LAGAN CYBER
§ 01 — Framework coverage · v0.3 · figures as at 5 August 2026

What we map, and how we count it.

Most compliance platforms show a grid of framework logos. This page shows the mapping data behind the logos, framework by framework, including the point at which each mapping stops.

Control library coverage as at 5 August 2026 — our own control library, not certification
Framework Controls mapped Evidence automated Cloud checks Coverage
ISO 27001:2022 Annex A CTRL 93/93 · EVID 24 · CHK 31 93 / 93 24 31 Mapped
Cyber Essentials / Plus NCSC scheme · five technical controls CTRL 5/5 · EVID 18 · CHK 26 5 / 5 18 26 Mapped
NCSC CAF v4 4 objectives · 14 principles · 39 outcomes CTRL 21/39 · EVID 9 · CHK 14 21 / 39 9 14 Partial
NIS2 Directive (EU) 2022/2555 · Art. 21(2)(a)–(j) CTRL 6/10 · EVID 4 · CHK 7 6 / 10 4 7 Partial

Mapping counts are our own control library, not certification. Framework names and control identifiers are the property of their respective publishers and are used here descriptively.

§ 02 — Counting method

What each column means.

Coverage numbers are easy to inflate. These are the definitions we hold ourselves to, published so that you can argue with them.

Controls mapped

Written mapping exists, reviewed by a person

The numerator counts controls, outcomes or requirements in the published framework for which the library carries a written mapping entry: the control identifier, our reading of what would satisfy it for a cloud-first SME, and the domain that produces the answer. The denominator is the count published by the framework’s own author.

A mapping entry is not automation. A control can be mapped and still require you to write a document or take a decision. Mapped means we know what the control asks for and where the answer comes from; it does not mean the platform produces the answer by itself.

Evidence automated

Controls where a record is produced without a human

The subset of mapped controls where a scheduled scan writes a complete evidence record with no manual step. This is always a much smaller number than “controls mapped”, and any platform telling you otherwise is counting something else. Governance controls — risk ownership, management review, policy approval — cannot be automated by reading a cloud tenant, and we do not pretend they can.

Cloud checks

Distinct configuration assertions we run

The number of individual configuration assertions relevant to that framework across Microsoft 365, Entra ID and Google Workspace. One check may support several controls in several frameworks, so these numbers deliberately do not add up across rows.

Coverage

Two states, and the count is the claim

  • Mapped — every control the framework publishes carries a library entry, and the checks that support it run.
  • Partial — the controls counted are mapped and the rest are not. The figure is the whole claim, and it is a count rather than a percentage for that reason.
  • Not mapped — used at control level inside a framework, where a specific outcome or measure has no library entry behind it yet.
§ 03 — ISO/IEC 27001:2022

Annex A — 93 of 93 mapped

The 2022 revision restructured Annex A into four themes and 93 controls. All 93 have an entry in our own control library. Twenty-four produce an automated evidence record; the rest need a document, a decision or a person.

Annex A themes — mapping and automation state
Theme Controls Mapped Automated evidence Where the answer comes from
A.5 Organisational 37 37 6 Mostly CD-03 Policies and CD-04 Supplier risk. Governance controls stay manual.
A.6 People 8 8 2 CD-05 People. Screening and terms of employment remain your HR records.
A.7 Physical 14 14 0 Not automatable from a cloud tenant. Mapped to guidance and an attestation record.
A.8 Technological 34 34 16 CD-01 Cloud posture. The bulk of the automation sits here.

Certification against ISO/IEC 27001 is issued by an accredited certification body following a two-stage audit. Nothing produced by this platform is a certificate, a pre-assessment or a statement of conformity.

§ 04 — Cyber Essentials

Cyber Essentials and Plus — 5 of 5 mapped

The scheme has five technical control themes, all five mapped in our own control library, and this is the framework where cloud posture scanning does the most useful work, because four of the five are configuration questions.

Cyber Essentials technical controls — coverage from cloud posture scanning, not certification
Control theme Checks What we can evidence What we cannot
Firewalls 3 Cloud network boundary settings where they exist in the tenant. Physical boundary firewalls and home-router configuration.
Secure configuration 9 Tenant baselines, default sharing, legacy protocol state, guest access. Endpoint build standards on unmanaged devices.
Security update management 4 Update policy configuration and compliance reporting where surfaced by the tenant. Devices not enrolled in a managed estate.
User access control 8 MFA enforcement, admin count, standing privilege, dormant accounts, conditional access. Access to systems outside the connected tenants.
Malware protection 2 Tenant-level protection policy state. Per-device engine and signature state without a management connector.

Cyber Essentials and Cyber Essentials Plus are UK government schemes delivered by IASME on behalf of the NCSC. Lagan Cyber is not a Certification Body and is not licensed by IASME. Certification is awarded by a licensed Certification Body against a self-assessment questionnaire and, for Plus, a technical audit, and passing every check in our platform does not award, imply or guarantee certification.

§ 05 — NCSC CAF

NCSC Cyber Assessment Framework v4 — 21 of 39 outcomes

CAF is written as outcomes with indicators of good practice rather than as a control checklist, which makes it a poor fit for naive automation and a good fit for evidence gathering. Objective A is mapped in full and B in the greater part, and the counts below say the rest.

CAF objectives — outcomes mapped in the control library
Objective Principles Outcomes mapped Coverage
A — Managing security risk 4 10 / 10 Mapped
B — Protecting against cyber attack 6 11 / 14 Partial
C — Detecting cyber security events 2 0 / 6 Not mapped
D — Minimising the impact of incidents 2 0 / 9 Not mapped

The Cyber Assessment Framework is published by the National Cyber Security Centre. Our mapping is an independent interpretation and carries no endorsement from, or affiliation with, the NCSC. CAF assessments for regulated sectors are carried out by the relevant competent authority, not by us.

§ 06 — NIS2

NIS2 — 6 of 10 Article 21(2) measures

Relevant to Irish essential and important entities, and increasingly to their UK suppliers, who are asked to demonstrate the same measures contractually. Article 21(2) lists ten minimum measures at points (a) to (j).

Article 21(2) minimum measures — coverage in the control library
Ref Measure Coverage
21(2)(a)Risk analysis and information system security policiesMapped
21(2)(b)Incident handlingNot mapped
21(2)(c)Business continuity, backup and crisis managementNot mapped
21(2)(d)Supply chain securityPartial
21(2)(e)Security in acquisition, development and maintenanceMapped
21(2)(f)Policies to assess effectiveness of risk-management measuresMapped
21(2)(g)Basic cyber hygiene practices and security trainingPartial
21(2)(h)Cryptography and encryption policiesMapped
21(2)(i)Human resources security, access control and asset managementMapped
21(2)(j)Multi-factor authentication and secured communicationsMapped

NIS2 is transposed into national law by each Member State, and Ireland’s implementing legislation governs how these measures apply to an Irish entity. Our mapping is to the Directive text and is not legal advice. You should take advice on whether your organisation is in scope and as what type of entity.

§ 07 — DORA

DORA, pillar by pillar

The Digital Operational Resilience Act applies to Irish financial entities and to the ICT providers serving them, and it arrives in most SME inboxes as a contract clause rather than as a regulator’s letter. Here is where each of its five pillars lands against the mapping above.

DORA pillars — where each one lands against the control library
Pillar Where the answer comes from
ICT risk managementSubstantially the same ground as Annex A and Article 21(2). The records that evidence those controls carry most of this pillar with them.
ICT incident reportingClassification thresholds and regulator-facing reports on statutory clocks. A process your business runs, evidenced by its own incident records.
Digital operational resilience testingTesting programmes, including threat-led penetration testing for some entities. Work for a testing provider rather than for a control library.
ICT third-party riskThe register of information is the demanding part. CD-04 tiers suppliers by the same criticality question, which is where a defensible answer starts.
Information sharingVoluntary between entities. Nothing a control library answers, and nothing we will pretend to.

DORA is a Regulation with direct effect, and its regulatory technical standards sit underneath it. What is written above is our reading of where the pillars fall against the controls in the library; it is not legal advice on whether your organisation is in scope, or as what.

§ 08 — NIST CSF 2.0

NIST CSF 2.0 in procurement questionnaires

CSF 2.0 reaches UK and Irish SMEs through enterprise procurement rather than through regulation: an American customer sends a spreadsheet quoting subcategory identifiers and wants it back by Friday. Six functions, 106 subcategories, and a vocabulary describing controls the Annex A mapping already answers.

CSF 2.0 functions — where a questionnaire answer comes from
Function Subcategories Where the answer comes from
GV — Govern31Annex A.5 organisational controls: policy, roles, supplier terms, compliance obligations.
ID — Identify21The tenant inventory a posture scan produces, plus the supplier register in CD-04.
PR — Protect22Annex A.8 and the Cyber Essentials technical themes: access, configuration, updates, malware, encryption.
DE — Detect11Audit logging and retention checks in CD-01, which are the same outcomes CAF objective C asks about.
RS — Respond13Your incident process and the records it leaves behind. No cloud scan answers this one.
RC — Recover8Restore testing and continuity evidence, which comes from whoever runs your backups.

The library is written against the identifiers in the left-hand column of the frameworks above, not against CSF subcategory numbers. Where a subcategory asks for multi-factor authentication, privileged access review, audit logging or supplier assurance, the record that answers the Annex A control answers the questionnaire line too: the identifier differs, the evidence does not. The NIST Cybersecurity Framework is published by the US National Institute of Standards and Technology, which does not endorse products, and we claim no relationship with it.

§ 09 — Ask us

Framework you need that is not on this list?

Tell us the framework, the sector, and who is asking you for it. More often than not the controls underneath it are ones the library already carries under another name, and the useful half hour is the one where we go through which of your records answer them.

Book an assessment conversation — hello@lagancyber.co.uk · we reply within two working days

We do not maintain a mailing list and will not add you to one. Your email is used to answer you and nothing else — see the privacy notice.