LAGAN CYBER
§ 01 — Framework coverage · v0.3 · updated 5 August 2026

What we map, how we count it, and what is not written yet.

Most compliance platforms show a grid of framework logos. This page shows the mapping data behind those logos — including the two frameworks where the mapping does not exist at all.

Control library coverage as at 5 August 2026 — our build state, not certification
Framework Controls mapped Evidence automated Cloud checks Status
ISO 27001:2022 ISO/IEC 27001:2022 · Annex A CTRL 93/93 · EVID 24 · CHK 31 93 / 93 24 31 Mapped
Cyber Essentials / Plus NCSC scheme · five technical controls CTRL 5/5 · EVID 18 · CHK 26 5 / 5 18 26 Mapped
NCSC CAF v4 4 objectives · 14 principles · 39 outcomes CTRL 21/39 · EVID 9 · CHK 14 21 / 39 9 14 In development
NIS2 Directive (EU) 2022/2555 · Art. 21(2)(a)–(j) CTRL 6/10 · EVID 4 · CHK 7 6 / 10 4 7 In development
DORA Regulation (EU) 2022/2554 · ICT risk CTRL — · EVID — · CHK — Planned
NIST CSF 2.0 6 functions · 106 subcategories CTRL — · EVID — · CHK — Planned

Mapping counts are our own control library, not certification. Lagan Cyber does not hold ISO 27001 or Cyber Essentials certification and does not issue certificates.

§ 02 — Counting method

What each column means.

Coverage numbers are easy to inflate. These are the definitions we hold ourselves to, published so that you can argue with them.

Controls mapped

Written mapping exists, reviewed by a person

The numerator counts controls, outcomes or requirements in the published framework for which we hold a written mapping entry: the control identifier, our interpretation of what would satisfy it for a cloud-first SME, and the domain in our platform that produces the answer. The denominator is the count published by the framework’s own author.

A mapping entry is not automation. A control can be mapped and still require you to write a document or take a decision. Mapped means we know what the control asks for and where the answer comes from; it does not mean the platform produces the answer by itself.

Evidence automated

Controls where a record is produced without a human

The subset of mapped controls where a scheduled scan writes a complete evidence record with no manual step. This is always a much smaller number than “controls mapped”, and any platform telling you otherwise is counting something else. Governance controls — risk ownership, management review, policy approval — cannot be automated by reading a cloud tenant, and we do not pretend they can.

Cloud checks

Distinct configuration assertions we run

The number of individual configuration assertions relevant to that framework across Microsoft 365, Entra ID and Google Workspace. One check may support several controls in several frameworks, so these numbers deliberately do not add up across rows.

Status

Three states, no fourth

  • Mapped — the control library is complete for that framework and the associated checks run in our internal build.
  • In development — the mapping is partially written. The figures show how far it has got, not where it is going.
  • Planned — scoped and on the roadmap. No mapping entries exist. The figures are dashes because zero would imply we had started.
§ 03 — ISO/IEC 27001:2022

ISO 27001:2022 — Annex A, 93 of 93 mapped

The 2022 revision restructured Annex A into four themes and 93 controls. All 93 have a mapping entry. Twenty-four produce an automated evidence record; the rest need a document, a decision or a person.

Annex A themes — mapping and automation state
Theme Controls Mapped Automated evidence Where the answer comes from
A.5 Organisational 37 37 6 Mostly CD-03 Policies and CD-04 Supplier risk. Governance controls stay manual.
A.6 People 8 8 2 CD-05 People. Screening and terms of employment remain your HR records.
A.7 Physical 14 14 0 Not automatable from a cloud tenant. Mapped to guidance and an attestation record.
A.8 Technological 34 34 16 CD-01 Cloud posture. The bulk of the automation sits here.

Certification against ISO/IEC 27001 is issued by an accredited certification body following a two-stage audit. Nothing produced by this platform is a certificate, a pre-assessment or a statement of conformity. Lagan Cyber is not certified to ISO/IEC 27001, and neither is the company behind it.

§ 04 — Cyber Essentials

Cyber Essentials and Cyber Essentials Plus — 5 of 5 mapped

The scheme has five technical control themes. All five are mapped, and this is the framework where cloud posture scanning does the most useful work, because four of the five are configuration questions.

Cyber Essentials technical controls — coverage from cloud posture scanning
Control theme Checks What we can evidence What we cannot
Firewalls 3 Cloud network boundary settings where they exist in the tenant. Physical boundary firewalls and home-router configuration.
Secure configuration 9 Tenant baselines, default sharing, legacy protocol state, guest access. Endpoint build standards on unmanaged devices.
Security update management 4 Update policy configuration and compliance reporting where surfaced by the tenant. Devices not enrolled in a managed estate.
User access control 8 MFA enforcement, admin count, standing privilege, dormant accounts, conditional access. Access to systems outside the connected tenants.
Malware protection 2 Tenant-level protection policy state. Per-device engine and signature state without a management connector.

Cyber Essentials and Cyber Essentials Plus are UK government schemes delivered by IASME on behalf of the NCSC. Certification is awarded by a licensed Certification Body against a self-assessment questionnaire and, for Plus, a technical audit. Lagan Cyber is not a Certification Body, is not licensed by IASME, and is not itself Cyber Essentials certified. Passing every check in our platform does not award, imply or guarantee certification.

§ 05 — NCSC CAF

NCSC Cyber Assessment Framework v4 — 21 of 39 outcomes

CAF is written as outcomes with indicators of good practice rather than as a control checklist, which makes it a poor fit for naive automation and a good fit for evidence gathering. Objectives A and B are mapped; C and D are in progress.

CAF objectives — mapping progress
Objective Principles Outcomes mapped State
A — Managing security risk 4 10 / 10 Mapped
B — Protecting against cyber attack 6 11 / 14 In development
C — Detecting cyber security events 2 0 / 6 In development
D — Minimising the impact of incidents 2 0 / 9 Planned

The Cyber Assessment Framework is published by the National Cyber Security Centre. Our mapping is an independent interpretation and carries no endorsement from, or affiliation with, the NCSC. CAF assessments for regulated sectors are carried out by the relevant competent authority, not by us.

§ 06 — NIS2

NIS2 — 6 of 10 Article 21(2) measures

Relevant to Irish essential and important entities, and increasingly to their UK suppliers, who are asked to demonstrate the same measures contractually. Article 21(2) lists ten minimum measures at points (a) to (j).

Article 21(2) minimum measures — mapping state
Ref Measure State
21(2)(a)Risk analysis and information system security policiesMapped
21(2)(b)Incident handlingPlanned
21(2)(c)Business continuity, backup and crisis managementPlanned
21(2)(d)Supply chain securityIn development
21(2)(e)Security in acquisition, development and maintenanceMapped
21(2)(f)Policies to assess effectiveness of risk-management measuresMapped
21(2)(g)Basic cyber hygiene practices and security trainingIn development
21(2)(h)Cryptography and encryption policiesMapped
21(2)(i)Human resources security, access control and asset managementMapped
21(2)(j)Multi-factor authentication and secured communicationsMapped

NIS2 is transposed into national law by each Member State, and Ireland’s implementing legislation governs how these measures apply to an Irish entity. Our mapping is to the Directive text and is not legal advice. You should take advice on whether your organisation is in scope and as what type of entity.

§ 07 — DORA

DORA — planned, nothing written

The Digital Operational Resilience Act applies to Irish financial entities and to ICT third-party service providers serving them. We have scoped it and written nothing. This row is a dash rather than a zero because zero would imply the work had begun.

DORA pillars — scoping notes only
Pillar Our assessment
ICT risk managementSubstantially overlaps our existing ISO 27001 and NIS2 mapping; expected to be the cheapest pillar to add.
ICT incident reportingRequires incident classification and regulator-facing reporting we have not built.
Digital operational resilience testingRequires testing programmes, including threat-led penetration testing for some entities. Out of scope for the product.
ICT third-party riskDepends on CD-04 Supplier risk, which is itself unbuilt. Register of information requirements are demanding.
Information sharingNot a product feature.

We will not put a date on DORA coverage. It follows CD-04 Supplier risk, and CD-04 has not been written.

§ 08 — NIST CSF 2.0

NIST CSF 2.0 — planned, nothing written

CSF 2.0 turns up in enterprise procurement questionnaires far more often than in UK or Irish regulation, which is why it is on the list at all. Six functions, 106 subcategories, none mapped.

CSF 2.0 functions — mapping state
Function Subcategories Mapped
GV — Govern310
ID — Identify210
PR — Protect220
DE — Detect110
RS — Respond130
RC — Recover80

The NIST Cybersecurity Framework is published by the US National Institute of Standards and Technology. NIST does not endorse products and we claim no relationship with it.

§ 09 — Ask us

Framework you need that is not on this list?

We would rather hear which framework your customers actually ask you about than guess. Tell us the framework, the sector and who is asking for it, and it goes into the roadmap discussion with your name against it.

Framework requests — hello@lagancyber.co.uk · we reply within two working days

We do not maintain a mailing list and will not add you to one. Your email is used to answer you and nothing else — see the privacy notice.