Case study
Desucla & YDC.is

Desucla: From strong foundations to independent security assurance

Desucla provides technology for managing tax representation, filing and payments across jurisdictions. YDC helped Desucla formalise its security programme, achieve Cyber Essentials and Cyber Essentials Plus, and develop and operate an ISO 27001-aligned information security management system.

Certification path
01

Cyber Essentials

Baseline verified

02

Cyber Essentials Plus

Hands-on audit passed

03

ISO 27001

Full ISMS accredited

Desucla security compliance and certification roadmap
Verified outcome

Certified across Cyber Essentials, Cyber Essentials Plus, and ISO 27001.

Industry

Fiscal & VAT technology

Timeline

Multi-stage rollout

Outcome

ISO 27001 accredited.

Case Background

Desucla's starting point

Desucla operates a platform supporting tax compliance across multiple jurisdictions and works with organisations that expect high confidence around information management.

Security was already an established consideration. The next step was to bring more structure to the existing work and achieve recognised, independently assessed standards.

Foundation already in place
Security was already an established consideration.
Stronger security structure
Existing work needed to become a consistent security programme.
Independent assurance
Desucla wanted recognised standards alongside the broader security management system.
Programme Transition

From existing security work to a working security programme

YDC helped Desucla turn existing security considerations into a structured programme covering risk, controls, evidence and ongoing management.

Engagement Pillars

What the engagement involved.

01
Foundation
Foundation
Building on what was already in place: formalised existing work into a consistent security programme covering risk management, asset and information management, supplier oversight, access control, incident management, business continuity, staff awareness and evidence.
02
Technical assurance
Cyber Essentials and Cyber Essentials Plus
Worked through the technical environment and remediation required to achieve Cyber Essentials and Cyber Essentials Plus, providing independent technical assurance.
03
Management system
ISO 27001
Developed and operated an Information Security Management System covering risk management, internal audit, management review, business continuity testing, supplier assurance, policy development and evidence collection, preparing Desucla for independent assessment.
Case in point: Desucla

The outcome.

Desucla achieved Cyber Essentials, Cyber Essentials Plus and ISO 27001 certification. More importantly, the engagement established a working security management system behind those certifications. Risks are reviewed, responsibilities are understood, evidence is collected, controls are tested and security decisions have a clear place to live.

Risks reviewed
Responsibilities understood
Evidence collected
Controls tested
“Certification was a milestone. It was never intended to be the end of the work. We continue to work with Desucla as an ongoing security consultancy partner.”

Desucla — cross-jurisdictional tax compliance technology

Ready to clear client security questionnaires with confidence?

Explore our certification frameworks or talk to a compliance consultant today.

Common questions

Frequently asked questions

Clear answers about certification paths, governance requirements, and scoping your security audit.

Not necessarily. Cyber Essentials and ISO 27001 address different aspects of security assurance. For Desucla, Cyber Essentials and Cyber Essentials Plus provided useful independent technical assurance alongside the broader ISO 27001 management system. Other organisations may take a different route depending on their requirements.

Tailored compliance support

Security assurance gets easier when the work joins up.

Cyber Essentials, Cyber Essentials Plus, ISO 27001, customer questionnaires and supplier reviews do not need to become separate programmes. YDC helps organisations build one sensible security system around the requirements that matter to their business.

ISO 27001 support
Resources & guides

Related reading and case studies

Explore how we help teams structure questionnaire responses, close compliance gaps, and satisfy security reviews.

Frameworks & Standards
Security certifications overview
Understand the key compliance standards, what auditors inspect, and how to prepare your team for verification.
Implementation Support
ISO 27001 support and readiness
A structured approach to building your Information Security Management System (ISMS) without unnecessary paperwork.