Home / Blog
Notes
Notes for UK security buyers.
Cyber Essentials, NCSC CAF, UK GDPR, PCI DSS — written as a tester, not a brochure.
Cyber Essentials
Cyber Essentials is not a pentest. Here is what UK buyers still get wrong.
Cyber Essentials and CE+ are a UK baseline. A penetration test is an attacker simulation. How they differ, when you need both, and what enterprise customers are actually asking for.
→ NCSC CAFWhat NCSC CAF evidence a penetration test can (and cannot) produce
The NCSC Cyber Assessment Framework is an outcome model. A pentest is one source of evidence. Here is an honest mapping for UK boards and CISOs.
→ UK GDPRUK GDPR and the ICO: when a pentest is the right technical measure
Article 32 does not say ‘buy a pentest’. Here is when independent testing is the measure a UK controller can defend to the ICO or to a customer.
→ PCI DSSPCI DSS v4 for UK e-commerce: the pentest you actually need
Requirement 11.4 still wants a pentest. For UK shops on Stripe, Adyen or Worldpay the scope question is the whole engagement. Here is how we draw it.
→