
What to Expect During Your First Pen Test
A founder's field guide to penetration testing, from a team that's run hundreds of them
Matt Jennings•Sep 08, 2026
What to Expect During Your First Pen TestBring any standard, checklist or internal framework onto Assuric
Not every requirement comes in a neat, off-the-shelf standard. With the custom framework builder you can bring any standard, regulator checklist or internal framework onto Assuric, structure it the way your team works, and manage it alongside everything else you already track. Do the work once, and reuse it everywhere.
Request a demoCustom Compliance Framework
Most custom frameworks arrive as a spreadsheet only one person understands. Here is where they end up.
compliance_tracker_v9 (1).xlsx
Your framework on Assuric
Governance
Operations
Groups, sections and requirements, each with an owner, tasks and evidence.
We are trusted by
Bring any framework onto the platform and manage it like a native one:
Structure any framework into groups, sections and requirements. Drag and drop to shape it around how your team actually works, then add tasks, owners and due dates like any other framework on Assuric.
Framework builder
Governance
Operations
Drag and drop groups, sections and requirements.
Send us the standard and we can load the requirements for you, then you add your tasks and evidence. Or build it yourself from scratch. Either way you are not starting with a blank page.
Your framework
LoadedFrom a PDF, spreadsheet or checklist
Set up for you
Link a single piece of evidence to requirements across your custom framework and your existing ones. No duplicating work, and no wondering whether two frameworks are telling the same story.
Evidence mapping
Staff training records
Uploaded once
Your custom framework
MetISO 27001
MetNHS DSPT
MetSet your own maturity scale, risk categories and scoring so the framework reflects how you actually measure progress, not a one-size-fits-all default.
Maturity score
Your scale, your scoring
Show your custom frameworks on your externally facing Trust Centre alongside your certifications, so buyers can see everything you comply with in one place.
Trust Centre
ISO 27001
Certified
NHS DTAC
Complete
Your custom framework
Alongside your certifications
Custom frameworks get the same controlled document management as the rest of the platform. Clear owners, review dates, approvals and full version history.
Version history
v3 · Current
Approved by Compliance Lead
v2
Requirements restructured
v1
Initial import
Get in touch if we haven’t answered your question below, we are always happy to help!
A custom framework lets you bring any set of requirements onto Assuric that is not already a built-in standard. That might be an environmental standard like ISO 14001, a sector checklist, a regulator framework or your own internal controls. You get the same structure, tasks, evidence and reporting as a native framework.
You get the full builder, task and evidence management, custom maturity and risk scoring, controlled documents and Trust Centre publishing. The main difference is that built-in frameworks come with our pre-loaded requirements, templates and guidance, whereas a custom framework starts from the requirements you or we load in. We can do the initial setup for you to close most of that gap. If you tell us the standard, we will tell you honestly what is and is not included.
Yes. For many customers we load the requirements in and hand it over ready to populate with tasks and evidence. For others we build more of it out. We will scope this with you on a call.
Yes, and this is where a lot of the value is. You can link evidence and controls across your custom framework and your existing ones, so overlapping requirements are satisfied once rather than several times.
Yes. Custom frameworks appear in your Trust Centre framework selector alongside your certifications, so buyers see the full picture.
Compliance is complex, but our AI tools simplify it. Discover features to stay ahead of regulations.
Kelly Klifa
CEO at Heim
Assuric has been transformative for Heim as we looked to achieve DCB0129 and DTAC compliance. The platform is easy to use, and the AI tools and automated reminders make previously dreaded compliance tasks a breeze. Paul and Matt supported us every step of the way.
Katie Baker
Director UK & Ireland at Tandem
Assuric has been fantastic in helping us quickly and safely navigate regulatory compliance in the UK. From completing Cybersecurity requirements to DSPT, DCB0129, and DTAC, the team was supportive, extremely knowledgeable, and the platform made everything quick and straightforward. A separate regulatory company we consulted at the beginning even remarked on how quickly we achieved compliance!
Maks Kozarzewski
COO at VitVio
We couldn't speak highly enough of both the Assuric team and the platform itself, which is incredibly easy to use, and with the skill and hardworking nature of the Assuric team. They've been a key component in accelerating our progress and deployments!
Maja Mazur
CEO at Healthnix
Assuric has been such a blessing in getting our DTAC and GDPR compliance done - completing all the documentation and deciding what needs to be done whilst running the business is very hard, but the team really helped us through that. The platform is easy to use, helps keep track of things and it even allows us to coordinate all the team training easily. Highly recommend them!
Dean Mawson
Clinical Director at DPM
Assuric streamlines the process of achieving and maintaining compliance with DCB0129 standards for digital health technologies. The user-friendly interface simplifies collaboration across multidisciplinary teams, while the built-in templates and workflows save significant time and effort during compliance projects. Assuric’s ability to centralise documentation and provide real-time visibility into project progress is particularly beneficial for Clinical Safety Officers and digital project teams, enhancing both efficiency and assurance.

A founder's field guide to penetration testing, from a team that's run hundreds of them
Matt Jennings•Sep 08, 2026
What to Expect During Your First Pen Test
Learn what CQC compliance is, who needs to register, how CQC inspections work, what evidence you'll need, and how to prepare for registration and inspections.
Dr Johnny Andrews,Cordi Mahony•Jul 24, 2026
CQC Compliance Explained: the Clinical Governance EssentialsGoodbye manual processes, hello automation. Let Assuric manage compliance and security, so you can focus on growth.
