United Kingdom
Cyber Essentials Plus and NCSC CAF, documented as you onboard.
The UK baseline is certification-led: Cyber Essentials Plus for procurement, NCSC CAF for critical services, UK GDPR for everyone. Blueprint generates the evidence pack alongside the onboarding itself.
What applies in the UK
UK GDPR and the Data Protection Act 2018 apply to any entity processing UK personal data, with a 72-hour breach notification window to the ICO. Cyber Essentials and its audited variant Cyber Essentials Plus are required for many UK government contracts. The NCSC Cyber Assessment Framework applies to operators of essential services and is increasingly used in GovAssure reviews.
Blueprint's Comply module maps every generated onboarding document to these frameworks, so the gap analysis and the delivery evidence come out of the same pipeline.
What the generated pack covers
Each UK onboarding pack includes the incident response framework with ICO notification steps, a risk register aligned to CAF objectives, detection priorities per sector, and source runbooks with the retention windows your frameworks require.
Statutory notification deadlines
| Trigger | Deadline | Report to |
|---|---|---|
| Personal data breach with risk to rights and freedoms | 72 hours from awareness | ICO |
| Material operational or cyber incident | 24 hours | FCA |
Frequently asked questions
Partner with us
Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. UK MSPs and consultancies resell Blueprint under their own name today.
Apply as a partner