UK SMEs spend 3× more hours on compliance admin than their US counterparts.
The output is a Word document. No one is safer.
We built SCH because the GRC SaaS market spent a decade ignoring the UK. The current landscape is dominated by vendors built for VC-backed startups chasing SOC 2 logos: cloud-native stacks, six-figure contracts, and a US sales motion. Not one of them has invested a single engineer hour in the NCSC Cyber Assessment Framework, the framework UK Critical National Infrastructure actually has to comply with.
Meanwhile the people who genuinely need this stuff, UK SMEs chasing Cyber Essentials, FCA-regulated firms, NHS suppliers, CNI operators, vCISOs, are still running compliance on spreadsheets, Word documents, and three consultants in a Teams call.
“This is not a tooling gap. This is a market failure.”
Nine frameworks. Four live integrations. One platform built for the SMEs and regulated organisations the GRC market forgot.
Cyber Essentials v3.3, CAF (incl. NHS DSPT), DORA, ISO 27001:2022, AI Governance (EU AI Act / ISO 42001 / NIST AI RMF), SOC Maturity, PE Cyber Due Diligence, the Cyber Resilience Maturity Assessment, and NIST CSF 2.0. 70-question assessments. Weighted scoring. Gap analysis. Not a checklist generator.
Microsoft Entra ID, Google Workspace, CrowdStrike Falcon, and Okta connect once and push live telemetry including MFA coverage, endpoint compliance, prevention policies, and identity posture directly into your assessment as pre-filled hints. No manual evidence gathering.
Multi-tenant client management, per-client assessment scoping, remediation tracking, AI-generated policy documents, and a public Trust Centre so your clients can show prospects they take security seriously.
Phronesis AI runs on every assessment. Not a chatbot. A structured analysis engine that reads your gaps and tells you what to do about them.
Reads your scores, identifies critical gaps, maps your 90-day remediation roadmap, and generates board-ready output. Ask it anything mid-assessment: per-control regulatory guidance, remediation options, what a finding means for your sector. It answers in context. Not generic boilerplate. Calibrated to your actual gaps.
Questionnaire distribution to suppliers with no login required. Passive domain scanning across DNS, TLS, breach databases, and Companies House cross-checks self-reported answers against live signals. Monthly automated re-scans alert you when a supplier’s posture degrades between assessments.
Standard mode scores your answers against the framework. Deep Analysis goes further — it reads your evidence notes, cross-references your connected tools (Entra ID, CrowdStrike, Okta, Google Workspace), and grounds every judgement against the framework’s own official guidance, flagging contradictions between what you said and what your tools actually show. Every finding it raises becomes a tracked action in the Remediation Tracker — not a paragraph you’ll forget by Friday.
Risk Scenarios aren’t hypothetical. A scenario is only surfaced when its enabling weaknesses are actually present — a vulnerability becomes “enabled” when a specific assessment answer fails, when a section score drops below a set threshold, or when a connected tool signal (CrowdStrike, Entra ID, Okta, Google Workspace) surfaces something the self-reported answer didn’t. Close the gap and the scenario’s exposure drops, or it disappears from the list entirely.
Your assessment gaps mapped to real-world loss events — in business terms, not just IT findings.
“Compliance shouldn’t require a consultant, a spreadsheet, and a prayer.
It should be continuous, connected, and proportionate to what you actually face.”
Finish a Cyber Essentials assessment on Monday. See it referenced on your CAF assessment Tuesday — without touching a spreadsheet.
Most organisations working toward more than one framework end up answering close to the same question five or six times, once per framework, because CE, CAF, ISO 27001, CIS Controls, NIST CSF 2.0, and NIS2 all ask about MFA, patching, incident response and supplier access — just worded differently and scored differently. SCH cross-references every finalised assessment you’ve completed and surfaces what you already said, right underneath the related question on the next framework you run.
Here’s what it looks like in practice — a practitioner who finalised Cyber Essentials starts a NIST CSF 2.0 assessment next, and sees this beneath the related question:
Two more pairs go a step further than the hub above. CMMC Level 2 ↔ FedRAMP and NIST CSF 2.0 ↔ HIPAA aren’t part of the six-framework hub — each is backed by a real, official NIST-published control mapping, not our own interpretation, so instead of just showing what you answered elsewhere, SCH suggests a translated answer at medium confidence, which you can accept or override on the spot.
Sourced directly from NIST’s own SP 800‑171 ↔ SP 800‑53 control mapping — the same catalog both frameworks are built from. Works in both directions: finalise either one first, and it feeds a suggested answer to the other.
123 shared NIST SP 800‑53 controlsChained through two official NIST crosswalks — SP 800‑66 Rev 2’s HIPAA ↔ CSF v1.1 mapping, joined to NIST’s own CSF v1.1 → v2.0 transition table — so the version gap between the two is bridged with NIST’s own data, never a guess.
106 CSF Subcategories, 2 chained NIST tablesEvery NIST CSF 2.0 report now includes an indicative Implementation Tier, mapped from your own answers onto NIST’s three official Tier dimensions — not a blunt conversion of your percentage score. Your overall Tier reflects your weakest dimension, never an average, and stays hidden until all three have at least one answer.
The assessment engine, Phronesis AI, and Supply Chain Risk Manager run on a shared services foundation, with live security-tool integrations feeding real tenant data directly into assessment questions.
Start with the Compliance Readiness Assessment. Free, no account needed, cross-framework picture in under 15 minutes. Or go straight to the framework that matters most to your obligations.