Readiness overview
Cyber Trust mark self-assessment checklist v202504 · CSA-CTM-self-assessment-v202504
Live · API
Readiness snapshot — not a certificate
8%SCORE
5/75
Met controls
2
Partial controls
68
Missing controls
7
Evidence items
Fusion: 2 control(s) satisfied by signed, signature-verified SOC evidence — live security telemetry becomes effectiveness-grade compliance evidence.
75 shown
B.1.3READY
Understanding the importance of cybersecurity
met1.0 pts
manual
1 freshsara.koh@meridianpay.example
Evidence & mappings →
B.10.1NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.10.2NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.10.3NOT STARTED
Using automated backup
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.10.4READY
Establishing backup plans
met1.0 pts
soc
1 freshmei.lim@meridianpay.example
Evidence & mappings →
B.10.5NOT STARTED
Use of technologh solutions for data backup and recovery
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.11.3NOT STARTED
Policies and procedures on BYOD
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.12.1NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.12.2NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.12.3NOT STARTED
Performing monitoring on updates and patches
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.12.4NOT STARTED
Implementing process for the application of secure configuration
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.12.5NOT STARTED
Implementing log management process
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.12.6READY
Implementing patch management process
met1.0 pts
connector
1 fresharjun.rao@meridianpay.example
Evidence & mappings →
B.13.1NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.13.2NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.13.3NOT STARTED
Selection of anti-virus and/or anti-malware solution
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.13.4NOT STARTED
Implementing web filtering
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.13.5NOT STARTED
Virus and/or malware isolation
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.13.6NOT STARTED
Isolation of codes or applications
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.14.3NOT STARTED
Establishing secure SDLC guidelines and requirements
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.15.1NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.15.2NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.15.3NOT STARTED
Role matrix review
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.15.4NOT STARTED
Account access and role matrix review follow-up process
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.15.5NOT STARTED
Principles of least privilege and segregation of duties
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.15.6NOT STARTED
Secure logon policy and procedure
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.17.3NOT STARTED
Service level Agreement
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.18.3NOT STARTED
Establishing vulnerability assessment plan
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.18.4NOT STARTED
Implementing regular vulnerability assessment
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.19.2NOT STARTED
Establishing detective control
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.19.3NOT STARTED
Protection against internal and external threats
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.19.4NOT STARTED
Implementing perimeter security
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.19.5NOT STARTED
Implementing visitor authorisation
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.19.6NOT STARTED
Monitoring physical premise
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.19.7NOT STARTED
Establishing physical media handling process
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.2.3NOT STARTED
Communicating cybersecurity guidance and/or requirements to employees regularly
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.20.2NOT STARTED
Implementing access control
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.20.3NOT STARTED
Implementing stateful firewall
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.20.4NOT STARTED
Network security review
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.20.5NOT STARTED
Implementing network security
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.20.6NOT STARTED
Implementing network segmentation
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.21.1NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.21.2NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.21.3NOT STARTED
Verifying contactability of personnel involved in incident response
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.21.4PENDING
Performing cyber exercises
partial0.5 pts
soc
1 freshwei.tan@meridianpay.example
  • Manual task pending (due 2026-07-12)
Evidence & mappings →
B.22.2NOT STARTED
Identifying critical assets requiring high availability
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.22.3NOT STARTED
Performing business impact analysis
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.22.4NOT STARTED
Implemenring process for redundancy
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.3.1NOT STARTED
Risk identification and remediation
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.3.2NOT STARTED
Risk analysis
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.3.3NOT STARTED
Risk response
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.3.4NOT STARTED
Regular risk identification and tracking
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.3.5NOT STARTED
Defining risk assessment process
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.3.6IN PROGRESS
Establishing cybersecurity risk register
partial0.5 pts
manual
1 freshsara.koh@meridianpay.example
  • Control in progress
Evidence & mappings →
B.5.1NOT STARTED
Identifying areas of cybersecurity-related law and regulation
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.5.2NOT STARTED
Establishing measures to ensure compliance
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.5.3NOT STARTED
Communicating cybersecurity laws, regulations and guidelines to employees for compliance
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.5.4NOT STARTED
Defining process for compliance
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.7.1NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.7.2NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.7.3NOT STARTED
Tracking metrics of employee cybersecurity awareness
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.7.4READY
Performing cybersecurity awareness assessments
met1.0 pts
connector
1 freshwei.tan@meridianpay.example
Evidence & mappings →
B.7.5NOT STARTED
Appointing cybersecurity champion
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.8.1NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.8.2NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.8.3READY
Assets handling policy and procedure
met1.0 pts
connector
1 fresharjun.rao@meridianpay.example
Evidence & mappings →
B.8.4NOT STARTED
Measures handling highly classified assets
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.8.5NOT STARTED
Defining roles and responsibilities for managing assets in inventory
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.9.1NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.9.2NOT STARTED
Reporting of data breach
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.9.3NOT STARTED
Aligning encryption algorithm and key length to industry best practices
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.9.4NOT STARTED
Cybersecurity measures in Cyber Essentials
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.9.5NOT STARTED
Measures for handling highly classified assets
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.9.6NOT STARTED
Establishing data flow diagram
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →
B.9.7NOT STARTED
Secure data handling policy and procedure
missing0.0 pts
no evidence
0 fresh
  • No evidence collected
  • Not started
Evidence & mappings →