Compliance
Operate framework-specific workspaces for ISO 27001, SOC 2 readiness, Cyber Essentials and Cyber Essentials Plus, NIST CSF 2.0 and CIS Controls v8.1 while reusing shared PurpleWASP Controls and assurance records.
From framework scope to demonstrable readiness and improvement
Choose the framework, establish its scope/profile/engagement, make the framework-specific decisions it requires, connect shared Controls and assurance, then use readiness, gap or continual-improvement views to drive the next action.
Choose ISO 27001, SOC 2, Cyber Essentials/Plus, NIST CSF 2.0 or CIS Controls v8.1.
Define the management-system, engagement, assessment or Organizational Profile boundary.
Record framework-specific applicability, criteria, questionnaire or Current/Target decisions.
Reuse organisation Controls and connect implementation, evidence, assessments, testing, issues and exceptions.
Use drivers, readiness, gaps, remediation and improvement actions to focus the next work.
Implement the selected Implementation Group through shared Controls
Confirm scope and accountability, work through targeted Safeguards, resolve Control coverage, reuse assurance and prioritise improvements without duplicating organisation-Control state.
Use Organizational Profiles to manage cybersecurity outcomes
Assess the complete CSF 2.0 Core, compare Current and Target Profiles, reuse shared Control assurance and turn gaps into an improvement plan.
Prepare for Cyber Essentials and Cyber Essentials Plus
Work from scope and questionnaire through technical-area readiness, remediation and the Plus technical-assurance workflow.
Prepare for SOC 2 without overstating the assurance outcome
Use PurpleWASP for management-side SOC 2 readiness, Control coverage, evidence, testing, remediation and audit preparation.
Operate the ISMS and continual-improvement cycle
Maintain Clauses 4–10, the Statement of Applicability, recurring assurance and operational registers in one connected ISMS workspace.
Configure and maintain the ISO 27001 ISMS
Maintain scope/context, objectives, legal obligations, training, suppliers, incidents, access reviews, BC/DR, internal audit, management review, nonconformities and compliance activity.
Annex ABuild the Statement of Applicability
Set Annex A applicability and implementation status, then connect Policies, Risks, Controls and evidence.
Reuse Controls and understand framework-specific readiness
Use shared organisation Controls across frameworks while keeping each framework's applicability, assessment and readiness model distinct.
Framework status and external assurance conclusions have different owners
PurpleWASP structures and connects the organisation records needed for compliance, readiness and improvement. External certification or independent attestation decisions remain with the appropriate external assurance provider where the framework uses one.
- SOC 2: PurpleWASP supports readiness management and audit preparation; it does not issue the service auditor opinion.
- Cyber Essentials/Plus: internal readiness and technical-assurance records do not replace the Certification Body/Assessor decision.
- NIST CSF 2.0: Current/Target percentages are PurpleWASP visualisations, not NIST certification, conformance or maturity scores.
- CIS Controls v8.1: Assessment Coverage, Implementation Progress and PurpleWASP Readiness are internal implementation indicators, not official CIS certification or CAS results.
- ISO 27001: dashboard percentages and internal assurance records are not themselves certification decisions.
- Use Control Management as the authoritative organisation-Control implementation and assurance layer shared across frameworks.
No guidance matches that search.