```
Readiness planning while the Bill progresses. CSRB-BRIDGE is built for operational readiness assessment. Buyers should verify current legal requirements against official sources before relying on dated Bill status, Parliamentary timing, commencement assumptions or regulator guidance. Royal Assent is not the same as commencement or enforcement.
CSRB-BRIDGE

10 of 16 anticipated CSRB requirement areas are not fully covered by Cyber Essentials. See where your baseline stands before the compliance window closes.

A regulatory diagnostic for UK MSPs who hold CE or CE+ certification. It maps 16 anticipated CSRB requirement areas against current CE/CE+ coverage, scores likely regulatory exposure against NCSC CAF v4.0, and provides a board-ready briefing you can act on the same day. Instant digital download.

24/100
CE/CE+ Baseline — High Exposure

This is the benchmark score used in CSRB-BRIDGE for a CE/CE+-certified MSP against anticipated CSRB requirement areas, weighted against NCSC CAF v4.0. It reflects 10 material gaps and a baseline posture likely to attract regulatory scrutiny without further remediation.

Your Gap Profile at a Glance
10 Critical Gaps
(RED)
4 Partial Coverage
(AMBER)
2 CE Baseline Valid
(GREEN)
24/100 Exposure
Score

Based on analysis of 16 anticipated CSRB requirement areas against CE and CE+ coverage, calibrated against NCSC CAF v4.0. RED items indicate areas where additional controls are likely to be needed as the framework develops.

What's Included — Diagnostic Pack
  • 1
    Executive Readiness Snapshot 1-Page Board Summary · Exposure Score · Decision Triggers Single-page dashboard presenting your exposure score, critical gap count, estimated remediation window, and likely pressure points. Designed to be handed to a director or presented at board level without further preparation.
    Score: 24/100 Board-ready Instant clarity
  • 2
    CSRB Scope Test Likely Regulatory Exposure · MSP Scope Assessment Step-by-step questions to assess whether your organisation may fall within scope under the Bill. Includes threshold and service criteria for operational readiness planning.
    Scope criteria Threshold checks Exposure confirmation
  • 3
    16-Area CE/CE+ Gap Mapping RAG Status · CAF Objective · Coverage Analysis All 16 anticipated CSRB requirement areas mapped against CE and CE+ coverage. Each area shows what CE covers, what CSRB appears likely to add, current RAG status, and a priority action.
    16 requirements RAG status Priority actions
  • 4
    CSRB Exposure Score Weighted Diagnostic · CAF v4.0 Calibrated · Auditable Methodology A weighted scoring model across all 16 domains, calibrated against NCSC CAF v4.0 regulatory priority. CE/CE+ baseline: 24/100. Indicative inspection-ready threshold: 86/100. Every weight and score is visible in the diagnostic.
    CAF v4.0 weighted Auditable Method visible
  • 5
    10 Critical Gap Cards Remediation Guidance · Effort Estimate · Priority Ranking One card per critical gap. Each card explains what the gap is, why CE does not sufficiently address it, what the likely regulatory expectation is, and what to do first.
    10 gaps Remediation steps Effort estimate
  • 6
    Remediation Tracker Owner Fields · Deadlines · Evidence Notes Pre-populated with all 16 remediation actions. Add owner names, target dates, and evidence notes. The output becomes a documented remediation programme you can use internally.
    Pre-populated Owner assignment Evidence trail
  • 7
    Board Briefing Template Regulatory Context · Gap Summary · Recommended Actions A structured briefing document for senior leadership. Contains the regulatory context, your gap summary, exposure score, and a recommended action plan.
    Board-ready Regulatory context Action plan
  • 8
    90-Day Transition Plan Phased Implementation · Milestone Roadmap · Readiness Timeline Three-phase implementation roadmap taking you from gap assessment to stronger readiness. Designed to run alongside normal operations without a dedicated project team.
    3 phases 12-week roadmap Readiness plan
  • +
    Bonus: 3 Client Email Templates Initial Awareness · Follow-Up · Report Delivery Three ready-to-brand emails covering the client conversation arc — from opening the discussion with CE-certified clients to formally delivering the gap analysis as a paid engagement.
    Initial awareness Follow-up Report delivery
CSRB-BRIDGE Regulatory Diagnostic cover

Regulatory diagnostic pack. Instant digital download. Includes readiness materials and client email templates.

What Happens After Purchase
  1. 1 Payment completes securely at checkout.
  2. 2 Download link is delivered automatically after checkout.
  3. 3 Open the Executive Snapshot first — your score is shown inside the diagnostic.
  4. 4 Complete the Scope Test, review your gap cards, and assign owners in the Remediation Tracker.
Instant access

Instant download — yours to keep. Deploy it at your own pace.

Instant download · single organisation licence
£297
Start Your Gap Analysis
Own MSP Use

Read the Snapshot. Review your Exposure Score. Assign owners to the critical gaps. Present the Board Briefing to leadership within 30 days.

Client Engagement

Use the client templates to open the conversation. Walk clients through the key gaps. Deliver the completed diagnostic as a paid engagement where appropriate.

Stay Current

Your gap position may change as the Bill and operational guidance evolve. Review sources regularly and update your readiness position before relying on older analysis.

Common Questions
We hold CE+ — isn't that a higher standard?
CE+ is a verified version of CE, not a broader one. It confirms that the same core CE control areas are operating in practice — it does not materially extend the scope of the framework. CSRB-BRIDGE assesses anticipated requirement areas including incident reporting, supply chain governance, board accountability, and continuous monitoring. In most of those areas, CE+ does not materially change the baseline position.
Can I use this diagnostic with my clients directly?
Yes. The diagnostic is designed for dual use. The client email templates help open the conversation. The gap analysis and exposure score can be presented to a client as a standalone paid deliverable or used to support a wider engagement. The single organisation licence covers your own internal use and delivery to your clients — you cannot resell the document itself as a standalone product.
What are the critical gaps CE misses?
The RED gaps assessed in the diagnostic include areas such as accelerated incident reporting, fuller follow-up incident reporting, supply chain risk management, governance over AI use where relevant, continuous monitoring, board-level accountability, data governance, resilience planning, logging and monitoring capability, and alerting maturity. Each gap is broken down into its own remediation card inside the diagnostic.
How is the Exposure Score calculated?
The score is a weighted composite across 16 anticipated CSRB requirement areas, calibrated against NCSC CAF v4.0 priority. Domains expected to attract higher scrutiny under enforcement, such as governance and monitoring, carry greater weighting. Score = Σ(weight × domain_score / 5) × 100. The CE/CE+ benchmark used in the diagnostic is 24/100. An indicative inspection-ready threshold is set at 86/100. Every weight and score is visible in the diagnostic.
```