Most compliance guidance is written for organisations with a dedicated security function. This guide is for everyone else — business owners, operations managers, and practice administrators who need to get their organisation compliant without technical expertise or internal IT support.
Most small businesses reach for a consultant before they understand their own situation — and pay for advice that is either too generic or too complex to act on. A self-assessment first tells you what you actually have, which makes any expert engagement far more targeted.
Your posture score across the control domains that matter (access control, data protection, business continuity), your specific gaps ranked by severity, and a starting list of actions.
Technical knowledge, IT qualifications, or knowing the difference between a firewall and a router. Well-designed assessments ask about outcomes, not configurations.
The assessment result is your roadmap input. It tells you where to start — which is almost always better than starting from a blank compliance checklist.
What they look for
If a client, insurer, or regulator asks how you manage compliance, the answer should be: 'We conducted an assessment on [date] which showed [score] and identified these priorities.' Without a baseline assessment, you are describing instincts rather than evidence. A scored assessment gives you a starting point you can reference and a benchmark to measure progress against.
Cyber Essentials, GDPR, ISO 27001 — compliance frameworks can feel overwhelming, especially without technical support. The practical answer is to focus on the foundational controls that underpin all of them, and let certification follow naturally.
Enable MFA on every cloud account: Microsoft 365, Google Workspace, your banking portal, any admin system. This single control blocks the majority of account compromise attacks.
Enable automatic updates on all devices. Remove software that is no longer supported by the vendor. This directly addresses one of the most exploited entry points.
Every person should log in with their own account. Shared passwords and shared admin accounts should be removed. When someone leaves, their access should be removed the same day.
Ensure critical data is backed up, and that the backup is not connected to the same system (so ransomware cannot encrypt it too). Test that you can restore from it.
What they look for
These four controls — MFA, patching, access management, and backups — are checked by cyber insurance underwriters, CE+ assessors, and ISO 27001 auditors. You don't need to know the frameworks to implement them. Start here, document that they are in place, and you will satisfy the majority of questions from clients, insurers, and certification bodies.
The compliance tooling market is full of platforms designed for GRC teams and enterprise security departments. For a business without a dedicated IT function, these are the wrong tools. Look for tools that tell you what to do, not just where to put documents.
A good tool interprets your assessment results and tells you what to do next — in plain English, in priority order.
Findings, actions, evidence, and reporting in one place. Not a spreadsheet for gaps and a separate folder for evidence.
Policies, vendor questionnaires, and incident report templates that you adapt rather than write from scratch.
What they look for
When a client or insurer asks 'how do you manage your compliance programme', being able to show a structured portal with findings, actions, and evidence attached is more credible than a folder of spreadsheets. Tools that tell you what to do — rather than just where to file things — are the right choice for non-technical users.
Not having an IT team does not mean doing everything yourself. Some tasks are well-suited to external help — others require internal ownership because they involve judgement about your business.
Risk prioritisation, deciding what data you hold and why, approving policies, managing the roadmap timeline. These require someone who understands the business context.
Technical configuration (firewall rules, MFA setup, patch management), penetration testing, and formal certification body audits.
Monitoring, patching, endpoint management, and responding to technical incidents. If you use an MSP, ask them to formally attest your Cyber Essentials controls in writing.
What they look for
If you use an MSP, ask them to provide a written statement of which CE+ controls they manage and maintain on your behalf. This document becomes your evidence. Without it, you cannot claim those controls as implemented — and your MSP cannot be held accountable if a control lapses.
The most common reason small businesses fail compliance reviews is not that they lack controls — it is that they cannot prove the controls exist. Documentation needs to be a habit, not a project.
A password policy, acceptable use policy, and data retention policy do not need to be long. A one-page document that is reviewed annually and signed off by the owner is more valuable than a 30-page document that no one reads.
Screenshot your MFA settings. Export your user access list. Attach your backup test result. These take two minutes when done as you go and hours when done retrospectively.
Keep a simple log of who completed what training and when. A spreadsheet or a training platform export is enough — the point is that you can show regulators or insurers that training happened.
What they look for
Documentation created at the time is more credible than documentation created retrospectively. A screenshot taken the day you enabled MFA has a timestamp. A policy document reviewed and signed annually has a version history. Evidence assembled the week before an audit is questioned by anyone who looks at the file dates.
A quarterly review does not need to be an all-day event. Thirty minutes looking at your open actions, checking that nothing significant has changed, and updating your evidence takes less time than responding to an incident that could have been prevented.
Open actions from your roadmap, any staff changes that affect access rights, new tools or services introduced that handle personal data, and any incidents or near-misses.
The business owner or MD should be involved at least annually. A quarterly review can be led by whoever manages IT or operations — but findings need to be visible at senior level.
Annually as a minimum. Also after a significant change: a new cloud platform, a data breach, a major staff restructure, or a new customer contract with compliance requirements.
What they look for
A quarterly review record — even a two-page document — demonstrates that your programme is active and not a one-time exercise. Insurers, clients doing due diligence, and certification bodies all look for evidence that security is an ongoing activity. A single assessment with no subsequent reviews suggests the programme stopped.
Where people go wrong
Delegating compliance entirely to an MSP without maintaining oversight
Your MSP manages IT. Compliance — deciding what data you hold, what risks are acceptable, what policies exist — is your responsibility as the data controller. An MSP cannot sign off your GDPR ROPA or your ISO 27001 Statement of Applicability.
Documenting policies but not verifying controls are actually in place
A password policy that says you require MFA has no value if MFA is not actually enabled. Policies describe intent; evidence demonstrates implementation. You need both.
Not updating records when people join or leave
Access rights and training records become inaccurate every time your team changes. A leaver's account staying active is both a security risk and a CE+ failure point. Access management needs to be a process triggered by HR, not a quarterly review.
Starting with frameworks rather than controls
Starting with 'we need to achieve Cyber Essentials' is more daunting than starting with 'let's enable MFA everywhere this week'. Start with the controls — CE+ and GDPR compliance follows naturally from having the controls in place.
Our IT is managed by an MSP — does that mean we are compliant?
Not automatically. An MSP manages your IT infrastructure, but GDPR compliance, business continuity planning, vendor risk management, and staff training remain your responsibility. Ask your MSP to confirm in writing which CE+ controls they manage and maintain on your behalf.
How much time does compliance management actually take?
For a small business starting from scratch, expect 2–3 days to complete a baseline assessment, review findings, and build a roadmap. After that, the maintenance overhead is roughly 2–4 hours per month — tracking actions, capturing evidence, and handling any incidents.
What is the minimum we need to do to satisfy customer or contract requirements?
Most SME contract requirements bottom out at Cyber Essentials certification and a GDPR compliance statement. Cyber Essentials costs around £300–500 for the self-assessment certification and proves you have the foundational controls in place. Add a short data protection policy and a GDPR data register and you cover most requirements.
We had an IT person who left — how do we know what is in place?
Start with an audit of accounts and access: who has admin rights, what cloud services are active, what email addresses still work. Then run a baseline assessment to understand the security posture of what you inherited. The assessment results will tell you what is in place and what the priority gaps are.
Fortify guides you through assessments, tells you what to fix in plain English, and tracks your progress — so you do not need to know the frameworks to be compliant with them.