IT, OT & IoT Compliance

A clear path to compliance, built around your business.

Compliance obligations are growing. NIS2, DORA, ISO 27001, Cyber Essentials. The hard part is not knowing which regulations apply. The hard part is turning that knowledge into a governed programme that holds up under scrutiny, across IT, OT, and IoT, month after month.

Cybersecurity Compliance Toolkit Org Profiles RACI Controls Risks Assets MFA Policies +10 more CSF OUTCOMEPRIORITYSTATUSEVIDENCETARGET GV.OC-01HighImplementedPolicy v2.1Tier 3 GV.OC-02HighPartialBoard minsTier 3 GV.RM-01CriticalImplementedFrameworkTier 4 GV.SC-01MediumPlanned.Tier 3 ID.AM-01CriticalImplementedAsset registerTier 4 ID.AM-02ID.RA-01 3.4/ 5.0MATURITY 17MODULES NIS2DORAISONISTIEC
The problem

Most compliance programmes fall apart between audits.

The initial effort is not usually the issue. Organisations invest time and money getting ready for an audit or certification. The gap analysis gets done, the policies get written, the evidence gets assembled.

Then the audit passes, and the programme starts to drift. The risk register stops being updated. New systems get deployed without being assessed. By the time the next audit comes around, the gap between where you think you are and where you actually are has widened.

Reports gather dust

Gap analyses and maturity assessments get filed after the audit. Nobody maintains the findings or tracks actions to closure.

Annual catch-up cycle

Compliance becomes a scramble before each audit rather than a continuously maintained position.

OT and IoT left out of scope

Most providers assess IT and call it done. Industrial controls, building management, and connected devices remain blind spots.

No visibility for the board

Leadership knows compliance matters but cannot see progress, gaps, or what needs attention without a translation exercise.

Multiple frameworks, separate exercises

NIS2, DORA, ISO 27001, GDPR each handled independently. Duplicate effort, inconsistent evidence, gaps between them.

New systems deployed unassessed

Cloud migrations, new SaaS tools, and infrastructure changes happen without being brought into the compliance programme.

Edge7 Networks works across all three environments. IT, OT, and IoT. We work with SMEs and enterprise organisations across manufacturing, energy, utilities, water, healthcare, critical infrastructure, financial services, and the public sector. With the technical depth to bring every environment properly into scope, not just tick a box for each.

The toolkit

Built around your business. Not a template.

Every Cybersecurity Compliance Toolkit is purpose-built for your organisation. Your single source of truth for all cybersecurity compliance and audit activity. Here is a sample of what it may contain.

Each toolkit is unique. Modules, fields, and structure are shaped to your business.

Cybersecurity Compliance Toolkit . [Your Organisation] . 2025
17
Modules
6+
Frameworks
IT+OT+IoT
All environments
Bespoke
Built for your org
The toolkit

A working system, not a one-off report.

The most common failure in compliance is not the initial assessment. It is what happens afterwards. The Cybersecurity Compliance Toolkit is designed to prevent that.

Runs month after month

Actions tracked and assigned. Progress visible. Reviews on schedule. A new version each year gives you a clean audit trail and clear year-on-year improvement.

Structured for your environment

Separate views for each business unit, site, or environment. IT and OT tracked independently. Per-environment policies, controls, asset registers, and gap analyses.

Everything in one place

NIS2, DORA, GDPR, ISO 27001, NIST CSF 2.0, Cyber Essentials. One integrated workbook. No separate exercises, no duplicate data entry.

Your board can read it

Maturity dashboards and action summaries give leadership a clear view of where you stand and what is moving. No translation exercise needed.

How it starts

Start with clarity, not commitment.

Every engagement begins with a structured maturity and gap analysis. A clear, evidence-based view of your current compliance position against the frameworks that matter to you.

01

On-site technical review

Firewalls, network infrastructure, endpoints, OT systems, and physical security. Assessed against the frameworks that apply to your sector.

02

Stakeholder interviews

Governance gaps that technical scans miss. How decisions get made, where accountability sits, what processes exist on paper versus in practice.

03

Maturity report and roadmap

A prioritised action plan you can act on immediately. Scored against the relevant frameworks, with clear next steps and effort estimates.

The report is yours. Act on it with Edge7 Networks, take it to another provider, or use it to guide your internal team. There is no obligation to go further.

Start with an assessment
Frameworks

Regulations set the destination. We help you build the road.

Compliance is not a single event. It is a journey from your current position to the level of governance your regulators, auditors, and board expect.

NIS2 EU Directive

Risk management, incident readiness, remediation processes, and supply chain due diligence. We build the governance programme that satisfies those obligations across your full environment.

DORA Financial Services

ICT risk management and resilience readiness for financial services. We structure the programme and evidence it.

ISO 27001 Certification

From gap analysis through to certification readiness. The same structured approach applies to ISO 9001, Cyber Essentials, and Cyber Essentials Plus.

GDPR Data Protection

Data governance, breach readiness, and processor due diligence. Maintained as a live function, not an annual review.

IEC 62443 / NIST SP 800-82 OT

OT cybersecurity brought into scope properly. Controls designed for operational environments, not adapted from IT frameworks.

NIST CSF 2.0 Framework

Control mapping and maturity assessment using the most widely adopted cybersecurity framework globally.

For many organisations, the journey involves more than one of these. A compliance programme built around NIS2 might draw on ISO 27001 for its management system, NIST CSF 2.0 for control mapping, and IEC 62443 for OT environments. We navigate that without running separate exercises for each.
Engagement model

Every organisation starts somewhere different.

01

You need a baseline

Start with the maturity assessment and gap analysis. Understand your current position and walk away with a prioritised roadmap.

Entry point
02

You need a structured programme

Phased delivery towards certification or compliance milestones. The Toolkit is built, governance cadence established, progress tracked.

Programme build
03

You need ongoing management

Sustained compliance across IT, OT, and IoT. Regular reporting, board-level visibility, a programme that stays current between audits.

Continuous
04

You need senior leadership

A dedicated vCISO embedded in your organisation, managing compliance as a strategic function at board level.

LeadershipSee vCISO
Why Edge7 Networks

What makes this different from a compliance consultancy.

Three things set this apart from hiring a traditional compliance provider.

IT, OT, and IoT in scope

Most providers assess IT and call it done. We bring operational technology, industrial control systems, and connected devices into scope with the technical depth those environments require. From SMEs to enterprise, across manufacturing, energy, healthcare, financial services, and critical infrastructure.

A working platform, not a project deliverable

The Cybersecurity Compliance Toolkit runs your programme month after month: Master Action List, RACI Matrix, Trend History, board dashboards. You leave with a live system, not a binder.

Trust first, not dependency

Every engagement begins with a structured gap analysis. The report is yours, whether you continue with Edge7 Networks or not. No lock-in. No minimum spend.

ISO 27001:2022
ISO 27001:2022
Information security management
ISO 9001:2015
ISO 9001:2015
Quality management
Cyber Essentials
Cyber Essentials
UK government-backed certification

We have been through it ourselves. Edge7 Networks is certified to ISO 27001:2022, ISO 9001:2015, and Cyber Essentials.

The Cybersecurity Compliance Toolkit was built through real engagements and our own certification processes. We know what auditors look for, what evidence holds up, and where programmes get stuck.

Frequently asked questions

Common questions about NIS2, DORA, ISO 27001, OT security, and Cyber Essentials.

NIS2 (Network and Information Security Directive 2) is an EU cybersecurity regulation that significantly expands on the original NIS Directive. It applies to a much broader set of organisations, including those in energy, transport, healthcare, financial services, digital infrastructure, and manufacturing, and imposes strict requirements for cybersecurity risk management, incident reporting, and supply chain security. NIS2 came into force in October 2024 and requires covered organisations to demonstrate active, documented cybersecurity governance.

DORA (Digital Operational Resilience Act) is an EU regulation applying to financial services organisations. Banks, insurance companies, investment firms, and their ICT third-party service providers. DORA requires robust ICT risk management frameworks, regular resilience testing, supply chain risk management, and major incident reporting. DORA has applied in full since January 2025.

ISO 27001 is an international standard for Information Security Management Systems (ISMS). It provides a systematic framework for managing information security risks and. When certified. Demonstrates that an organisation has implemented controls to protect the confidentiality, integrity, and availability of its information assets. The current version is ISO 27001:2022. Edge7 Networks is certified to ISO 27001:2022.

OT (Operational Technology) cybersecurity addresses the security of industrial control systems, SCADA systems, PLCs, and other technology that controls physical processes. In manufacturing, utilities, energy, and transport. OT security differs from IT security because OT systems often cannot tolerate patching or downtime and were designed without security in mind. As OT environments connect to IT networks, they create new attack surfaces that require specialist security and compliance approaches. Edge7 Networks addresses IT, OT, and IoT environments under a unified compliance framework.

Cyber Essentials is a UK government-backed cybersecurity certification scheme that helps organisations demonstrate they have fundamental technical controls in place to protect against common cyber threats. It covers five controls: firewalls and internet gateways, secure configuration, user access control, malware protection, and patch management. Edge7 Networks holds Cyber Essentials certification and can support organisations through their own certification process.

Ready to see where you stand?

A maturity assessment is the most accessible first step. A clear view of your current position, a prioritised roadmap, and a report that is yours to act on.

Assess first

Start with a maturity assessment and gap analysis. Understand where you are today and walk away with a prioritised roadmap.

Build a programme

Move into phased delivery towards certification or compliance milestones. The Toolkit is built, governance established, progress tracked.

Ongoing management

Sustained compliance across IT, OT, and IoT. Regular reporting, board-level visibility, and a programme that stays current between audits.

Let's start with a conversation