Case Study 05 · Compliance & Procurement

The enterprise contract stalled.
Security was the question nobody had prepared for.

When the firm pivoted from research and development to consultancy, three compliance workstreams landed simultaneously: an internal Cyber Essentials Plus audit, CE+ readiness advisory work for three new clients, and procurement bid responses across frameworks with combined contract values exceeding £1 million. This case study covers how two years of prior governance work became the foundation that made all three possible, and what compliance integrity looks like when commercial pressure makes it inconvenient.

~30 Devices inventoried
3 Client engagements
6 Frameworks contributed to
1st Attempt CE+ audit pass

A Pivot, a New Role, and Three Simultaneous Compliance Demands

In late 2024 the firm pivoted away from its commercial product strategy. The data engineers moved into client-facing consultancy work. The commercial product was sunset. The role that had been embedded security R&D work became a compliance and procurement role, working under the security controller alongside the wider cybersecurity consultancy team.

Three concurrent workstreams landed simultaneously: the firm's own Cyber Essentials Plus certification, CE+ readiness advisory work for three new consultancy clients, and procurement bid responses across multiple public sector frameworks. Each had its own stakeholders, evidence requirements, and commercial deadline.

What made this phase manageable was not the pivot itself. It was what had been built before it.

The shift-left security programme had produced a documented, validated control environment across the firm's Azure Databricks production environment. That environment remained in scope for the internal CE+ audit, and because the controls had already been documented in Jira and Confluence and validated before the pivot, the security controller had an evidence base ready rather than one he needed to reconstruct.

The client advisory work drew on the same foundation in a different way. Having designed and validated CE+ controls from scratch for the firm's own environment meant the gap analysis conversations with clients were not theoretical. The questions an auditor would ask, the evidence they would require, the gaps that typically surfaced: these were things that had already been worked through in practice, not read from a framework.

And for the procurement bids, the technical capability and security posture sections required claims that could be substantiated. Because the documentation already existed, the bidding team was not starting from scratch. That saved time and, more critically, meant the claims were grounded in real evidence rather than aspirational ones.

The through-line across all three workstreams was the same: ensure that what was being claimed could be substantiated. That principle had been the foundation of the previous two years of work. In this phase, it was tested under commercial pressure.

💡
Why this phase mattered. Compliance work in a small organisation under commercial pressure is where judgement matters most. There are no second-line assurance functions, no internal audit, and no formal escalation pathways. The integrity of the output depends on the people doing the work being willing to raise difficult issues at the right time.

What Made This Phase Difficult

Three structural complications shaped this phase. Each one created the conditions for things to go wrong if compliance work was treated as a tick-box exercise rather than a substantive activity.

⏱️
Concurrent deadlines, finite resources. The internal audit, client engagements, and procurement submissions all had to progress simultaneously against external deadlines. The organisation had no dedicated IT support function. Evidence gathering, scoping, and bid drafting all sat with a small team operating across multiple deliverables at once.
💷
Commercial pressure on bid responses. Procurement deadlines are immovable. Contract values were significant, exceeding £1 million across the framework portfolio. The temptation in any small organisation under financial pressure is to push submissions through rather than slow them down for compliance verification.
🔍
Single line of defence. No internal audit function existed. No independent second-line review. As the only Business Analyst in the organisation, identifying gaps, raising issues, and driving improvement had always been part of the role. In this phase that responsibility carried more weight. The stakes were commercial, the deadlines were external, and the pressure to move quickly rather than carefully was real.

The Shape of the Response

The role operated across all three workstreams under the security controller's direction. Each required a different mode of working: operational evidence gathering for the internal audit, advisory engagement for clients, and bid contribution for procurement. The through-line across all three was the same: ensure that what was being claimed could be substantiated.

Of the three, the procurement work required the steepest learning curve. Public sector bid writing is a specialist discipline. Larger organisations have dedicated teams who understand the format, the evaluation criteria, and the register that buyers expect. Working without that infrastructure meant developing that judgement independently, under deadline, while running two other workstreams simultaneously.

That context is relevant to the MCF4 story in section 07. The judgement call made there was not made from a position of comfort. It was made under the kind of commercial pressure that tests whether compliance integrity holds when it is inconvenient.

🏛️
Workstream 01
Internal CE+ Audit
Evidence gathering across 15 employees and ~30 devices for the firm's first CE+ certification.
🤝
Workstream 02
Client Advisory
CE+ readiness scoping, CAF baseline, gap mapping, and roadmap development for three first-time clients.
📋
Workstream 03
Procurement Bids
Security posture and technical capability sections across six public sector frameworks, including CCS and defence supplier portals.

The Firm's First Cyber Essentials Plus Audit

Workstream 01 · Internal Audit Support

Evidence gathering across 15 employees and approximately 30 devices, validated through a single Teams channel

The security controller owned the audit preparation. The evidence gathering across all in-scope assets was owned separately. The asset inventory sat on SharePoint and was maintained continuously as evidence was collected and validated against CE+ technical requirements.

Communication ran through a single dedicated Teams channel for the audit. Cadence started weekly and tightened to daily in the week before the audit date. Each employee was contacted to verify operating system version, browser currency, multi-factor authentication enforcement, firewall configuration, and user permission level. Outliers were escalated to the security controller for scoping decisions.

15
Employees coordinated for evidence verification
~30
In-scope devices across laptops, MacBooks, and tablets
1st
Attempt audit pass
⚠️
The pre-audit incident. Thirty minutes before the external assessment, an employee returning from leave reviewed the Teams channel and recognised that her own laptop setup did not match what was being asked of the wider team. She still held local administrator rights on her MacBook from when her user profile had originally been created. The issue was escalated immediately to the security controller, who escalated to a senior stakeholder with system administration access. Her account was reassigned, a temporary password shared, and she was walked through setting up a new standard user profile. Permissions were verified as correct and the audit proceeded as planned.
📋
Honest framing. The overprivileged account was not surfaced by direct evidence gathering. It was surfaced because the employee read the Teams channel messages and recognised the gap herself. That is a process working — communication clear enough that a user could see and report her own non-compliance — but the credit is for resolving it under time pressure, not for identifying it.

Cyber Essentials Plus Readiness for Three First-Time Clients

Workstream 02 · External Engagements

Scoping, baselining, gap mapping, and roadmap development for first-time certification clients

Three clients were engaged for CE+ readiness during this phase, each preparing for first-time certification. The remit covered the front end of each engagement: scoping discussions to define what would and would not sit inside the assessment boundary, current-state baselining using the NCSC Cyber Assessment Framework, gap mapping against CE+ technical requirements, and remediation roadmap development.

Implementation and audit support sat with the security controller and the other cybersecurity consultant. On an ad hoc basis, the firm was represented in ongoing client check-ins when the security controller was unavailable — typically to address patching status, scheduling around employees on parental or sick leave, or other operational queries that came up between scheduled sessions.

01
Scoping discussion
Define assessment boundary and document exclusions with justification.
02
NCSC CAF baseline
Structured security baseline across CAF objectives and principles.
03
Gap mapping to CE+
Gaps identified across five CE+ control areas: firewalls, secure config, access control, malware protection, patch management.
04
Remediation roadmap
Sequenced plan with cost and timeline estimates enabling an informed certification decision.
🎯
Why the CAF as the baseline. The Cyber Assessment Framework is a richer instrument than CE+ alone — it gives a fuller picture of organisational security posture without requiring the certification overhead. Using CAF as the diagnostic stage and CE+ as the target state gave clients a clearer view of where their broader security posture stood, not just where they fell short of one specific certification.

Crown Commercial Service and Defence Supplier Bid Contributions

Workstream 03 · Bid Drafting & Evidence

Drafting security posture and technical capability sections across six frameworks

Across this phase contributions were made to procurement responses for six public sector frameworks, including the Crown Commercial Service framework portfolio and a defence supplier portal. Combined contract values across the portfolio exceeded £1 million. The contribution was section-level: drafting the security posture evidence and technical capability narrative under the direction of the bid lead and the security controller.

This was structured, deadline-driven, evidence-based work. Each framework had its own question set, evaluation criteria, and supporting evidence requirements.

Each section required a clear-eyed assessment of what the organisation could legitimately claim. The security posture and technical capability sections of a public sector bid are not places for aspiration. They are places for evidence. Getting that right under deadline, without a formal review process, required the same discipline that had shaped the compliance work from the start.

6
Public sector frameworks contributed to
£1M+
Combined contract value across the portfolio
2
Section types owned: security posture, technical capability
📌
The judgement layer. Procurement bid drafting in a small organisation under commercial pressure is where compliance integrity is tested. The pressure to claim more than can be substantiated is real. On at least one framework submission during this phase, that pressure surfaced directly and required a difficult escalation upward. That story is covered in the next section.

The MCF4 Submission: A Judgement Call on Misrepresentation

One framework — MCF4, with a contract value of approximately £500,000 — was assigned as lead end to end. It was scoped as a standard selection questionnaire and was expected to be straightforward. The way it unfolded turned out to be the most consequential piece of judgement work of this entire phase.

How a routine questionnaire became a test of organisational integrity

The MCF4 framework was assigned as lead, with a colleague working alongside as a supporting contributor and a senior stakeholder set up as the escalation point but otherwise hands-off. Initial scoping suggested the questionnaire was standard — broadly the same questions filled in across other bids — and the colleague's early review estimated approximately two weeks of effort. The active work was scheduled to start three weeks before the submission deadline.

When drafting began in earnest, two mandatory requirements surfaced that had not appeared in the initial review: ISO 9001 certification with the ability to demonstrate compliance after contract award, and a published Carbon Reduction Plan linked from the organisation's website. The firm held neither.

The Carbon Reduction Plan was feasible inside the timeline. A template-based document, supported by data from the office landlord on energy use and from a senior stakeholder on forward-looking reduction commitments, could realistically have been drafted, signed off, and published within three weeks.

The ISO 9001 requirement was a different matter. Even with an external consultant engaged immediately, certification typically requires several months. Three weeks was not enough.

The issue was escalated to a senior stakeholder, who escalated further within the organisation. The directive returned was to state that the organisation held ISO 9001 compliance and engage a consultant in parallel — on the basis that Crown Commercial Service responses often take months to come back and that certification might be in place by then.

The decision sat with the submission lead. A risk-benefit assessment concluded that the reputational and contractual exposure of a misrepresented submission to a public sector body outweighed the upside of the contract, especially given the realistic probability that the response window would not align with the certification timeline.

The other framework opportunities in the active pipeline were reviewed. Several alternatives offered comparable revenue with materially more feasible compliance requirements. An alternative analysis was prepared and the position was taken back upward.

The conversation that followed involved senior stakeholders with decision-making authority. It was professional but not comfortable. After deliberation, the organisation took the decision not to submit the MCF4 response and to redirect resourcing toward the alternative frameworks. The risk-based judgement held.

~£500K
Contract value at stake on MCF4
2
Mandatory gaps identified ahead of deadline
0
Misrepresented claims made to public sector body

The reputational exposure of misrepresentation to a public sector body outweighed the value of the contract. Redirecting to alternatives the organisation could substantiate was the only defensible position.

What I Would Do Differently at Scale

This phase combined operational evidence work, advisory delivery, and bid drafting under commercial pressure with limited internal assurance infrastructure. The work held up because the team was small enough to escalate clearly and judgement was applied at the right moments. The following is an honest assessment of what would change in a more mature setting.

How I operated under the circumstances
1
Treated compliance integrity as non-negotiable even when commercial pressure created reasons to compromise it.
2
Escalated the MCF4 misrepresentation risk upward rather than processing the directive without challenge.
3
Built the alternative case on commercial merits, not just compliance feasibility, to land a difficult conversation.
4
Maintained a Teams channel transparent enough that an employee could self-identify her own non-compliance thirty minutes before an audit.
5
Used the NCSC CAF as a richer diagnostic baseline rather than mapping clients straight to CE+ requirements.
What I would do differently at scale
1
Build an independent second-line review so bid responses are verified by someone outside the drafting team.
2
Treat framework prerequisite scoping as a standalone workstream to surface mandatory requirements before drafting begins.
3
Establish a written policy on unsubstantiated claims in public sector submissions, removing the need for case-by-case escalation.
4
Use an asset management tool with automated discovery rather than employee self-attestation through Teams.

Standards and Tooling

Standards, frameworks & tooling
NCSC Cyber Assessment Framework Cyber Essentials Plus CCS framework requirements ISO 9001 (assessed) SharePoint Microsoft Teams Azure Active Directory Microsoft 365