Schedule
VIII
IT and cyber
Infrastructure, application inventory, cyber posture, security incidents.
- VIII.1Obtain application inventory with licence type, user count and renewal date.Severity B
- VIII.2Identify any SaaS or licensing true-up exposure.Severity B
- VIII.3Review infrastructure topology: cloud accounts, on-prem, hybrid.Severity B
- VIII.4Confirm Cyber Essentials Plus or ISO 27001 certification status.[NCSC CE]Severity B
- VIII.5Obtain most recent penetration-test report and remediation evidence.Severity A
- VIII.6Review security-incident log for the last three years and ICO notifications.Severity A
- VIII.7Confirm backup, BCP and DR test history.Severity B
- VIII.8Test password, MFA and privileged-access controls on a sample.Severity B
- VIII.9Review identity / SSO architecture and joiner-mover-leaver cadence.Severity B
- VIII.10Confirm cyber-insurance cover and any exclusion for prior incidents.Severity B
- VIII.11Identify open-source software dependencies and any GPL-style licensing risk.Severity B
- VIII.12Confirm software-development lifecycle: code review, SCA, SAST, DAST.Severity C
- VIII.13Review hosting locations and data-residency commitments.Severity B
- VIII.14Obtain SOC 2 Type II report (or evidence in-scope alternative).Severity B
- VIII.15Confirm vendor-risk-management process for third-party services.Severity C
- VIII.16Identify any pending IT-modernisation capex in the forecast.Severity C
- VIII.17Confirm shadow-IT discovery and any unmanaged sanctioned tools.Severity C
- VIII.18Review historic security incidents impacting customers and notifications.Severity A
Reviewed by Oliver Wakefield-Smith, Founder, Digital SignetLast verified 21 June 2026Schedule VIII
This page is anchored to UK primary legislation and named regulator guidance only. Not legal advice. Confirm position with your appointed adviser before signing.