2026.01
- Testing of backups has been removed from P11-ILv.1 and rolled into P5 to address Issue #2.
- The order of P5 has been modified. ILv.2 and ILv.3 have been swapped, backups are now required at ILv.2, need to know access controls are moved to ILv.3.
- The scope of backup now required under P5-ILv.2 has been broadened from just data in cloud applications to all important data.
- P11-ILv.1 has been replaced with a new requirement to “Know where to get help”, which aims to ensure very small businesses with no regular IT or cybersecurity support have arrangements in place for professional assistance at least in the case of an incident.
- GUIDANCE.md has been updated to reflect the above changes to the SPECIFICATION.
- The self assessment spreadsheet was also updated with a more functional version. This was pushed to main out of the regular schedule as only a very early draft was mistakenly included in the 2025-07 update.
- Italian Translation added! Repository file structure has been adjusted as per description in Issue #4
2025.07
- Clarifications to completion criteria and guidance for P1-ILv2 & -ILv3.
- Documented mapping of data assets to relevant business roles added to completion criteria for P5-ILv2
- Simple attestation badges added.
- Version numbers added to attestation badges.
- Typos & grammatical errors fixed.
BETA RELEASE (2025-05)
- Initial public draft.