Compliance Has Been
Broken for a Decade

UK SMEs spend 3× more hours on compliance admin than their US counterparts.
The output is a Word document. No one is safer.

We built SCH because the GRC SaaS market spent a decade ignoring the UK. The current landscape is dominated by vendors built for VC-backed startups chasing SOC 2 logos: cloud-native stacks, six-figure contracts, and a US sales motion. Not one of them has invested a single engineer hour in the NCSC Cyber Assessment Framework, the framework UK Critical National Infrastructure actually has to comply with.

Meanwhile the people who genuinely need this stuff, UK SMEs chasing Cyber Essentials, FCA-regulated firms, NHS suppliers, CNI operators, vCISOs, are still running compliance on spreadsheets, Word documents, and three consultants in a Teams call.

“This is not a tooling gap. This is a market failure.”

The Old Way
  • Manual questionnaires, blank Word templates
  • PDF reports that age badly the moment they’re saved
  • Consultant-dependent: expert knowledge locked away
  • One framework at a time, one point-in-time snapshot
  • No evidence trail, certificates living in email inboxes
The SCH Way
  • Automated assessment with live tool signals pre-filled
  • Real-time scoring that updates as you act and remediate
  • Self-serve with expert AI guidance on demand
  • CE, CAF, DORA, ISO 27001, AI Act in parallel
  • Built-in Evidence Vault with certifier-ready audit pack export

Compliance Re-engineered

Nine frameworks. Four live integrations. One platform built for the SMEs and regulated organisations the GRC market forgot.

Assess

Nine production-grade frameworks

Cyber Essentials v3.3, CAF (incl. NHS DSPT), DORA, ISO 27001:2022, AI Governance (EU AI Act / ISO 42001 / NIST AI RMF), SOC Maturity, PE Cyber Due Diligence, the Cyber Resilience Maturity Assessment, and NIST CSF 2.0. 70-question assessments. Weighted scoring. Gap analysis. Not a checklist generator.

Connect

Your tools are already producing the signal. We read it.

Microsoft Entra ID, Google Workspace, CrowdStrike Falcon, and Okta connect once and push live telemetry including MFA coverage, endpoint compliance, prevention policies, and identity posture directly into your assessment as pre-filled hints. No manual evidence gathering.

Manage

Built for portfolios, not point-in-time projects

Multi-tenant client management, per-client assessment scoping, remediation tracking, AI-generated policy documents, and a public Trust Centre so your clients can show prospects they take security seriously.

AI that does the thinking,
not the ticking

Phronesis AI runs on every assessment. Not a chatbot. A structured analysis engine that reads your gaps and tells you what to do about them.

Phronesis AI

Analysis, guidance & remediation

Reads your scores, identifies critical gaps, maps your 90-day remediation roadmap, and generates board-ready output. Ask it anything mid-assessment: per-control regulatory guidance, remediation options, what a finding means for your sector. It answers in context. Not generic boilerplate. Calibrated to your actual gaps.

Supply Chain Risk Manager

External verification, not self-attestation

Questionnaire distribution to suppliers with no login required. Passive domain scanning across DNS, TLS, breach databases, and Companies House cross-checks self-reported answers against live signals. Monthly automated re-scans alert you when a supplier’s posture degrades between assessments.

Standard mode scores your answers against the framework. Deep Analysis goes further — it reads your evidence notes, cross-references your connected tools (Entra ID, CrowdStrike, Okta, Google Workspace), and grounds every judgement against the framework’s own official guidance, flagging contradictions between what you said and what your tools actually show. Every finding it raises becomes a tracked action in the Remediation Tracker — not a paragraph you’ll forget by Friday.

Risk Scenarios aren’t hypothetical. A scenario is only surfaced when its enabling weaknesses are actually present — a vulnerability becomes “enabled” when a specific assessment answer fails, when a section score drops below a set threshold, or when a connected tool signal (CrowdStrike, Entra ID, Okta, Google Workspace) surfaces something the self-reported answer didn’t. Close the gap and the scenario’s exposure drops, or it disappears from the list entirely.

Your assessment gaps mapped to real-world loss events — in business terms, not just IT findings.

“Compliance shouldn’t require a consultant, a spreadsheet, and a prayer.
It should be continuous, connected, and proportionate to what you actually face.”

One answer, six frameworks

Finish a Cyber Essentials assessment on Monday. See it referenced on your CAF assessment Tuesday — without touching a spreadsheet.

Most organisations working toward more than one framework end up answering close to the same question five or six times, once per framework, because CE, CAF, ISO 27001, CIS Controls, NIST CSF 2.0, and NIS2 all ask about MFA, patching, incident response and supplier access — just worded differently and scored differently. SCH cross-references every finalised assessment you’ve completed and surfaces what you already said, right underneath the related question on the next framework you run.

Crosswalk Hints 30 directions CE Cyber Essentials CAF NCSC framework ISO 27001 CIS Controls v8 NIST CSF 2.0 NIS2 Directive source only
Hints flow both directions
NIS2 feeds hints out, never receives them
6
frameworks in the hub
15
hand-authored relationship tables
30
directional pairings covered
0
answers ever auto-filled for you

Here’s what it looks like in practice — a practitioner who finalised Cyber Essentials starts a NIST CSF 2.0 assessment next, and sees this beneath the related question:

NIST CSF 2.0 · PROTECT · PR.AA
PR.AA‑03
Is multi-factor authentication enforced for all users accessing cloud-based services?
Fully aligned — enforced everywhere, no exceptions
Partially aligned — enforced on some services
Not aligned — not enforced
🔗 Cyber Essentials — “Is Multi-Factor Authentication (MFA) enabled on ALL cloud services?”: Yes, MFA is enabled on all cloud services. Finalised 12 Aug 2026 · informational only, not applied to this answer
Cross-framework references are Security Compliance Hub’s own analysis relating similar requirements — not an official or certified equivalence between frameworks.
Why it matters

Built for portfolios running more than one framework

  • Saves re-answering. You see your own prior answer immediately, instead of digging back through a finished assessment to check what you said.
  • Never auto-fills. Every hint is a reference, not a suggestion — you still make the call on the current framework’s own question.
  • Works both ways. Finalise NIST CSF 2.0 first, and the same hint appears back on Cyber Essentials the next time it’s opened.
  • NIS2 is the one exception. Its 56 questions are the broadest of the six, so NIS2 always contributes hints outward — it never receives one back.

Two more pairs go a step further than the hub above. CMMC Level 2 ↔ FedRAMP and NIST CSF 2.0 ↔ HIPAA aren’t part of the six-framework hub — each is backed by a real, official NIST-published control mapping, not our own interpretation, so instead of just showing what you answered elsewhere, SCH suggests a translated answer at medium confidence, which you can accept or override on the spot.

suggests answer CMMC Level 2 FedRAMP Rev5 Moderate

Sourced directly from NIST’s own SP 800‑171 ↔ SP 800‑53 control mapping — the same catalog both frameworks are built from. Works in both directions: finalise either one first, and it feeds a suggested answer to the other.

123 shared NIST SP 800‑53 controls
suggests answer NIST CSF 2.0 HIPAA Security Rule

Chained through two official NIST crosswalks — SP 800‑66 Rev 2’s HIPAA ↔ CSF v1.1 mapping, joined to NIST’s own CSF v1.1 → v2.0 transition table — so the version gap between the two is bridged with NIST’s own data, never a guess.

106 CSF Subcategories, 2 chained NIST tables
Also new on NIST CSF 2.0 reports
Partial Risk‑Informed Repeatable Adaptive

Every NIST CSF 2.0 report now includes an indicative Implementation Tier, mapped from your own answers onto NIST’s three official Tier dimensions — not a blunt conversion of your percentage score. Your overall Tier reflects your weakest dimension, never an average, and stays hidden until all three have at least one answer.

How it all fits together

The assessment engine, Phronesis AI, and Supply Chain Risk Manager run on a shared services foundation, with live security-tool integrations feeding real tenant data directly into assessment questions.

Security Compliance Hub platform architecture showing who plugs in (SMEs, MSP/vCISO practices, PE firms), the assessment engine, Phronesis AI advisor, Supply Chain Risk Manager, live security-tool integrations, and the trust and data foundation

See where you actually stand

Start with the Compliance Readiness Assessment. Free, no account needed, cross-framework picture in under 15 minutes. Or go straight to the framework that matters most to your obligations.