CMMC Phase 2 Suspended: What It Means for Your Supply Chain

Key Takeaways Introduction The US has hit pause on the part of CMMC that most worried organisations in the supply chain. On 13 July 2026 it suspended Phase 2, the stage that would have forced mandatory independent assessment from 10 November 2026. A pause is not the same as the end, so it would be […]

The Cyber Security and Resilience Bill: Who It Impacts

Key Takeaways The rules that govern cyber security in the UK are about to cover far more organisations than they do today. Until now, legal duties fell only on operators of essential services, in sectors such as energy, transport, water, health and digital infrastructure, and on a small group of digital providers, namely online marketplaces, […]

Defence Cyber Certification: Certify Before You Bid 

Key Takeaways With the demise of the UK MOD accreditation process, the ability to demonstrate a business conformed to MOD assurance requirements, was lost.  This has had significant ramifications for UK businesses, resulting in an increase in due diligence activities to provide evidence of compliance with MOD requirements for every contract or collaboration activity a […]

Cloud Is In Scope: What Cyber Essentials Requires From You

Cyber Essentials Cloud Scope

Amy Osborne, Head of Audit Services Key Takeaways Some organisations approach Cyber Essentials assuming that because their data sits in Microsoft 365 or another cloud platform that information security is largely someone else’s responsibility; however, that assumption can cause assessments to fail. Your cloud provider secures the infrastructure it runs but your organisation is responsible […]

Cyber Essentials Scoping: The Decision That Determines Whether You Pass or Fail

Cyber Essentials Scoping: The Decision That Determines Whether You Pass or Fail

Key Takeaways Introduction Most organisations focus on the five technical controls when preparing for Cyber Essentials. Fewer give the same attention to scoping and that is where assessments are quietly lost before a single question has been answered. The scope defines exactly which systems, devices, and services are being assessed. Too broad, without the right […]

List X Is Now Facility Security Clearance (FSC): What Changed, What Didn’t, and What It Means for Your Accreditation 

Key Takeaways  Introduction  The term “List X” is still relevant to other parts of HMG, but not MOD. MOD have now fully embraced FSC, replacing the List X approach to securing facilities.  This said, you will often come across the term ‘List X’ being used in Defence related conversations and it is worth being cautious of this.  Many well-meaning people refer to […]

Cybersecurity Maturity Model Certification 2.0: Requirement for UK Contractors in US Defence

Key Takeaways If your organisation supplies components, software, services, or specialist expertise into the US defence market, the rules for doing so have changed. The US Department of Defence (DoD) Cybersecurity Maturity Model Certification (CMMC) 2.0 is no longer an aspiration. Phase 1 went live in November 2025, and Phase 2, mandatory third-party certification, arrives […]

Beyond the Questionnaire: What Real Supply Chain Assurance Looks Like for PRIMEs 

Key Takeaways  Every year, a swathe of SAQs are issued and respective suppliers fill them in. In effect, the box gets ticked.   For many Prime’s, this has become the accepted standard for supply chain assurance, repeated without question year after year. This level of complacency is a problem and the regulatory environment is making it harder to ignore. Under CSMv4 and DEFCON 658, what Prime’s are now […]

Breach, Report, Recover: What Security Incidents Organisations must Report and how to do it

Key Takeaways:  When a security incident occurs, the instinct in many organisations is to delay,  assess whether the magnitude of the incident and then judge whether or not to report the incident. This procrastination is itself a compliance failure. ISN 2025/03, issued by the Ministry of Defence in May 2025, removes any ambiguity.  Defence suppliers are obligated to report all security incidents promptly.   This blog sets out what that […]