{"generatedAt":"2026-07-29T11:29:24Z","source":"ismscopilot-marketing","contract":"v1","product":"isms-copilot-logged-out-landings","origin":"https://chat.ismscopilot.com","note":"Public landing copy for agents. Chat SPA HTML may still be bot-challenged. Do not invoke demo/chat POST as a public agent API (wallet path).","landings":[{"slug":"home","path":"/","canonicalUrl":"https://chat.ismscopilot.com/","seedContext":null,"heading":"How can I help?","subheading":"GRC AI for ISO 27001, SOC 2, GDPR, NIS 2, DORA and more.","meta":{"title":"ISMS Copilot — AI for ISO 27001, SOC 2, GDPR & more","description":"Ask ISMS Copilot anything about information security compliance. Try it free, no account needed."},"appName":null,"chips":[{"label":"ISO 27001 risk assessment","prompt":"How do I run an ISO 27001 risk assessment?"},{"label":"Explain a SOC 2 control","prompt":"Explain SOC 2 control CC6.1 in plain language."},{"label":"Vendor security questionnaire","prompt":"Help me answer a vendor security questionnaire."}],"brief":null},{"slug":"iso27001","path":"/iso-27001-assistant","canonicalUrl":"https://chat.ismscopilot.com/iso-27001-assistant","seedContext":"ISO/IEC 27001 information security management systems","heading":"How can I help with ISO 27001?","subheading":"Free AI guidance for ISO 27001 compliance.","meta":{"title":"ISO 27001 AI Assistant: risk assessments, Annex A, SoA | ISMS Copilot","description":"Free AI assistant for ISO 27001. Ask about risk assessments, Annex A controls, the Statement of Applicability, and certification audits. No account needed."},"appName":"ISO 27001 AI Assistant","chips":[{"label":"Run a risk assessment","prompt":"How do I run an ISO 27001 risk assessment, step by step?"},{"label":"Explain an Annex A control","prompt":"Explain ISO 27001 Annex A control A.8.16 in plain language."},{"label":"Build a Statement of Applicability","prompt":"How do I build an ISO 27001 Statement of Applicability (SoA)?"}],"brief":{"title":"About the ISO 27001 assistant","grounding":"Seeded with ISO/IEC 27001 concepts: ISMS scope, the risk assessment and treatment process, Annex A reference controls, the Statement of Applicability, internal audit, and Stage 1 and Stage 2 certification readiness.","capabilities":["Scope your ISMS and map out the certification path.","Run a risk assessment and choose your risk treatments.","Select and justify Annex A controls and draft your Statement of Applicability."],"boundary":"It gives implementation guidance to speed up your work. It does not replace an auditor and does not guarantee certification.","guideUrl":"https://www.ismscopilot.com/frameworks/iso-27001","guideLabel":"Read the full ISO 27001 guide"}},{"slug":"soc2","path":"/soc-2-assistant","canonicalUrl":"https://chat.ismscopilot.com/soc-2-assistant","seedContext":"SOC 2 Trust Services Criteria and service organization controls","heading":"How can I help with SOC 2?","subheading":"Free AI guidance for SOC 2 compliance.","meta":{"title":"SOC 2 AI Assistant: Trust Services Criteria, controls, Type II | ISMS Copilot","description":"Free AI assistant for SOC 2. Ask about the Trust Services Criteria, Common Criteria controls, readiness, and Type I vs Type II reports. No account needed."},"appName":"SOC 2 AI Assistant","chips":[{"label":"Scope the Trust Services Criteria","prompt":"Which SOC 2 Trust Services Criteria should be in my report scope?"},{"label":"Explain a Common Criteria control","prompt":"Explain SOC 2 Common Criteria control CC6.1 in plain language."},{"label":"Type I vs Type II report","prompt":"What is the difference between a SOC 2 Type I and Type II report?"}],"brief":{"title":"About the SOC 2 assistant","grounding":"Seeded with SOC 2 concepts: the five trust services categories (security, availability, processing integrity, confidentiality, and privacy), the Common Criteria for security, defining your system and report scope, readiness assessments, and the difference between Type I and Type II examinations.","capabilities":["Decide which trust services categories belong in your report scope.","Work through the Common Criteria (CC1 to CC9) and map your controls to them.","Prepare for a readiness assessment and choose between a Type I and a Type II report."],"boundary":"It gives implementation guidance to speed up your work. It does not replace a licensed CPA firm, and a SOC 2 report is an attestation, not a certification.","guideUrl":"https://www.ismscopilot.com/frameworks/soc-2","guideLabel":"Read the full SOC 2 guide"}},{"slug":"gdpr","path":"/gdpr-assistant","canonicalUrl":"https://chat.ismscopilot.com/gdpr-assistant","seedContext":"EU General Data Protection Regulation (GDPR) compliance","heading":"How can I help with GDPR?","subheading":"Free AI guidance for GDPR compliance.","meta":{"title":"GDPR AI Assistant: ROPA, DPIA, data subject rights | ISMS Copilot","description":"Free AI assistant for GDPR. Ask about records of processing (ROPA), DPIAs, data subject rights, lawful bases, and breach notification. No account needed."},"appName":"GDPR AI Assistant","chips":[{"label":"Build a record of processing (ROPA)","prompt":"How do I build a GDPR record of processing activities (ROPA) under Article 30?"},{"label":"Run a DPIA","prompt":"When does GDPR require a data protection impact assessment (DPIA), and how do I run one?"},{"label":"Handle a data subject request","prompt":"How do I handle a GDPR data subject access request, and what are the deadlines?"}],"brief":{"title":"About the GDPR assistant","grounding":"Seeded with GDPR concepts: lawful bases for processing (Article 6), records of processing activities (Article 30), data protection impact assessments (Article 35), data subject rights (Articles 15 to 22), personal data breach notification (Article 33), and the data protection officer role (Article 37).","capabilities":["Map your processing activities into a ROPA and identify the lawful basis for each.","Decide when a DPIA is needed and work through the assessment step by step.","Set up workable processes for data subject requests and breach notification."],"boundary":"It gives implementation guidance to speed up your work. It is not legal advice and does not replace a qualified privacy professional or your DPO.","guideUrl":"https://www.ismscopilot.com/frameworks/gdpr","guideLabel":"Read the full GDPR guide"}},{"slug":"nis2","path":"/nis-2-assistant","canonicalUrl":"https://chat.ismscopilot.com/nis-2-assistant","seedContext":"EU NIS 2 Directive (EU) 2022/2555 cybersecurity risk management and incident reporting","heading":"How can I help with NIS 2?","subheading":"Free AI guidance for NIS 2 compliance.","meta":{"title":"NIS 2 AI Assistant: scope, risk measures, incident reporting | ISMS Copilot","description":"Free AI assistant for NIS 2 (NIS2). Ask about scope (essential vs important entities), the Article 21 risk-management measures, incident reporting deadlines, and supply chain security. No account needed."},"appName":"NIS 2 AI Assistant","chips":[{"label":"Check if NIS 2 applies to you","prompt":"Does NIS 2 apply to my organization, and would we count as an essential or important entity?"},{"label":"Cover the Article 21 measures","prompt":"What cybersecurity measures does NIS 2 Article 21 require, and how do I put them in place?"},{"label":"Plan incident reporting","prompt":"How does NIS 2 incident reporting work, including the early warning and notification deadlines?"}],"brief":{"title":"About the NIS 2 assistant","grounding":"Seeded with NIS 2 concepts: who falls in scope as an essential or important entity (Articles 2 and 3), the security measures required for managing cyber risk (Article 21), the incident reporting obligations and their deadlines (Article 23), and how the directive is transposed into each member state's national law.","capabilities":["Work through whether NIS 2 applies to you and whether you would be an essential or important entity.","Translate the Article 21 measures into concrete controls, from risk analysis to supply chain security and multi-factor authentication.","Plan an incident reporting process around the early warning, notification, and final report stages."],"boundary":"It gives implementation guidance to speed up your work. It is not legal advice, and national transposition can vary, so confirm specifics with your competent authority or a qualified professional.","guideUrl":"https://www.ismscopilot.com/frameworks/nis-2","guideLabel":"Read the full NIS 2 guide"}},{"slug":"dora","path":"/dora-assistant","canonicalUrl":"https://chat.ismscopilot.com/dora-assistant","seedContext":"EU Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, ICT risk management and third-party risk for financial entities","heading":"How can I help with DORA?","subheading":"Free AI guidance for DORA compliance.","meta":{"title":"DORA AI Assistant: ICT risk, third-party risk, resilience testing | ISMS Copilot","description":"Free AI assistant for DORA, the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554). Ask about scope, managing ICT risk, incident reporting, resilience testing, and ICT third-party risk. No account needed."},"appName":"DORA AI Assistant","chips":[{"label":"Check if DORA applies to you","prompt":"Does DORA apply to my organization, and which type of financial entity would we be?"},{"label":"Build your ICT risk framework","prompt":"How do I set up a framework to manage ICT risk that meets DORA's requirements?"},{"label":"Manage ICT third-party risk","prompt":"What does DORA require for managing ICT third-party providers, and what contract terms do I need to cover?"}],"brief":{"title":"About the DORA assistant","grounding":"Seeded with DORA concepts: which financial entities and ICT third-party service providers fall in scope, how to manage ICT risk, how to classify and report ICT-related incidents, how to test digital operational resilience including threat-led penetration testing, and how to manage ICT third-party risk with the contract terms DORA expects.","capabilities":["Work through whether DORA applies to you and which category of financial entity you fall under.","Turn DORA's ICT risk obligations into concrete controls, governance, and an incident reporting process.","Plan how you manage ICT third-party risk, from an inventory of ICT provider contracts to the contract terms DORA expects and resilience testing."],"boundary":"It gives implementation guidance to speed up your work. It is not legal advice, so confirm specifics with your competent authority or a qualified professional.","guideUrl":"https://www.ismscopilot.com/frameworks/dora","guideLabel":"Read the full DORA guide"}},{"slug":"iso42001","path":"/iso-42001-assistant","canonicalUrl":"https://chat.ismscopilot.com/iso-42001-assistant","seedContext":"ISO/IEC 42001 artificial intelligence management system (AIMS), AI risk and impact assessment, and Annex A controls","heading":"How can I help with ISO 42001?","subheading":"Free AI guidance for ISO 42001 compliance.","meta":{"title":"ISO 42001 AI Assistant: AI management system, Annex A, risk assessment | ISMS Copilot","description":"Free AI assistant for ISO 42001, the AI management system standard. Ask about scope, AI risk and impact assessment, Annex A controls, the Statement of Applicability, and building your AIMS. No account needed."},"appName":"ISO 42001 AI Assistant","chips":[{"label":"Scope your AI management system","prompt":"How do I define the scope of an ISO 42001 AI management system for my organization?"},{"label":"Assess AI risks and impacts","prompt":"How do I carry out the AI risk assessment and the AI system impact assessment that ISO 42001 expects?"},{"label":"Pick your Annex A controls","prompt":"Which ISO 42001 Annex A controls apply to us, and how do I document the Statement of Applicability?"}],"brief":{"title":"About the ISO 42001 assistant","grounding":"Seeded with ISO 42001 concepts: how to scope and run an AI management system, how to assess AI risks and the impact of AI systems on people and society, the Annex A reference controls and how to record a Statement of Applicability, and the management-system clauses for leadership, planning, operation, and continual improvement.","capabilities":["Work through whether ISO 42001 fits your organization and how to scope your AI management system.","Turn ISO 42001's requirements into an AI risk assessment, an AI system impact assessment, and a risk treatment plan.","Select the Annex A controls that apply to you and draft a Statement of Applicability that records which controls are included or excluded, why, and their implementation status."],"boundary":"It gives implementation guidance to speed up your work. It is not certification or legal advice, so confirm specifics with your certification body or a qualified professional.","guideUrl":"https://www.ismscopilot.com/frameworks/iso-42001","guideLabel":"Read the full ISO 42001 guide"}},{"slug":"hipaa","path":"/hipaa-assistant","canonicalUrl":"https://chat.ismscopilot.com/hipaa-assistant","seedContext":"US HIPAA Security Rule, Privacy Rule, and Breach Notification Rule for covered entities and business associates","heading":"How can I help with HIPAA?","subheading":"Free AI guidance for HIPAA compliance.","meta":{"title":"HIPAA AI Assistant: Security Rule, safeguards, risk analysis, BAA | ISMS Copilot","description":"Free AI assistant for HIPAA compliance. Ask about the Security, Privacy, and Breach Notification Rules, the administrative, physical, and technical safeguards, risk analysis, Business Associate Agreements, and whether HIPAA applies to you. Built for covered entities and business associates. No account needed."},"appName":"HIPAA AI Assistant","chips":[{"label":"See if HIPAA applies to you","prompt":"How do I tell whether my organization is a HIPAA covered entity or a business associate?"},{"label":"Plan your Security Rule risk analysis","prompt":"How do I carry out a HIPAA Security Rule risk analysis and a risk management plan?"},{"label":"Map the safeguards","prompt":"Which administrative, physical, and technical safeguards does the HIPAA Security Rule expect, and how do I document them?"}],"brief":{"title":"About the HIPAA assistant","grounding":"Seeded with HIPAA concepts: the Security, Privacy, and Breach Notification Rules, who counts as a covered entity or a business associate, the administrative, physical, and technical safeguards, the expected risk analysis and risk management, and when a Business Associate Agreement is needed.","capabilities":["Work through whether HIPAA applies to you and whether you are a covered entity or a business associate.","Plan a Security Rule risk analysis and risk management approach, and turn the safeguards into policies you can document.","Understand your Breach Notification obligations and review where a Business Associate Agreement is needed across your vendors."],"boundary":"It gives implementation guidance to speed up your work. It is not legal advice and is not a HIPAA Business Associate, so do not paste protected health information, and confirm specifics with a qualified professional.","guideUrl":"https://www.ismscopilot.com/frameworks/hipaa","guideLabel":"Read the full HIPAA guide"}},{"slug":"euAiAct","path":"/eu-ai-act-assistant","canonicalUrl":"https://chat.ismscopilot.com/eu-ai-act-assistant","seedContext":"EU AI Act, Regulation (EU) 2024/1689, risk classification, high-risk AI system obligations, and general-purpose AI models","heading":"How can I help with the EU AI Act?","subheading":"Free AI guidance for EU AI Act compliance.","meta":{"title":"EU AI Act Assistant: compliance, risk classification, obligations | ISMS Copilot","description":"Free AI assistant for EU AI Act compliance. Ask about risk classification, prohibited practices, high-risk obligations, provider and deployer roles, transparency rules, general-purpose AI models, conformity assessment, and how the Act relates to ISO 42001. No account needed."},"appName":"EU AI Act Assistant","chips":[{"label":"Classify your AI system","prompt":"How do I work out which EU AI Act risk category my AI system falls into (prohibited practice, high-risk, transparency risk, or minimal risk)?"},{"label":"Find your role and obligations","prompt":"Am I a provider or a deployer under the EU AI Act, and which obligations apply to my role?"},{"label":"Plan high-risk compliance","prompt":"My AI system may be high-risk under the EU AI Act. How do I plan for risk management, technical documentation, and human oversight?"}],"brief":{"title":"About the EU AI Act assistant","grounding":"Seeded with EU AI Act concepts: the risk-based classification (prohibited practices, high-risk systems, transparency risk, and minimal risk), provider and deployer roles, the high-risk requirements such as risk management, data governance, technical documentation, and human oversight, transparency rules for AI-generated content, and the obligations for general-purpose AI models.","capabilities":["Work through which risk category your AI system falls into and whether the EU AI Act applies to you as a provider or a deployer.","Plan the high-risk requirements: risk management, data governance, technical documentation, logging, human oversight, and conformity assessment.","Understand the transparency rules for AI-generated content and chatbots, the general-purpose AI model obligations, and how the Act relates to ISO 42001."],"boundary":"It gives implementation guidance to speed up your work. It is not legal advice, and the Act's obligations phase in over time, so confirm the current dates and specifics with a qualified professional.","guideUrl":"https://www.ismscopilot.com/frameworks/eu-ai-act","guideLabel":"Read the full EU AI Act guide"}},{"slug":"pciDss","path":"/pci-dss-assistant","canonicalUrl":"https://chat.ismscopilot.com/pci-dss-assistant","seedContext":"PCI DSS (Payment Card Industry Data Security Standard) version 4.0, cardholder data environment scoping, the 12 requirements and six control objectives, SAQ validation, and the defined and customised approaches","heading":"How can I help with PCI DSS?","subheading":"Free AI guidance for PCI DSS compliance.","meta":{"title":"PCI DSS Assistant: CDE scoping, SAQ, 12 requirements | ISMS Copilot","description":"Free AI assistant for PCI DSS compliance. Ask about cardholder data environment (CDE) scoping, choosing the right Self-Assessment Questionnaire (SAQ), the 12 requirements across six control objectives, merchant and service-provider levels, the defined vs customised approach in version 4.0, the Report on Compliance (ROC) and Qualified Security Assessor (QSA), and drafting your Attestation of Compliance (AOC). No account needed."},"appName":"PCI DSS Assistant","chips":[{"label":"Scope your CDE","prompt":"How do I define and reduce the scope of my cardholder data environment (CDE) for PCI DSS, and where does cardholder data live in my systems?"},{"label":"Pick the right SAQ","prompt":"Which PCI DSS Self-Assessment Questionnaire (SAQ) type applies to my business, and how do I work out my merchant or service-provider level?"},{"label":"Plan the 12 requirements","prompt":"How do I work through the 12 PCI DSS requirements, and what is the difference between the defined and customised approach in version 4.0?"}],"brief":{"title":"About the PCI DSS assistant","grounding":"Seeded with PCI DSS concepts: the Payment Card Industry Data Security Standard maintained by the PCI Security Standards Council for any entity that stores, processes, or transmits cardholder data, the cardholder data environment (CDE) and scoping, the 12 requirements grouped under six control objectives, merchant and service-provider validation levels, the Self-Assessment Questionnaire (SAQ) types, the Report on Compliance (ROC) and Attestation of Compliance (AOC), and the defined and customised approaches introduced in version 4.0.","capabilities":["Work through defining and reducing your cardholder data environment (CDE) scope and identify where cardholder data is stored, processed, or transmitted.","Figure out your merchant or service-provider level and which Self-Assessment Questionnaire (SAQ) type fits, and when a Qualified Security Assessor (QSA) and a Report on Compliance (ROC) are needed instead.","Plan the 12 requirements across the six control objectives, understand the defined vs customised approach in version 4.0, and draft supporting policies and Attestation of Compliance (AOC) narratives."],"boundary":"It gives implementation guidance to speed up your work. It is not a Qualified Security Assessor, it cannot issue PCI DSS certification or attestation, and it is not legal advice.","guideUrl":"https://www.ismscopilot.com/frameworks/pci-dss","guideLabel":"Read the full PCI DSS guide"}},{"slug":"iso27701","path":"/iso-27701-assistant","canonicalUrl":"https://chat.ismscopilot.com/iso-27701-assistant","seedContext":"ISO/IEC 27701 privacy information management system (PIMS), a stand-alone privacy management system standard in its latest edition that can also build on an ISO/IEC 27001 ISMS, PII controller and PII processor roles, the Annex A privacy controls, and mapping to GDPR","heading":"How can I help with ISO 27701?","subheading":"Free AI guidance for ISO 27701 compliance.","meta":{"title":"ISO 27701 Assistant: PIMS, PII roles, GDPR mapping | ISMS Copilot","description":"Free AI assistant for ISO/IEC 27701, the privacy information management system (PIMS) standard. Ask about setting up a PIMS as a stand-alone system or on top of an existing ISO 27001 ISMS, working out PII controller and PII processor roles and the controls shared by both, the Annex A privacy controls, mapping your controls to GDPR and other privacy frameworks, handling data subject (PII principal) expectations, and building the records and evidence for certification. No account needed."},"appName":"ISO 27701 Assistant","chips":[{"label":"Set up a PIMS","prompt":"How do I set up a privacy information management system (PIMS) under ISO/IEC 27701, either as a stand-alone system or built on an existing ISO/IEC 27001 ISMS?"},{"label":"Controller or processor","prompt":"How do I determine whether my organization acts as a PII controller or a PII processor under ISO/IEC 27701, and which privacy controls apply to each role plus the shared ones?"},{"label":"Map to GDPR","prompt":"How does ISO/IEC 27701 map to GDPR obligations, and how can a PIMS help me demonstrate accountability for personal data (PII)?"}],"brief":{"title":"About the ISO 27701 assistant","grounding":"Seeded with ISO/IEC 27701 concepts: the privacy information management system (PIMS), which in its latest edition (ISO/IEC 27701:2025) is a stand-alone management system standard that can also build on an existing ISO/IEC 27001 ISMS, the distinction between a PII controller, a PII processor, and controls shared by both roles, the Annex A privacy controls, and the mappings that connect a PIMS to GDPR and other privacy frameworks such as ISO/IEC 29100.","capabilities":["Plan how to build a PIMS under ISO/IEC 27701, either as a stand-alone privacy management system or integrated with an existing (or planned) ISO/IEC 27001 ISMS, including the privacy scope, risk assessment, and Statement of Applicability.","Work out whether you act as a PII controller, a PII processor, or both, and which role-specific and shared privacy controls and responsibilities apply to you.","Use the PIMS-to-GDPR and related mappings to connect your controls to legal obligations, and draft the privacy policies, records (such as records of processing and data subject request handling), and evidence an auditor will expect for certification."],"boundary":"It gives implementation guidance to speed up your work. It is not a certification body, it cannot issue ISO/IEC 27701 certification, and it is not legal advice.","guideUrl":"https://www.ismscopilot.com/frameworks/iso-27701","guideLabel":"Read the full ISO 27701 guide"}},{"slug":"ccpa","path":"/ccpa-assistant","canonicalUrl":"https://chat.ismscopilot.com/ccpa-assistant","seedContext":"California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), business applicability thresholds, California consumer privacy rights, the sale and sharing of personal information and opt-outs, sensitive personal information, opt-out preference signals, and the California Privacy Protection Agency (CPPA)","heading":"How can I help with CCPA and CPRA?","subheading":"Free AI guidance for CCPA and CPRA compliance.","meta":{"title":"CCPA Assistant: CPRA, consumer rights, opt-out | ISMS Copilot","description":"Free AI assistant for the CCPA (California Consumer Privacy Act) as amended by the CPRA (California Privacy Rights Act). Ask about the applicability thresholds, the California consumer rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, the difference between selling and sharing for cross-context behavioral advertising, the Do Not Sell or Share My Personal Information link and opt-out preference signals like Global Privacy Control, notice at collection, service provider and contractor contract terms, and the records an audit or California Privacy Protection Agency (CPPA) inquiry expects. No account needed."},"appName":"CCPA Assistant","chips":[{"label":"Check if it applies","prompt":"How do I work out whether the CCPA, as amended by the CPRA, applies to my business, based on doing business in California and the applicability thresholds for annual revenue, the volume of personal information handled, and revenue from selling or sharing personal information?"},{"label":"Handle consumer requests","prompt":"How should we set up a process to receive, verify, and respond to California consumer requests, covering the rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information?"},{"label":"Opt-out and GPC","prompt":"How do I handle opt-outs of the sale and sharing of personal information, including the Do Not Sell or Share My Personal Information link and honoring opt-out preference signals such as Global Privacy Control?"}],"brief":{"title":"About the CCPA assistant","grounding":"Seeded with CCPA concepts, as amended by the CPRA: who the law applies to and the applicability thresholds, the California consumer rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, the difference between selling and sharing (including cross-context behavioral advertising), the roles of businesses, service providers, contractors, and third parties, opt-out preference signals such as Global Privacy Control, and the enforcement role of the California Privacy Protection Agency (CPPA).","capabilities":["Work through whether the CCPA and its CPRA amendments apply to your business, using the do-business-in-California test together with the thresholds for annual revenue, the volume of personal information handled, and revenue from selling or sharing personal information, and map which obligations follow.","Design a workflow to receive, verify, and respond to consumer requests within the required timelines, covering the rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, plus non-discrimination for consumers who exercise them.","Set up the opt-out mechanics (the Do Not Sell or Share My Personal Information link and honoring opt-out preference signals like Global Privacy Control), draft the notice at collection and privacy policy, structure service provider and contractor contract terms, and keep the records an audit or CPPA inquiry expects."],"boundary":"It gives implementation guidance to speed up your work. It is not a substitute for legal advice, and it cannot represent you before the California Privacy Protection Agency or a court.","guideUrl":"https://www.ismscopilot.com/frameworks/ccpa","guideLabel":"Read the full CCPA guide"}},{"slug":"cyberEssentials","path":"/cyber-essentials-assistant","canonicalUrl":"https://chat.ismscopilot.com/cyber-essentials-assistant","seedContext":"UK Cyber Essentials and Cyber Essentials Plus, the government-backed certification scheme developed by the NCSC and delivered through IASME, the five technical control themes (firewalls, secure configuration, security update management, user access control, malware protection), the verified self-assessment and the independent technical testing at Plus level, certification scoping including end-user devices, cloud services, home working, and BYOD, and annual recertification","heading":"How can I help with Cyber Essentials?","subheading":"Free AI guidance for Cyber Essentials certification.","meta":{"title":"Cyber Essentials AI Assistant: scope, five controls | ISMS Copilot","description":"Free AI assistant for Cyber Essentials, the UK government-backed certification scheme. Ask about the five technical control themes (firewalls, secure configuration, security update management, user access control, and malware protection), preparing the verified self-assessment, applying the scoping rules for end-user devices, cloud services, home working, and BYOD, stepping up to Cyber Essentials Plus with its independent technical testing, and the annual renewal cycle. No account needed."},"appName":"Cyber Essentials AI Assistant","chips":[{"label":"Prepare the self-assessment","prompt":"How do I prepare for the Cyber Essentials self-assessment, working through what the assessor expects under each of the five technical control themes: firewalls, secure configuration, security update management, user access control, and malware protection?"},{"label":"Define your scope","prompt":"How do I set the scope of my Cyber Essentials certification, when should it cover the whole organisation rather than a well-defined, separately managed sub-set, and how do the scoping rules apply to end-user devices, cloud services, home and remote working, and BYOD?"},{"label":"Step up to Plus","prompt":"What changes when moving from Cyber Essentials to Cyber Essentials Plus, how does the independent technical testing of in-scope devices work, and how should we prepare our configurations to pass it?"}],"brief":{"title":"About the Cyber Essentials assistant","grounding":"Seeded with Cyber Essentials concepts: the UK government-backed scheme developed by the NCSC and delivered through IASME, the five technical control themes (firewalls, secure configuration, security update management, user access control, and malware protection), the verified self-assessment route and the independent technical testing added at Cyber Essentials Plus, the scoping rules for end-user devices, cloud services, home and remote working, and BYOD, and the 12-month certification cycle.","capabilities":["Prepare your self-assessment answers theme by theme, working through what good looks like for firewalls, secure configuration, security update management, user access control, and malware protection across the devices, software, and services your organisation uses.","Set a defensible certification scope: the whole organisation or a well-defined, separately managed sub-set, knowing that end-user devices must be included and cloud services that hold organisational data or services cannot be excluded, and work out which home and remote working and user-owned (BYOD) devices fall in scope.","Plan the step up to Cyber Essentials Plus and the annual renewal, understand the independent technical testing an assessor carries out on in-scope devices, and prepare for bids where UK public-sector buyers ask for Cyber Essentials certification."],"boundary":"It gives preparation guidance to speed up your work. It is not a certification body, it cannot award Cyber Essentials or Cyber Essentials Plus, and it is not a substitute for assessment by a licensed certification body.","guideUrl":"https://www.ismscopilot.com/frameworks/cyber-essentials","guideLabel":"Read the full Cyber Essentials guide"}}],"tools":[{"slug":"iso27001-risk-analysis","path":"/iso-27001-risk-analysis","canonicalUrl":"https://chat.ismscopilot.com/iso-27001-risk-analysis","title":"Free ISO 27001 Risk Analysis | ISMS Copilot","description":"Free ISO 27001 risk analysis tool. Enter a company name and get an illustrative information-security risk assessment and risk register, generated live. No signup.","heading":"See an ISO 27001 risk analysis for your company","seoHeading":"About this free ISO 27001 risk analysis tool","seoParagraphs":["This free tool builds an illustrative ISO 27001 risk analysis for any company. Enter a company name or website and ISMS Copilot researches it, then drafts a structured information-security risk assessment in real time.","An ISO 27001 risk assessment identifies the threats and vulnerabilities facing your information assets, weighs their likelihood and impact, and records them in a risk register alongside treatment options and the relevant Annex A controls. This demo shows what that output can look like for your organisation.","It is free to use with no signup. The analysis is AI-generated from public information for illustration only, not a certified ISO 27001 or ISO 27005 assessment. For a full information security management system (ISMS), ISMS Copilot helps you build and maintain your ISO 27001 programme end to end."],"note":"Landing copy only. Running the demo POSTs to the chat backend and is not agent-open (wallet path)."}],"markdown":"# ISMS Copilot logged-out public landings\n\nPublic landing copy for agents. Chat SPA HTML may still be bot-challenged. Do not invoke demo/chat POST as a public agent API (wallet path).\n\n## How can I help?\n\n- Path: `/`\n- URL: https://chat.ismscopilot.com/\n- Subheading: GRC AI for ISO 27001, SOC 2, GDPR, NIS 2, DORA and more.\n- Meta: Ask ISMS Copilot anything about information security compliance. Try it free, no account needed.\n- Starter chips:\n  - **ISO 27001 risk assessment**: How do I run an ISO 27001 risk assessment?\n  - **Explain a SOC 2 control**: Explain SOC 2 control CC6.1 in plain language.\n  - **Vendor security questionnaire**: Help me answer a vendor security questionnaire.\n\n## How can I help with ISO 27001?\n\n- Path: `/iso-27001-assistant`\n- URL: https://chat.ismscopilot.com/iso-27001-assistant\n- Subheading: Free AI guidance for ISO 27001 compliance.\n- Meta: Free AI assistant for ISO 27001. Ask about risk assessments, Annex A controls, the Statement of Applicability, and certification audits. No account needed.\n- Framework focus: ISO/IEC 27001 information security management systems\n- Starter chips:\n  - **Run a risk assessment**: How do I run an ISO 27001 risk assessment, step by step?\n  - **Explain an Annex A control**: Explain ISO 27001 Annex A control A.8.16 in plain language.\n  - **Build a Statement of Applicability**: How do I build an ISO 27001 Statement of Applicability (SoA)?\n- Grounding: Seeded with ISO/IEC 27001 concepts: ISMS scope, the risk assessment and treatment process, Annex A reference controls, the Statement of Applicability, internal audit, and Stage 1 and Stage 2 certification readiness.\n- Capabilities:\n  - Scope your ISMS and map out the certification path.\n  - Run a risk assessment and choose your risk treatments.\n  - Select and justify Annex A controls and draft your Statement of Applicability.\n- Boundary: It gives implementation guidance to speed up your work. It does not replace an auditor and does not guarantee certification.\n- Guide: https://www.ismscopilot.com/frameworks/iso-27001\n\n## How can I help with SOC 2?\n\n- Path: `/soc-2-assistant`\n- URL: https://chat.ismscopilot.com/soc-2-assistant\n- Subheading: Free AI guidance for SOC 2 compliance.\n- Meta: Free AI assistant for SOC 2. Ask about the Trust Services Criteria, Common Criteria controls, readiness, and Type I vs Type II reports. No account needed.\n- Framework focus: SOC 2 Trust Services Criteria and service organization controls\n- Starter chips:\n  - **Scope the Trust Services Criteria**: Which SOC 2 Trust Services Criteria should be in my report scope?\n  - **Explain a Common Criteria control**: Explain SOC 2 Common Criteria control CC6.1 in plain language.\n  - **Type I vs Type II report**: What is the difference between a SOC 2 Type I and Type II report?\n- Grounding: Seeded with SOC 2 concepts: the five trust services categories (security, availability, processing integrity, confidentiality, and privacy), the Common Criteria for security, defining your system and report scope, readiness assessments, and the difference between Type I and Type II examinations.\n- Capabilities:\n  - Decide which trust services categories belong in your report scope.\n  - Work through the Common Criteria (CC1 to CC9) and map your controls to them.\n  - Prepare for a readiness assessment and choose between a Type I and a Type II report.\n- Boundary: It gives implementation guidance to speed up your work. It does not replace a licensed CPA firm, and a SOC 2 report is an attestation, not a certification.\n- Guide: https://www.ismscopilot.com/frameworks/soc-2\n\n## How can I help with GDPR?\n\n- Path: `/gdpr-assistant`\n- URL: https://chat.ismscopilot.com/gdpr-assistant\n- Subheading: Free AI guidance for GDPR compliance.\n- Meta: Free AI assistant for GDPR. Ask about records of processing (ROPA), DPIAs, data subject rights, lawful bases, and breach notification. No account needed.\n- Framework focus: EU General Data Protection Regulation (GDPR) compliance\n- Starter chips:\n  - **Build a record of processing (ROPA)**: How do I build a GDPR record of processing activities (ROPA) under Article 30?\n  - **Run a DPIA**: When does GDPR require a data protection impact assessment (DPIA), and how do I run one?\n  - **Handle a data subject request**: How do I handle a GDPR data subject access request, and what are the deadlines?\n- Grounding: Seeded with GDPR concepts: lawful bases for processing (Article 6), records of processing activities (Article 30), data protection impact assessments (Article 35), data subject rights (Articles 15 to 22), personal data breach notification (Article 33), and the data protection officer role (Article 37).\n- Capabilities:\n  - Map your processing activities into a ROPA and identify the lawful basis for each.\n  - Decide when a DPIA is needed and work through the assessment step by step.\n  - Set up workable processes for data subject requests and breach notification.\n- Boundary: It gives implementation guidance to speed up your work. It is not legal advice and does not replace a qualified privacy professional or your DPO.\n- Guide: https://www.ismscopilot.com/frameworks/gdpr\n\n## How can I help with NIS 2?\n\n- Path: `/nis-2-assistant`\n- URL: https://chat.ismscopilot.com/nis-2-assistant\n- Subheading: Free AI guidance for NIS 2 compliance.\n- Meta: Free AI assistant for NIS 2 (NIS2). Ask about scope (essential vs important entities), the Article 21 risk-management measures, incident reporting deadlines, and supply chain security. No account needed.\n- Framework focus: EU NIS 2 Directive (EU) 2022/2555 cybersecurity risk management and incident reporting\n- Starter chips:\n  - **Check if NIS 2 applies to you**: Does NIS 2 apply to my organization, and would we count as an essential or important entity?\n  - **Cover the Article 21 measures**: What cybersecurity measures does NIS 2 Article 21 require, and how do I put them in place?\n  - **Plan incident reporting**: How does NIS 2 incident reporting work, including the early warning and notification deadlines?\n- Grounding: Seeded with NIS 2 concepts: who falls in scope as an essential or important entity (Articles 2 and 3), the security measures required for managing cyber risk (Article 21), the incident reporting obligations and their deadlines (Article 23), and how the directive is transposed into each member state's national law.\n- Capabilities:\n  - Work through whether NIS 2 applies to you and whether you would be an essential or important entity.\n  - Translate the Article 21 measures into concrete controls, from risk analysis to supply chain security and multi-factor authentication.\n  - Plan an incident reporting process around the early warning, notification, and final report stages.\n- Boundary: It gives implementation guidance to speed up your work. It is not legal advice, and national transposition can vary, so confirm specifics with your competent authority or a qualified professional.\n- Guide: https://www.ismscopilot.com/frameworks/nis-2\n\n## How can I help with DORA?\n\n- Path: `/dora-assistant`\n- URL: https://chat.ismscopilot.com/dora-assistant\n- Subheading: Free AI guidance for DORA compliance.\n- Meta: Free AI assistant for DORA, the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554). Ask about scope, managing ICT risk, incident reporting, resilience testing, and ICT third-party risk. No account needed.\n- Framework focus: EU Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, ICT risk management and third-party risk for financial entities\n- Starter chips:\n  - **Check if DORA applies to you**: Does DORA apply to my organization, and which type of financial entity would we be?\n  - **Build your ICT risk framework**: How do I set up a framework to manage ICT risk that meets DORA's requirements?\n  - **Manage ICT third-party risk**: What does DORA require for managing ICT third-party providers, and what contract terms do I need to cover?\n- Grounding: Seeded with DORA concepts: which financial entities and ICT third-party service providers fall in scope, how to manage ICT risk, how to classify and report ICT-related incidents, how to test digital operational resilience including threat-led penetration testing, and how to manage ICT third-party risk with the contract terms DORA expects.\n- Capabilities:\n  - Work through whether DORA applies to you and which category of financial entity you fall under.\n  - Turn DORA's ICT risk obligations into concrete controls, governance, and an incident reporting process.\n  - Plan how you manage ICT third-party risk, from an inventory of ICT provider contracts to the contract terms DORA expects and resilience testing.\n- Boundary: It gives implementation guidance to speed up your work. It is not legal advice, so confirm specifics with your competent authority or a qualified professional.\n- Guide: https://www.ismscopilot.com/frameworks/dora\n\n## How can I help with ISO 42001?\n\n- Path: `/iso-42001-assistant`\n- URL: https://chat.ismscopilot.com/iso-42001-assistant\n- Subheading: Free AI guidance for ISO 42001 compliance.\n- Meta: Free AI assistant for ISO 42001, the AI management system standard. Ask about scope, AI risk and impact assessment, Annex A controls, the Statement of Applicability, and building your AIMS. No account needed.\n- Framework focus: ISO/IEC 42001 artificial intelligence management system (AIMS), AI risk and impact assessment, and Annex A controls\n- Starter chips:\n  - **Scope your AI management system**: How do I define the scope of an ISO 42001 AI management system for my organization?\n  - **Assess AI risks and impacts**: How do I carry out the AI risk assessment and the AI system impact assessment that ISO 42001 expects?\n  - **Pick your Annex A controls**: Which ISO 42001 Annex A controls apply to us, and how do I document the Statement of Applicability?\n- Grounding: Seeded with ISO 42001 concepts: how to scope and run an AI management system, how to assess AI risks and the impact of AI systems on people and society, the Annex A reference controls and how to record a Statement of Applicability, and the management-system clauses for leadership, planning, operation, and continual improvement.\n- Capabilities:\n  - Work through whether ISO 42001 fits your organization and how to scope your AI management system.\n  - Turn ISO 42001's requirements into an AI risk assessment, an AI system impact assessment, and a risk treatment plan.\n  - Select the Annex A controls that apply to you and draft a Statement of Applicability that records which controls are included or excluded, why, and their implementation status.\n- Boundary: It gives implementation guidance to speed up your work. It is not certification or legal advice, so confirm specifics with your certification body or a qualified professional.\n- Guide: https://www.ismscopilot.com/frameworks/iso-42001\n\n## How can I help with HIPAA?\n\n- Path: `/hipaa-assistant`\n- URL: https://chat.ismscopilot.com/hipaa-assistant\n- Subheading: Free AI guidance for HIPAA compliance.\n- Meta: Free AI assistant for HIPAA compliance. Ask about the Security, Privacy, and Breach Notification Rules, the administrative, physical, and technical safeguards, risk analysis, Business Associate Agreements, and whether HIPAA applies to you. Built for covered entities and business associates. No account needed.\n- Framework focus: US HIPAA Security Rule, Privacy Rule, and Breach Notification Rule for covered entities and business associates\n- Starter chips:\n  - **See if HIPAA applies to you**: How do I tell whether my organization is a HIPAA covered entity or a business associate?\n  - **Plan your Security Rule risk analysis**: How do I carry out a HIPAA Security Rule risk analysis and a risk management plan?\n  - **Map the safeguards**: Which administrative, physical, and technical safeguards does the HIPAA Security Rule expect, and how do I document them?\n- Grounding: Seeded with HIPAA concepts: the Security, Privacy, and Breach Notification Rules, who counts as a covered entity or a business associate, the administrative, physical, and technical safeguards, the expected risk analysis and risk management, and when a Business Associate Agreement is needed.\n- Capabilities:\n  - Work through whether HIPAA applies to you and whether you are a covered entity or a business associate.\n  - Plan a Security Rule risk analysis and risk management approach, and turn the safeguards into policies you can document.\n  - Understand your Breach Notification obligations and review where a Business Associate Agreement is needed across your vendors.\n- Boundary: It gives implementation guidance to speed up your work. It is not legal advice and is not a HIPAA Business Associate, so do not paste protected health information, and confirm specifics with a qualified professional.\n- Guide: https://www.ismscopilot.com/frameworks/hipaa\n\n## How can I help with the EU AI Act?\n\n- Path: `/eu-ai-act-assistant`\n- URL: https://chat.ismscopilot.com/eu-ai-act-assistant\n- Subheading: Free AI guidance for EU AI Act compliance.\n- Meta: Free AI assistant for EU AI Act compliance. Ask about risk classification, prohibited practices, high-risk obligations, provider and deployer roles, transparency rules, general-purpose AI models, conformity assessment, and how the Act relates to ISO 42001. No account needed.\n- Framework focus: EU AI Act, Regulation (EU) 2024/1689, risk classification, high-risk AI system obligations, and general-purpose AI models\n- Starter chips:\n  - **Classify your AI system**: How do I work out which EU AI Act risk category my AI system falls into (prohibited practice, high-risk, transparency risk, or minimal risk)?\n  - **Find your role and obligations**: Am I a provider or a deployer under the EU AI Act, and which obligations apply to my role?\n  - **Plan high-risk compliance**: My AI system may be high-risk under the EU AI Act. How do I plan for risk management, technical documentation, and human oversight?\n- Grounding: Seeded with EU AI Act concepts: the risk-based classification (prohibited practices, high-risk systems, transparency risk, and minimal risk), provider and deployer roles, the high-risk requirements such as risk management, data governance, technical documentation, and human oversight, transparency rules for AI-generated content, and the obligations for general-purpose AI models.\n- Capabilities:\n  - Work through which risk category your AI system falls into and whether the EU AI Act applies to you as a provider or a deployer.\n  - Plan the high-risk requirements: risk management, data governance, technical documentation, logging, human oversight, and conformity assessment.\n  - Understand the transparency rules for AI-generated content and chatbots, the general-purpose AI model obligations, and how the Act relates to ISO 42001.\n- Boundary: It gives implementation guidance to speed up your work. It is not legal advice, and the Act's obligations phase in over time, so confirm the current dates and specifics with a qualified professional.\n- Guide: https://www.ismscopilot.com/frameworks/eu-ai-act\n\n## How can I help with PCI DSS?\n\n- Path: `/pci-dss-assistant`\n- URL: https://chat.ismscopilot.com/pci-dss-assistant\n- Subheading: Free AI guidance for PCI DSS compliance.\n- Meta: Free AI assistant for PCI DSS compliance. Ask about cardholder data environment (CDE) scoping, choosing the right Self-Assessment Questionnaire (SAQ), the 12 requirements across six control objectives, merchant and service-provider levels, the defined vs customised approach in version 4.0, the Report on Compliance (ROC) and Qualified Security Assessor (QSA), and drafting your Attestation of Compliance (AOC). No account needed.\n- Framework focus: PCI DSS (Payment Card Industry Data Security Standard) version 4.0, cardholder data environment scoping, the 12 requirements and six control objectives, SAQ validation, and the defined and customised approaches\n- Starter chips:\n  - **Scope your CDE**: How do I define and reduce the scope of my cardholder data environment (CDE) for PCI DSS, and where does cardholder data live in my systems?\n  - **Pick the right SAQ**: Which PCI DSS Self-Assessment Questionnaire (SAQ) type applies to my business, and how do I work out my merchant or service-provider level?\n  - **Plan the 12 requirements**: How do I work through the 12 PCI DSS requirements, and what is the difference between the defined and customised approach in version 4.0?\n- Grounding: Seeded with PCI DSS concepts: the Payment Card Industry Data Security Standard maintained by the PCI Security Standards Council for any entity that stores, processes, or transmits cardholder data, the cardholder data environment (CDE) and scoping, the 12 requirements grouped under six control objectives, merchant and service-provider validation levels, the Self-Assessment Questionnaire (SAQ) types, the Report on Compliance (ROC) and Attestation of Compliance (AOC), and the defined and customised approaches introduced in version 4.0.\n- Capabilities:\n  - Work through defining and reducing your cardholder data environment (CDE) scope and identify where cardholder data is stored, processed, or transmitted.\n  - Figure out your merchant or service-provider level and which Self-Assessment Questionnaire (SAQ) type fits, and when a Qualified Security Assessor (QSA) and a Report on Compliance (ROC) are needed instead.\n  - Plan the 12 requirements across the six control objectives, understand the defined vs customised approach in version 4.0, and draft supporting policies and Attestation of Compliance (AOC) narratives.\n- Boundary: It gives implementation guidance to speed up your work. It is not a Qualified Security Assessor, it cannot issue PCI DSS certification or attestation, and it is not legal advice.\n- Guide: https://www.ismscopilot.com/frameworks/pci-dss\n\n## How can I help with ISO 27701?\n\n- Path: `/iso-27701-assistant`\n- URL: https://chat.ismscopilot.com/iso-27701-assistant\n- Subheading: Free AI guidance for ISO 27701 compliance.\n- Meta: Free AI assistant for ISO/IEC 27701, the privacy information management system (PIMS) standard. Ask about setting up a PIMS as a stand-alone system or on top of an existing ISO 27001 ISMS, working out PII controller and PII processor roles and the controls shared by both, the Annex A privacy controls, mapping your controls to GDPR and other privacy frameworks, handling data subject (PII principal) expectations, and building the records and evidence for certification. No account needed.\n- Framework focus: ISO/IEC 27701 privacy information management system (PIMS), a stand-alone privacy management system standard in its latest edition that can also build on an ISO/IEC 27001 ISMS, PII controller and PII processor roles, the Annex A privacy controls, and mapping to GDPR\n- Starter chips:\n  - **Set up a PIMS**: How do I set up a privacy information management system (PIMS) under ISO/IEC 27701, either as a stand-alone system or built on an existing ISO/IEC 27001 ISMS?\n  - **Controller or processor**: How do I determine whether my organization acts as a PII controller or a PII processor under ISO/IEC 27701, and which privacy controls apply to each role plus the shared ones?\n  - **Map to GDPR**: How does ISO/IEC 27701 map to GDPR obligations, and how can a PIMS help me demonstrate accountability for personal data (PII)?\n- Grounding: Seeded with ISO/IEC 27701 concepts: the privacy information management system (PIMS), which in its latest edition (ISO/IEC 27701:2025) is a stand-alone management system standard that can also build on an existing ISO/IEC 27001 ISMS, the distinction between a PII controller, a PII processor, and controls shared by both roles, the Annex A privacy controls, and the mappings that connect a PIMS to GDPR and other privacy frameworks such as ISO/IEC 29100.\n- Capabilities:\n  - Plan how to build a PIMS under ISO/IEC 27701, either as a stand-alone privacy management system or integrated with an existing (or planned) ISO/IEC 27001 ISMS, including the privacy scope, risk assessment, and Statement of Applicability.\n  - Work out whether you act as a PII controller, a PII processor, or both, and which role-specific and shared privacy controls and responsibilities apply to you.\n  - Use the PIMS-to-GDPR and related mappings to connect your controls to legal obligations, and draft the privacy policies, records (such as records of processing and data subject request handling), and evidence an auditor will expect for certification.\n- Boundary: It gives implementation guidance to speed up your work. It is not a certification body, it cannot issue ISO/IEC 27701 certification, and it is not legal advice.\n- Guide: https://www.ismscopilot.com/frameworks/iso-27701\n\n## How can I help with CCPA and CPRA?\n\n- Path: `/ccpa-assistant`\n- URL: https://chat.ismscopilot.com/ccpa-assistant\n- Subheading: Free AI guidance for CCPA and CPRA compliance.\n- Meta: Free AI assistant for the CCPA (California Consumer Privacy Act) as amended by the CPRA (California Privacy Rights Act). Ask about the applicability thresholds, the California consumer rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, the difference between selling and sharing for cross-context behavioral advertising, the Do Not Sell or Share My Personal Information link and opt-out preference signals like Global Privacy Control, notice at collection, service provider and contractor contract terms, and the records an audit or California Privacy Protection Agency (CPPA) inquiry expects. No account needed.\n- Framework focus: California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), business applicability thresholds, California consumer privacy rights, the sale and sharing of personal information and opt-outs, sensitive personal information, opt-out preference signals, and the California Privacy Protection Agency (CPPA)\n- Starter chips:\n  - **Check if it applies**: How do I work out whether the CCPA, as amended by the CPRA, applies to my business, based on doing business in California and the applicability thresholds for annual revenue, the volume of personal information handled, and revenue from selling or sharing personal information?\n  - **Handle consumer requests**: How should we set up a process to receive, verify, and respond to California consumer requests, covering the rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information?\n  - **Opt-out and GPC**: How do I handle opt-outs of the sale and sharing of personal information, including the Do Not Sell or Share My Personal Information link and honoring opt-out preference signals such as Global Privacy Control?\n- Grounding: Seeded with CCPA concepts, as amended by the CPRA: who the law applies to and the applicability thresholds, the California consumer rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, the difference between selling and sharing (including cross-context behavioral advertising), the roles of businesses, service providers, contractors, and third parties, opt-out preference signals such as Global Privacy Control, and the enforcement role of the California Privacy Protection Agency (CPPA).\n- Capabilities:\n  - Work through whether the CCPA and its CPRA amendments apply to your business, using the do-business-in-California test together with the thresholds for annual revenue, the volume of personal information handled, and revenue from selling or sharing personal information, and map which obligations follow.\n  - Design a workflow to receive, verify, and respond to consumer requests within the required timelines, covering the rights to know, delete, correct, opt out of the sale or sharing of personal information, and limit the use of sensitive personal information, plus non-discrimination for consumers who exercise them.\n  - Set up the opt-out mechanics (the Do Not Sell or Share My Personal Information link and honoring opt-out preference signals like Global Privacy Control), draft the notice at collection and privacy policy, structure service provider and contractor contract terms, and keep the records an audit or CPPA inquiry expects.\n- Boundary: It gives implementation guidance to speed up your work. It is not a substitute for legal advice, and it cannot represent you before the California Privacy Protection Agency or a court.\n- Guide: https://www.ismscopilot.com/frameworks/ccpa\n\n## How can I help with Cyber Essentials?\n\n- Path: `/cyber-essentials-assistant`\n- URL: https://chat.ismscopilot.com/cyber-essentials-assistant\n- Subheading: Free AI guidance for Cyber Essentials certification.\n- Meta: Free AI assistant for Cyber Essentials, the UK government-backed certification scheme. Ask about the five technical control themes (firewalls, secure configuration, security update management, user access control, and malware protection), preparing the verified self-assessment, applying the scoping rules for end-user devices, cloud services, home working, and BYOD, stepping up to Cyber Essentials Plus with its independent technical testing, and the annual renewal cycle. No account needed.\n- Framework focus: UK Cyber Essentials and Cyber Essentials Plus, the government-backed certification scheme developed by the NCSC and delivered through IASME, the five technical control themes (firewalls, secure configuration, security update management, user access control, malware protection), the verified self-assessment and the independent technical testing at Plus level, certification scoping including end-user devices, cloud services, home working, and BYOD, and annual recertification\n- Starter chips:\n  - **Prepare the self-assessment**: How do I prepare for the Cyber Essentials self-assessment, working through what the assessor expects under each of the five technical control themes: firewalls, secure configuration, security update management, user access control, and malware protection?\n  - **Define your scope**: How do I set the scope of my Cyber Essentials certification, when should it cover the whole organisation rather than a well-defined, separately managed sub-set, and how do the scoping rules apply to end-user devices, cloud services, home and remote working, and BYOD?\n  - **Step up to Plus**: What changes when moving from Cyber Essentials to Cyber Essentials Plus, how does the independent technical testing of in-scope devices work, and how should we prepare our configurations to pass it?\n- Grounding: Seeded with Cyber Essentials concepts: the UK government-backed scheme developed by the NCSC and delivered through IASME, the five technical control themes (firewalls, secure configuration, security update management, user access control, and malware protection), the verified self-assessment route and the independent technical testing added at Cyber Essentials Plus, the scoping rules for end-user devices, cloud services, home and remote working, and BYOD, and the 12-month certification cycle.\n- Capabilities:\n  - Prepare your self-assessment answers theme by theme, working through what good looks like for firewalls, secure configuration, security update management, user access control, and malware protection across the devices, software, and services your organisation uses.\n  - Set a defensible certification scope: the whole organisation or a well-defined, separately managed sub-set, knowing that end-user devices must be included and cloud services that hold organisational data or services cannot be excluded, and work out which home and remote working and user-owned (BYOD) devices fall in scope.\n  - Plan the step up to Cyber Essentials Plus and the annual renewal, understand the independent technical testing an assessor carries out on in-scope devices, and prepare for bids where UK public-sector buyers ask for Cyber Essentials certification.\n- Boundary: It gives preparation guidance to speed up your work. It is not a certification body, it cannot award Cyber Essentials or Cyber Essentials Plus, and it is not a substitute for assessment by a licensed certification body.\n- Guide: https://www.ismscopilot.com/frameworks/cyber-essentials\n\n## Tools\n\n### See an ISO 27001 risk analysis for your company\n\n- Path: `/iso-27001-risk-analysis`\n- URL: https://chat.ismscopilot.com/iso-27001-risk-analysis\n- Description: Free ISO 27001 risk analysis tool. Enter a company name and get an illustrative information-security risk assessment and risk register, generated live. No signup.\n- This free tool builds an illustrative ISO 27001 risk analysis for any company. Enter a company name or website and ISMS Copilot researches it, then drafts a structured information-security risk assessment in real time.\n- An ISO 27001 risk assessment identifies the threats and vulnerabilities facing your information assets, weighs their likelihood and impact, and records them in a risk register alongside treatment options and the relevant Annex A controls. This demo shows what that output can look like for your organisation.\n- It is free to use with no signup. The analysis is AI-generated from public information for illustration only, not a certified ISO 27001 or ISO 27005 assessment. For a full information security management system (ISMS), ISMS Copilot helps you build and maintain your ISO 27001 programme end to end.\n- Note: Landing copy only. Running the demo POSTs to the chat backend and is not agent-open (wallet path).\n","byteLength":29597,"servedAt":"2026-08-10T16:42:38.333Z","snapshotSource":"isms-copilot loggedOutVariants + en.json + riskDemoLanding"}