Hamilton Group · Free Tool

Compliance Framework Chooser

Cyber Essentials, IASME, ISO 27001, SOC 2, DSPT, PCI DSS — most businesses need one or two of them, not all six. Answer a few questions and see which actually apply to you, in what order, and roughly what they cost.

where to start
0
effectively required
indicative first step
Answer the questions below.

About your business

Sector and data
NHS or health dataYou process patient data or connect to NHS systems
MoD supply chainYou hold or bid for defence contracts
US clientsYou sell to American companies
EU operations or customersAn EU entity, or you offer services into the EU
Essential or digital servicesUtilities, transport, health, digital infrastructure, cloud or search
Regulated financial servicesFCA regulated, or an EU financial entity
Large volumes of personal dataConsumer records, special category or children's data
You supply other businesses' IT or dataYou are in someone else's supply chain
What you already hold
Cyber Essentials
Cyber Essentials Plus
IASME Cyber Assurance
ISO 27001
NHS Data Security and Protection Toolkit
SOC 2

Your route

Frameworks build on each other. Doing them in the wrong order means paying twice for the same evidence.

Every framework, and whether it applies to you

Certification is the paperwork. The controls are the work.

Hamilton Group gets businesses through Cyber Essentials and Cyber Essentials Plus, and builds the technical controls that ISO 27001 and client questionnaires ask for. Book a free readiness review.

Guidance, not a compliance assessment. Costs are indicative UK ranges covering certification and typical support for a business of your size — they exclude VAT and any remediation work needed to pass, which is often the larger cost. Whether a framework is contractually or legally required depends on your specific contracts, regulator and data. Check the tender or contract wording before relying on this.