Custom Frameworks
Spartacus Insights' Custom Frameworks helps organisations and consultancies operationalise proprietary, internal, hybrid, sector-specific and emerging assurance frameworks within the same governed platform used for recognised standards. It provides the structure and repeatability needed to apply bespoke methodologies consistently across teams, clients and multi-year programmes.

How do you scale your own cybersecurity framework or methodology without losing consistency, credibility, or control?
The challenge is rarely defining a custom framework. It is preserving the consistency, durability, and trust that framework needs as it is applied across teams, clients, and delivery cycles over time.
Spartacus Insights' Custom Frameworks helps organisations and consultancies preserve the integrity of bespoke methodologies as they scale, giving them a governed way to apply custom frameworks consistently across teams, clients, and delivery cycles.
Bespoke frameworks often begin with strong intent and expert ownership, but as delivery expands they are frequently managed through spreadsheets, emails, and one-off tooling. Interpretation starts to vary, evidence fragments, reporting diverges, and confidence shifts from structure to individuals.
What becomes difficult is executing those requirements consistently at scale, without reinterpretation, drift, or dependence on specific people. Spartacus addresses that problem by making proprietary and internal frameworks governed by configuration rather than dependent on ad hoc delivery, helping them scale without being diluted, reinvented, or weakened under scrutiny.
Spartacus Insights provides the tools to create and operate custom frameworks within the same governed lifecycle used across the platform. This allows proprietary and internal methodologies to be delivered through a structured assessment, analysis, reporting, project, and trend model rather than through fragmented tools or one-off processes.
In practice, that means organisations and consultancies can apply bespoke frameworks with stronger traceability, more consistent analysis and reporting, clearer linkage into projects, visibility over time, and controlled sharing of approved outputs.












Custom Frameworks is built into the same governed methodology used to deliver recognised standards. This means bespoke frameworks benefit from the same structured assessment, analysis, reporting, and long-term delivery discipline as the recognised framework products supported in Spartacus.
Assess cybersecurity posture using a widely adopted framework for understanding current state, target state and improvement priorities.
Support a more structured view of ISMS maturity across clauses and Annex A controls, with stronger evidence, reporting, and visibility.
Evaluate practical cybersecurity safeguards in a more consistent and actionable way, with clearer visibility of implementation gaps and priorities.
Support a more structured approach to CMMC readiness, with clearer evidence, defensible reporting and stronger visibility of gaps.
Bring ICT risk, incident readiness, resilience testing and third-party dependency into a clearer digital operational resilience view.
Make management accountability, supplier assurance, incident readiness and resilience themes easier to evidence and explain.
AI adoption is moving quickly, but assurance often struggles to keep pace. Spartacus Insights provides a governed route for bringing AI governance and secure AI system delivery into a structured, evidence-backed assessment model through Custom Frameworks. The two routes can be used separately or together, depending on the assurance need.
Aligned to the NIST AI RMF, AI Risk Management helps assess whether AI risk is governed, owned, measured, managed and reviewed through accountable oversight and evidence-backed decision-making.
Aligned to NCSC Secure AI System Development guidance, this Custom Framework helps assess whether AI-enabled systems are designed, developed, deployed, operated and maintained with appropriate security practices, evidence and review discipline.
Custom Frameworks is designed for organisations and consultancies that need to run proprietary, internal, hybrid, or sector-specific methodologies as governed, repeatable frameworks rather than informal delivery models.
It is especially useful for consultancy teams protecting proprietary IP, internal teams formalising bespoke assessment approaches, and organisations that need custom frameworks to operate with the same discipline as recognised standards.
Custom Frameworks is not a workaround for unsupported standards, a loose survey builder, or an informal way to manage bespoke methodologies outside the main platform. It is a governed product capability designed to operationalise custom frameworks with the same structure, repeatability, and discipline applied across Spartacus.
It is also not dependent on individual delivery habits or one-off tooling. Its value lies in preserving the intent, integrity, and usability of bespoke methodologies as they scale across teams, clients, and delivery cycles.
Explore productised capabilities that support clearer decisions across supplier assurance, quantitative risk, threat-informed protection, control investment and Custom Frameworks.