Enterprise — Govern & Scale
Run readiness as one programme across several sites, and report it upward
At a certain size the constraint stops being implementation and becomes consistency. Enterprise adds the governance layer: a scope and ownership map across sites, corrective actions tracked to verified closure, a small set of indicators management will actually read, and a reporting pack that turns all of it into a defensible view.
Who this is for
- Groups operating several sites or legal entities in scope
- Organisations with a formal obligation to report security posture upward
- Teams consolidating readiness that currently varies site by site
- Programmes that need corrective action tracked with verified closure rather than assertion
- Organisations planning to add sites or entities within the next year
Enterprise
Govern & Scale
Everything in Professional plus the governance layer multi-site organisations need: consolidated oversight, corrective action tracking, measurement and executive reporting.
- Multi-site governance model and scope mapping
- CAPA tracker with ownership and verification
- KPI / KRI dashboard structure
- Third-party portfolio register
- Training and competence matrix
- Executive reporting pack
Best for: Groups running several sites or legal entities, and teams that must report readiness upward on a fixed cycle.
The outcomes this tier is built for
One scope map across sites
Which site owns which part of the scope, and where the boundaries actually sit. The prerequisite for any consolidated view.
Corrective action with verified closure
A CAPA tracker with root cause, owner, verification and evidence — so a finding is closed because someone checked, not because someone said so.
Measurement management will read
A KPI and KRI structure built around a small number of indicators. Four measures reviewed seriously beat twenty collected mechanically.
A third-party portfolio view
Criticality tiering and review cycle across the whole portfolio rather than assessment by assessment.
Competence you can evidence
A training and awareness matrix by role, which is also the fastest way to answer a question about who was trained on what.
Executive reporting
A board-level readiness summary with a trend view, so the conversation is about direction rather than about a snapshot.
What is included
Quick Start Guide
How to sequence preparation work in the first four weeks.
Core Policies
Information security policy set with ownership and review cadence.
Readiness Roadmap
Phased plan from initial scoping to internal verification.
Evidence Guidance
What each theme typically needs to demonstrate, and who should own it.
Gap Assessment
Structured maturity and gap review with owner and target date per finding.
Risk Management
Risk register, criteria, treatment plan and residual risk acceptance.
Supplier Assessment
Third-party security questionnaire and follow-up tracking.
Internal Audit Programme
Audit plan, checklists, findings log and closure verification.
Management Review
Agenda, input pack and decision record aligned to management system practice.
ISO/IEC 27001 Alignment Layer
Mapping view and Statement of Applicability structure.
Prototype Protection Readiness
Readiness structure for organisations with a prototype protection scope.
Data Protection Readiness
Readiness structure where a data protection scope applies.
ISA2027 Transition Support
Change-impact worksheet and transition planning structure.
Multi-Site Governance
Scope map, site ownership model and consolidated oversight.
CAPA Tracker
Corrective and preventive actions with root cause and verification.
KPI / KRI Dashboard
Measurement structure for security performance and risk indicators.
Third-Party Portfolio
Portfolio register with criticality tiering and review cycle.
Training Matrix
Role-based competence and awareness tracking.
Executive Reporting
Board-level readiness summary with trend view.
What is not included
Stated plainly, because finding out after purchase is a bad experience.
Everything in the comparison matrix is included in this tier.
- Consulting, implementation services, or a managed programme
- Software licensing — the materials are working documents you own and adapt
- Any guarantee of an assessment result, label or certification
Questions about this tier
Do we need Professional as well?
How many sites does this realistically handle?
Is this a software platform?
Can we discuss a multi-site rollout first?
Not sure this is the right tier?
The free self-assessment ends with a recommendation based on your readiness indicator and organisation profile — including the reasoning, so you can disagree with it.