US

Key Takeaways Every year, a swathe of SAQs are issued and respective suppliers fill them in. In effect, the box gets