This is for you if

  • You need a compliance pack for Cyber Essentials, ISO 27001, SOC 2, the DSP Toolkit or a customer's security questionnaire
  • You've bought template packs before and drowned in documents that still needed rewriting
  • You want to know what 'good' looks like before you spend another penny or another weekend on it

Most compliance packs fail not because a document is missing, but because nobody knew what the full set should be or where the evidence for each control was supposed to live. You find out during the audit, when an assessor asks for a register you've never created. Knowing the whole shape up front is the cheapest insurance there is.

A compliance pack is not a pile of documents. It is a set of controls, each with a policy that states your intent, a procedure or SOP that says how it is done, and evidence that proves it is actually happening. Off-the-shelf template packs hand you the documents and leave you to work out the rest. This is the map: what a complete pack contains, what each part is for, and where the evidence lives.

Use it two ways. If you are starting from nothing, it is the shopping list. If you already have a pack, run down it and mark what you are missing: most businesses find the gaps are not policies at all, they are the registers and evidence nobody thought to create.

1. Governance and the top-level policy set

The documents that set the tone and satisfy the first questions any assessor or customer asks.

  • Information Security PolicyPolicy

    Your overarching statement of intent.

    Evidence: Signed and dated by leadership, reviewed at least annually.

  • Acceptable Use PolicyPolicy

    What staff can and can't do with company systems and data.

    Evidence: Staff acknowledgement records.

  • Roles and responsibilitiesStandard

    Who owns security, who owns each control.

    Evidence: A named owner against every policy, not “IT”.

  • Risk registerRegister

    Your identified risks, their likelihood, impact and treatment.

    Evidence: Dated entries with review notes, not a one-off snapshot.

2. Access and identity

  • Access Control Policy, plus a joiner, mover and leaver procedureProcedure

    Who gets access, and how it changes and ends.

    Evidence: A leavers register showing access was revoked, with dates.

  • Multi-factor authentication standardStandard

    Where MFA is enforced and how.

    Evidence: A configuration export, not a claim.

  • Privileged access procedureProcedure

    How admin rights are granted, reviewed and removed.

    Evidence: An admin account review log.

3. Devices and endpoints

  • Device and endpoint management policy, and an enrolment SOPProcedure

    How devices are enrolled and kept compliant.

    Evidence: An asset register mapped to enrolled, compliant devices.

  • Patch management procedureProcedure

    Cadence, ownership, exceptions.

    Evidence: Patch compliance reporting over time.

  • Encryption and remote-wipe standardStandard

    What is encrypted, and how a lost device is wiped.

    Evidence: Proof encryption is enforced, and a wipe has been tested.

4. Data protection

  • Data protection and privacy policy, and a retention schedulePolicy

    What you hold, why, and for how long.

    Evidence: A data map or Record of Processing Activities.

  • Backup policy and a restore procedureProcedure

    What is backed up, and how it comes back.

    Evidence: A successful test-restore record, the single most-requested and least-produced artefact.

  • Data classification and handling standardStandard

    How sensitive data is marked and treated.

    Evidence: Sensitivity labels or equivalent applied in practice.

5. Operations and resilience

  • Incident response planPlan

    Defined roles and contacts.

    Evidence: A tabletop exercise or a real incident write-up.

  • Business continuity and disaster recovery planPlan

    How the business keeps going, and recovers.

    Evidence: An RTO and RPO statement, and the date it was last tested.

  • Change management procedureProcedure

    How changes are approved and recorded.

    Evidence: A change log.

  • Supplier and third-party security procedureProcedure

    How suppliers' security is checked.

    Evidence: A supplier register with their security status recorded.

6. People and the human layer

  • Security awareness training procedureProcedure

    How staff are trained, and how often.

    Evidence: Completion records and phishing-test results.

  • Onboarding and offboarding SOPs that include security stepsProcedure

    Security steps for every starter and leaver.

    Evidence: Checklists completed per starter and leaver.

The pattern to notice

Read back through the list and the same shape repeats: a policy (intent), a procedure or SOP (method), and evidence (proof). Template packs are strong on the first, thin on the second, and silent on the third, which is precisely the order an assessor cares about in reverse. They want the evidence first, the procedure to explain it, and the policy to authorise it.

That is why "we bought a template pack" and "we are audit-ready" are rarely the same sentence. The documents are the easy part. The procedures written around your real systems, and the evidence that they are actually followed, are what decides whether you pass.

Where this leaves you

  • The gaps are registers and evidence, not policies

    The usual finding. Start the registers with dated entries, and test a restore and record it: the single most-requested and least-produced artefact.

  • Documents bought, procedures never written around your systems

    Template packs are strong on intent and thin on method. Write the procedures around your real systems, so the evidence has something to prove.

  • Policy, procedure and evidence line up for every control

    You are in a strong position for an auditor, insurer or prospect. Keep the registers current and review the policy set at least annually.

  • Starting from nothing

    Use the kit as the shopping list. Systech holds Cyber Essentials and ISO 27001 and helps clients prepare; for Cyber Essentials, the certification body assesses and issues the certificate.

If this list showed you gaps, that is the point: better to find them here than in an audit. The slow way to close them is to write every document by hand and manually assemble the evidence. The fast way is to generate the policies, procedures and SOPs around your actual systems and framework, then run an internal audit that tells you exactly which evidence you are missing and who owns it. That is what Systech's Compliance Packs and Audit Readiness service does with EtherAssist, so the pack fits from day one and stays current, and our security team closes the technical gaps the self-audit surfaces.

More from the set

This is one of a set. The rest, covering AI readiness, security, cost, compliance and device management in the same format, are listed on all our free checklists and assessments.