Help Centre workspace

Compliance

Operate framework-specific workspaces for ISO 27001, SOC 2 readiness, Cyber Essentials and Cyber Essentials Plus, NIST CSF 2.0 and CIS Controls v8.1 while reusing shared PurpleWASP Controls and assurance records.

Start with the workflow

From framework scope to demonstrable readiness and improvement

Choose the framework, establish its scope/profile/engagement, make the framework-specific decisions it requires, connect shared Controls and assurance, then use readiness, gap or continual-improvement views to drive the next action.

1
Select

Choose ISO 27001, SOC 2, Cyber Essentials/Plus, NIST CSF 2.0 or CIS Controls v8.1.

2
Scope

Define the management-system, engagement, assessment or Organizational Profile boundary.

3
Decide

Record framework-specific applicability, criteria, questionnaire or Current/Target decisions.

4
Assure

Reuse organisation Controls and connect implementation, evidence, assessments, testing, issues and exceptions.

5
Improve

Use drivers, readiness, gaps, remediation and improvement actions to focus the next work.

CIS Controls v8.1

Implement the selected Implementation Group through shared Controls

Confirm scope and accountability, work through targeted Safeguards, resolve Control coverage, reuse assurance and prioritise improvements without duplicating organisation-Control state.

NIST CSF 2.0

Use Organizational Profiles to manage cybersecurity outcomes

Assess the complete CSF 2.0 Core, compare Current and Target Profiles, reuse shared Control assurance and turn gaps into an improvement plan.

Cyber Essentials

Prepare for Cyber Essentials and Cyber Essentials Plus

Work from scope and questionnaire through technical-area readiness, remediation and the Plus technical-assurance workflow.

SOC 2 readiness

Prepare for SOC 2 without overstating the assurance outcome

Use PurpleWASP for management-side SOC 2 readiness, Control coverage, evidence, testing, remediation and audit preparation.

ISO 27001

Operate the ISMS and continual-improvement cycle

Maintain Clauses 4–10, the Statement of Applicability, recurring assurance and operational registers in one connected ISMS workspace.

Cross-framework operation

Reuse Controls and understand framework-specific readiness

Use shared organisation Controls across frameworks while keeping each framework's applicability, assessment and readiness model distinct.

Important operating rules

Framework status and external assurance conclusions have different owners

PurpleWASP structures and connects the organisation records needed for compliance, readiness and improvement. External certification or independent attestation decisions remain with the appropriate external assurance provider where the framework uses one.

  • SOC 2: PurpleWASP supports readiness management and audit preparation; it does not issue the service auditor opinion.
  • Cyber Essentials/Plus: internal readiness and technical-assurance records do not replace the Certification Body/Assessor decision.
  • NIST CSF 2.0: Current/Target percentages are PurpleWASP visualisations, not NIST certification, conformance or maturity scores.
  • CIS Controls v8.1: Assessment Coverage, Implementation Progress and PurpleWASP Readiness are internal implementation indicators, not official CIS certification or CAS results.
  • ISO 27001: dashboard percentages and internal assurance records are not themselves certification decisions.
  • Use Control Management as the authoritative organisation-Control implementation and assurance layer shared across frameworks.