Regulation
UK cyber-security regulation, from the inside
Firebed's founder worked in UK government cyber-security regulation, with the NIS Regulations, the NCSC Cyber Assessment Framework and the policy that became the Cyber Security and Resilience Bill. We know what an assessor is looking for because we have been the assessor. This page explains the frameworks that matter in 2026 and what we do about each.
The NIS Regulations 2018 and the Cyber Security and Resilience Bill
The Network and Information Systems Regulations 2018 place security and incident-reporting duties on operators of essential services in energy, transport, health, drinking water and digital infrastructure, and on relevant digital service providers. Each sector has a competent authority, and the NCSC Cyber Assessment Framework is the instrument most of them assess against.
The Cyber Security and Resilience Bill amends and substantially expands that regime. It brings managed service providers, data centres and designated critical suppliers into scope, tightens incident reporting, introduces a two-tier penalty regime and strengthens regulators' powers. It cleared the House of Commons in June 2026 and is before the House of Lords as this page is written; substantive obligations are expected to follow through secondary legislation. Organisations that will fall into scope for the first time have a window now to build the evidence base the regime will ask for.
What Firebed does
- Scope determination: whether and how the Regulations or the Bill reach your organisation, and as which kind of entity
- A CAF-based gap analysis with the missing evidence named, outcome by outcome
- Incident-reporting readiness: the detection, triage and notification path exercised before it is needed
- Supplier and managed-service-provider due diligence framed the way a competent authority will frame it
The NCSC Cyber Assessment Framework and GovAssure
The Cyber Assessment Framework organises cyber resilience into four objectives: managing security risk, protecting against attack, detecting security events and minimising the impact of incidents. Each objective breaks into principles and contributing outcomes, assessed as achieved, partially achieved or not achieved against indicators of good practice. GovAssure applies the same framework to central government departments and arm's-length bodies through independent assurance reviews, and the CAF-aligned Data Security and Protection Toolkit applies it to the health and care sector with a fifth objective on using and sharing information appropriately.
Firebed has applied the CAF-aligned DSPT to a real codebase, all 49 outcomes, mapping each to the code that enforces it, the test that proves it and the document that records it. The map is kept current in the same change as the code, and a gate checks the edition of the framework it was built against. That gate earned its keep: the 2026-27 edition of the DSPT replaced every one of the previously mandated outcomes with a new set of eleven, and the stamp is what caught the change.
What Firebed does
- CAF self-assessment support and independent pre-assessment, with evidence rather than assertion at every outcome
- GovAssure preparation for departments and arm's-length bodies
- DSPT submissions for NHS bodies and their suppliers, mapped to the current edition
- Engineering the evidence: turning an outcome into a control with a call site, a test and a document
NIS2 and DORA, for organisations serving the EU
UK organisations that provide services in the European Union, or supply entities that do, meet the NIS2 Directive and, in financial services, the Digital Operational Resilience Act. The obligations overlap heavily with the CAF's outcomes, and a single evidence base can serve both if it is designed to. We map once and report in each regime's vocabulary.
Cyber Essentials, ISO/IEC 27001 and the Software Security Code of Practice
Cyber Essentials and Cyber Essentials Plus set the baseline that public-sector contracts increasingly require. ISO/IEC 27001 provides the management-system frame that larger clients ask for. The Software Security Code of Practice, published by the Department for Science, Innovation and Technology with the NCSC in 2025, sets fourteen principles for organisations that develop or sell software, from secure design to communicating with customers about vulnerabilities and end of life. ExPriori maps to each principle, and the same map is available for your product.
UK GDPR, the DPIA and health-specific standards
Data protection is a security requirement, not a legal afterthought: the UK GDPR's Article 32 asks for security appropriate to the risk, and a data protection impact assessment is where the risk is written down. In health, DCB0129 and DCB0160 set the clinical safety standards for manufacturers and deployers of health IT, and the Digital Technology Assessment Criteria is the NHS's entry test for digital products. Firebed produced a data inventory, a flow map, a draft DPIA, a DCB0129 safety case and a DTAC assessment for ExPriori and can produce them for you.
Why it works
Compliance as engineering, not paperwork
The difference between a compliance map that survives an assessment and one that does not is whether it is attached to the code. Ours are.
- Map the framework to controlsEvery outcome or requirement is written against the control that satisfies it, with the framework edition recorded.
- Attach each control to its evidenceThe enforcing line of code, the test that fails if it is removed, and the document that records the decision.
- Gate the map in continuous integrationA change to a control that does not update its row fails the build. A framework edition that has moved fails the build.
- Score from evidence, and say where there is noneAchieved, partially achieved, not achieved, and not established where nobody has measured. Assessors trust the last category more than a wall of green.