Libraries
Flexible assessments for every assurance requirement
Erebus Assure brings a wide range of cyber security, resilience, compliance and specialist assessment frameworks together in one flexible platform.
From established standards such as ISO 27001, NIST, NCSC CAF and Cyber Essentials through to Operational Technology, supply chain, cloud, AI and bespoke customer requirements, assessments can be configured to reflect the areas most relevant to each organisation.
Use the library below to explore the available assessment types, the standards and guidance they are based on, and the core areas each assessment can cover.
| Category | Erebus Assure Assessment | Basis / Reference | Core Coverage / Configurable Sections |
|---|---|---|---|
| Information Security | ISO 27001 Readiness Assessment | ISO/IEC 27001:2022 |
|
| Information Security | Cyber Essentials Readiness Assessment | NCSC Cyber Essentials |
|
| Information Security | NCSC CAF Assessment | NCSC Cyber Assessment Framework |
|
| Information Security | NIST Cybersecurity Framework Assessment | NIST CSF 2.0 |
|
| Information Security | CIS Controls Assessment | CIS Controls |
|
| Defence | DEFSTAN 05-138 Readiness Assessment | DEF STAN 05-138 |
|
| Operational Technology | OT / ICS Cyber Security Assessment | IEC 62443 / NCSC CAF / NIS good practice |
|
| Supply Chain | Supplier Security Assessment | ISO 27001 / NIST / NCSC / IEC 62443 / industry good practice |
|
| Physical & Protective Security | Physical & Protective Security Assessment | ISO 27001 / NPSA good practice |
|
| Protective Security | Martyn’s Law Readiness Assessment | Terrorism (Protection of Premises) Act / supporting guidance |
|
| Privacy | Data Protection & UK GDPR Assessment | UK GDPR / DPA 2018 / ICO guidance |
|
| Resilience | Business Resilience Assessment | ISO 22301 / NCSC / industry good practice |
|
| Cloud & Technology | Cloud Security Assessment | ISO 27017 / CIS / NCSC / provider good practice |
|
| AI | AI Governance & Security Assessment | ISO/IEC 42001 / NIST AI RMF / industry good practice |
|
| Software Security | Secure Development Assessment | OWASP / NIST / secure development good practice |
|
| General Assurance | Cyber Security Maturity Assessment | Erebus Assure methodology / ISO / NIST / NCSC / CIS |
|
| Bespoke | Customer-Specific Assurance Assessment | Customer policies, contracts, standards or requirements |
|
ISO 27001 Readiness Assessment
Basis / ReferenceISO/IEC 27001:2022
Core Coverage- ISMS governance
- Organisational context
- Leadership
- Risk management
- Policies
- Asset management
- Access control
- People security
- Physical security
- Operational security
- Supplier security
- Incident management
- Business continuity
- Compliance
- Continual improvement
Cyber Essentials Readiness Assessment
Basis / ReferenceNCSC Cyber Essentials
Core Coverage- Firewalls
- Secure configuration
- Security update management
- User access control
- Malware protection
- CE / CE+ readiness
NCSC CAF Assessment
Basis / ReferenceNCSC Cyber Assessment Framework
Core Coverage- Managing security risk
- Protecting against cyber attack
- Detecting cyber security events
- Minimising the impact of incidents
- Individual CAF objectives/principles selected as required
NIST Cybersecurity Framework Assessment
Basis / ReferenceNIST CSF 2.0
Core Coverage- Govern
- Identify
- Protect
- Detect
- Respond
- Recover
CIS Controls Assessment
Basis / ReferenceCIS Controls
Core Coverage- Organisational controls
- Technical controls
- Asset management
- Access management
- Vulnerability management
- Security monitoring
- Incident response
- Relevant Implementation Groups
DEFSTAN 05-138 Readiness Assessment
Basis / ReferenceDEF STAN 05-138
Core Coverage- High-level readiness against applicable requirements
- Applicable sections selected according to requirement
- RAG status only
- No detailed sensitive or classified evidence captured due to classification implications
OT / ICS Cyber Security Assessment
Basis / ReferenceIEC 62443 / NCSC CAF / NIS good practice
Core Coverage- Governance
- Asset management
- Architecture
- Zones & conduits
- Access control
- Remote access
- Vulnerability management
- Patch management
- Secure configuration
- Monitoring
- Incident response
- Backup & recovery
- Supplier access
- Lifecycle management
Supplier Security Assessment
Basis / ReferenceISO 27001 / NIST / NCSC / IEC 62443 / industry good practice
Core Coverage- Security governance
- Cyber controls
- Data protection
- Access control
- Hosting & cloud
- Incident management
- Business resilience
- Subcontractors
- Personnel security
- Supply-chain dependencies
- OT / ICS security
- OT remote access
- OT asset interaction & dependencies
- OT vulnerability & patch management
- OT network / system access
- OT incident notification & response
- Light-touch, standard or critical-supplier options
Physical & Protective Security Assessment
Basis / ReferenceISO 27001 / NPSA good practice
Core Coverage- Site perimeter
- Physical access control
- Visitors & contractors
- CCTV
- Intruder detection
- Keys & access credentials
- Secure areas
- Comms/server rooms
- Environmental threats
- Security monitoring
- Personnel arrangements
Martyn’s Law Readiness Assessment
Basis / ReferenceTerrorism (Protection of Premises) Act / supporting guidance
Core Coverage- Premises applicability
- Governance
- Terrorism risk
- Protective procedures
- Evacuation
- Invacuation / lockdown
- Communications
- Staff awareness
- Training
- Preparedness
Data Protection & UK GDPR Assessment
Basis / ReferenceUK GDPR / DPA 2018 / ICO guidance
Core Coverage- Governance
- Lawful processing
- Privacy information
- Data subject rights
- DPIAs
- Records management
- Retention
- Data sharing
- Processors
- Breach management
- Information security
Business Resilience Assessment
Basis / ReferenceISO 22301 / NCSC / industry good practice
Core Coverage- Business continuity
- Business impact analysis
- Disaster recovery
- Backup & recovery
- Cyber incident response
- Crisis management
- Exercises & testing
- Critical dependencies
- Recovery arrangements
Cloud Security Assessment
Basis / ReferenceISO 27017 / CIS / NCSC / provider good practice
Core Coverage- Cloud governance
- Identity management
- Privileged access
- Secure configuration
- Logging & monitoring
- Encryption
- Network security
- Vulnerability management
- Backup
- Resilience
- M365, Azure and AWS-specific sections where required
AI Governance & Security Assessment
Basis / ReferenceISO/IEC 42001 / NIST AI RMF / industry good practice
Core Coverage- AI governance
- Approved AI use
- AI risk assessment
- Data protection
- AI security
- Third-party AI
- Generative AI
- Human oversight
- Transparency
- Monitoring
- Shadow AI
Secure Development Assessment
Basis / ReferenceOWASP / NIST / secure development good practice
Core Coverage- SDLC governance
- Secure design
- Secure coding
- Code repositories
- Software dependencies
- CI/CD
- Security testing
- Vulnerability management
- Secrets management
- Open-source software
- Software supply chain
Cyber Security Maturity Assessment
Basis / ReferenceErebus Assure methodology / ISO / NIST / NCSC / CIS
Core Coverage- Governance
- People
- Technology
- Data
- Identity & access
- Vulnerability management
- Monitoring
- Incident management
- Resilience
- Supplier security
Customer-Specific Assurance Assessment
Basis / ReferenceCustomer policies, contracts, standards or requirements
Core Coverage- Customer-defined requirements
- Customer policies
- Contractual requirements
- Bespoke control areas
- Configurable questions
- Configurable scoring
- Configurable maturity criteria
- Relevant Erebus library sections can be reused
Why It Matters
Cyber security is not a one-time exercise—it’s an ongoing process of assessment, improvement and resilience.
Our platform transforms assessment data into practical, actionable insights, enabling organisations to make informed decisions, prioritise investment and strengthen their Operational Technology environments with confidence.
Ready to understand your cyber resilience?
Start your Operational Technology Cyber Assessment today and receive practical recommendations tailored to your organisation.
Get in touch
Contact
Connect

Copyright © 2026 Erebus Assure. All Rights Reserved.
2026