Cyber Essentials Compliance, Made Simple
Policy Monitor helps organisations achieve and maintain Cyber Essentials and Cyber Essentials Plus by creating a compliance programme that runs in the background, keeping your organisation certification-ready all year round.
Built for SMEs
Integrated Vulnerability Scanning
Assessment & Certification Support
No Dedicated Compliance Team Required

The Problem
Cyber Essentials Is Simple.
Staying On Top Of It Isn't.
Cyber Essentials provides a practical framework for improving cyber security.
The challenge isn't understanding the requirements.
The challenge is remembering what needs to happen, who's responsible, whether it's been completed, and where the evidence is when assessment time arrives.
Activities Get Missed
Policy reviews, security checks and training can easily slip.
Evidence Lives Everywhere
Documents, screenshots and records become scattered across systems.
Renewal Becomes a Project
Each year starts with another scramble to gather information.
The Policy Monitor Approach
Compliance That Keeps Moving
Cyber Essentials
Compliance Checks
Activities
Assigned tasks
Evidence
Assessment Ready
Policy Monitor automatically creates a compliance programme based on Cyber Essentials requirements.
Activities are scheduled.
Tasks are assigned to the right people.
Evidence is collected automatically.
Progress is tracked.
Your compliance programme runs itself in the background.
At assessment time, you have all the information you need, all in one place.
Why Organisations Choose Policy Monitor
Know What Needs to Happen
Framework requirements become practical tasks.
Know What's Done
Track completion and maintain an audit trail.
Know Who Owns It
Responsibilities are assigned automatically.
Know You're Ready
Prepare for assessments with evidence already organised and linked to each control.
Know Your Risks
Areas of non-compliance are flagged.
Get Certified
Submit your CE Assessment for certification directly from the platform.
How It Works
Automated Cyber Compliance Plans
We provide customisable policies mapped to Industry Standards, Automated Centralised Compliance Tracking, Easy to Follow Workflows and Integrated Cyber Security Tooling so you feel empowered with your own Cyber Security.

Automated Compliance Tracking
Monitor compliance across different control areas for your chosen policies, standards and frameworks.

Mapped to Industry Standards & Frameworks
Compliance plans are aligned to industry standards with mappings across different frameworks and standards.

Integrated Cyber Security Tools
Enhance your security posture with integrated vulnerability scanning and backup as a service.

Security Awareness and Compliance Training
Keep staff up to date on security best practices, course content aligned to industry standards, automatic training delivery and monitoring.


Automated Workflows
Step-by-step instructions on what you need to do to achieve compliance, scheduled automatically, and assigned to the right people.

Streamlined Assessments & Audits
Integrated assessment portal for industry standards and frameworks, compliance evidence automatically linked to controls, simple submission and exporting processes.
Our Solution
Automated Compliance Tracking
Monitor compliance across different control areas for your chosen policies, standards and frameworks.
Track Everything in One Place
Gain a unified view of your compliance and security posture. Our pre-built Compliance Checks track your alignment with your policy, standard or framework and help you identify areas of risk and non-compliance.


Mapped to Industry Standards
Compliance Checks are pre-mapped to controls from industry standards and frameworks. You just choose which standards you're interested in, and your compliance plan is generated automatically.
Tailored to Your Business
You can customise your compliance plan by selecting and removing Compliance Checks from our library, allowing you to track the controls that matter to your organisation.


View an Audit Trail of All Your Compliance Activities
Compliance Checks are linked to an audit trail of relevant activities, so you can track who did what, and when. This evidence is all linked to the mapped standard and framework controls, so you can easily access it at audit time.
Our Solution
Pre-built Workflows
Step-by-step instructions on what you need to do to achieve compliance, scheduled automatically, and assigned to the right people.
Build Your Compliance Plan in Minutes
Just select which standards or frameworks you want to align with and assign people to the key roles, and your customisable compliance plan will be automatically generated and initiated.


Compliance Activities Scheduled for You
A schedule of compliance activities will be created, creating a roadmap to your fully compliant state. You can move activities around in the schedule to better fit in around your business and timeframes.
Tasks Automatically Assigned to the Right People
Tasks will automatically be sent out to the right people and teams based on their roles. Shared to-do lists allow teams to share and manage compliance activities between them.


Easily Track and Manage Progress
Access a full audit trail of your organisation's compliance activities, and easily send reminders and reassign outstanding tasks.
Clear Task Descriptions and Guidance
Our task descriptions break down what you need to do to achieve compliance in clear and easy to follow language. Task descriptions include guidance on how to apply specific controls to different types of systems and where to find further information.

Our Solution
Streamlined Audits & Assessments
Integrated assessment portal for industry standards and frameworks, compliance evidence automatically linked to controls, simple submission and exporting processes.
Integrated Assessment Portal
A dedicated assessment portal for specific industry standards and frameworks allow your team to easily collaborate in one place.


Framework Controls Linked to Compliance Activities
Each control from a standard or framework is linked to relevant compliance activities so you can see the status, an audit trail and the relevant evidence for your assessment.
Stay up to Date with Evolving Frameworks and Standards
We regularly update the assessment portal with the most up to date versions of frameworks, including mappings to compliance checks, so you can stay up to date while minimising the work you need to do.


Avoid Duplicating Work
Mappings are maintained between compliance checks and controls from different frameworks, and different versions of those frameworks. Evidence only needs to be provided once, and it will be linked to all relevant controls.
Our Solution
Integrated Vulnerability Scanning
Identify and remediate vulnerabilities quickly and consistently, keep your organisation secure, be protected from malware and cyber attacks.
Get Daily Reporting on your Vulnerabilities
Get regular reporting on the vulnerabilities across assets in your organisation. Easily identify non-compliant and high risk devices.


Access Patches and Remediation Guides
See a breakdown of vulnerabilities on each device, along with patches and remediation instructions. Access on-demand scans to test remediation efforts have been successful.
Powered by Qualys
With Policy Monitor and Qualys' Vulnerability Scanning add-on, your organisation can take advantage of the industry standard for risk based vulnerability scanning.
With daily on demand scans, you can access full vulnerability reports, remediation instructions and patches - accurately measuring risk reduction over time.
Our Solution
Integrated Backup as a Service
Protection from ransomware, data loss and system failure, automated secure and encrypted backups, quick and simple system recovery.
Ensure Your Critical Systems are Always Backed Up
Know that your most important data and systems are being regularly and automatically backed up. You can easily configure what is backed up and when, and see the status of all your backups.


Keep Your Data Secure and Encrypted
Your backups are secure and encrypted, keeping your data safe.
Powered by Infrascale
Policy Monitor has partnered with Infrascale to deliver Microsoft 365 backup that you can actually rely on when things go wrong.
With our backup, your data is protected and always available on your time. Infrascale provides automated data and critical systems backup; mitigating the risk of data loss from human error, data corruption, malware/ransomware, and gaps in retention policy.

Our Solution
Security Awareness & Compliance Training
Keep staff up to date on security best practices, course content aligned to industry standards, automatic training delivery and monitoring.
Automate Your Training Deilvery
Save time and money on security awareness and compliance training using our built in training modules. Choose a schedule for your training program and the platform will handle enrolment, reminders, training records, and everything else.


Keep Your People up to Date with evolving Best Practices
Training modules are regularly updated and aligned with industry best practices to ensure your people have the knowledge they need to stay secure.
Easy to Follow Content
A mixture of text, videos and quizzes ensure our content is engaging, efficient, easy to follow, and that the key information has actually been absorbed.

Pricing
1
Policy Monitor Platform
from £10 per month
Access to the full Policy Monitor Platform including automated compliance tracking, framework specific content, self-assessments and security awareness training.
£10 per month per administrator account.
£1 per month per standard account.
2
Vulnerability Scanning Add-On
from £5 per month
Regular automated vulnerability scans (up to once a day), access to on-demand scans, full vulnerability reports, remediation instructions and patches.
£5 per month + £0.15 per device per month for scans every 2 days.
£10 per month + £0.25 per device per month for daily scans and on demand scans. More here.
3
Automated Backup & Recovery Add-On
from £5 per month
Regular automated backups of your critical systems and data, encrypted storage, automated recovery process.
Pay for the amount of storage you need: £50 per terabyte per month.
Who we are

Based in London, Policy Monitor is a cyber security company founded by experts with extensive experience in operational and risk management.
Policy Monitor is a policy management system that incorporates global cyber security standards to guide organisations through complex industry-certified accreditation assessments.

IASME


