Four frameworks. Probably not four of your problems.
Each page below answers the same four questions in the same order: does this apply to you, what does it require, what does Fortoxa produce toward it, and what stays your job. Start with the last column here — if a framework is not yours, the most useful thing this site can do is tell you so.
Which one is actually yours?
Keyed on your situation rather than on what each framework contains.
Cyber Essentials
Yours if: A UK customer, insurer or buying framework has asked for it, or you are bidding for central government work involving personal information or certain ICT services.
GDPR Article 32
Yours if: You process personal data — which in practice means you employ people or have customers. There is no company-size threshold in Article 32.
NIS2 Directive
Yours if: You operate in an Annex I or Annex II sector AND have 50+ employees, or turnover and balance sheet both above €10 million. Supplying an in-scope entity does not by itself put you in scope.
NCSC CAF
Yours if: You are an operator of essential services under the UK NIS Regulations 2018, or a government body assessed under GovAssure. Most businesses are not.
One command, then it builds itself.
The same five steps whichever framework you picked. Only the mapping in step three differs between them.
Install the agent on one server
A single command. The agent reads system and authentication logs and ships events to your workspace. Nothing else on the host changes.
Events become artifacts
Raw events are turned into the records an assessor can read — blocked connections, account changes, configuration and patch state — each keeping the system it came from and the time it was collected.
Artifacts map to your framework
Each artifact is placed against the requirements of the framework you picked. Requirements with nothing behind them stay visible and marked as not measured.
The register tracks what changed
Collection is continuous, so a requirement that was evidenced last month and is stale today reads as stale rather than as satisfied.
Export what your assessor asked for
Take the register as a PDF or the underlying records as CSV. Each line traces back to a timestamped source, so you can answer “how do you know” without going back to the logs yourself.
Fortoxa produces evidence. It does not reach conclusions.
Certification, assessment and enforcement are done by certification bodies, competent authorities and supervisory authorities. Nothing Fortoxa outputs is a certificate, an assessment, or a statement that you comply.
It does not certify you
Cyber Essentials is awarded by an IASME-licensed certification body. The CAF is assessed by your competent authority. Fortoxa produces the evidence you hand them.
It only knows what it can see
The agent runs on the servers you install it on. Laptops, phones, SaaS accounts and physical controls show as not measured, never as a pass.
Some requirements are not technical
Governance, training records, supplier contracts and restore tests are not server telemetry. The register references them and tracks whether they exist; it does not invent them.
The control register starts at £349 a month.
Business is the plan that produces the control register and the evidence export, at £349 for twenty seats. Micro at £29 and Starter at £99 cover monitoring, alerts and the live activity feed — neither includes the register.