Summary
- OneClickComply has raised £1m, taking total funding above £2.4m.
- Its software automates evidence gathering, policy work, vulnerability management, penetration testing, and configuration around common security standards.
- Demand is being driven partly by customers and supply chains making security certification a condition of doing business.
Sunderland cybersecurity company OneClickComply has raised £1 million to expand software designed to automate the administrative and technical work around security certification as cyber assurance becomes a more routine part of procurement and supplier relationships.
The investment comes from the North East Accelerate Fund managed by Mercia Ventures, alongside the Venture Sunderland Fund and Northstar EIS Growth Fund. It takes total funding in the company above £2.4 million.
OneClickComply says its platform can automate up to 90% of the work involved in standards including Cyber Essentials, ISO 27001, and SOC 2. The software monitors IT environments, gathers evidence, generates policies, manages vulnerabilities, performs elements of penetration testing, and can remediate some configuration problems.
The proposition addresses a less visible cost of cybersecurity: proving repeatedly that controls exist and remain current.
Compliance becomes part of selling
Larger organisations increasingly require suppliers to demonstrate recognised security standards before contracts are awarded. That turns certification from an occasional governance exercise into part of the commercial process.
The burden can be substantial for smaller companies without dedicated governance, risk, and compliance teams. Even a relatively focused framework requires organisations to understand which systems are in scope, how accounts are managed, whether software is patched, and how relevant controls are documented.
More extensive standards add policies, risk processes, supplier management, evidence retention, and formal audit requirements. Keeping documentation aligned with a changing technology estate can consume significant staff time.
Continuous evidence narrows the gap
OneClickComply is building around the idea that evidence should be collected from live systems rather than reconstructed immediately before an audit.
The platform connects to workplace and cloud services, checks settings against relevant controls, records evidence, and can correct some configuration issues.
That moves compliance software closer to security operations. Traditional governance tools often concentrate on documents and control mapping, while vulnerability and configuration products operate elsewhere. Combining them can reduce duplicate work if the technical evidence remains accurate.
Automated remediation also requires care. Changing a security setting can disrupt access or affect production services, so permissions, approval, logging, and rollback matter where software moves beyond reporting a problem and begins fixing it.
Certification is not the same as security
The expansion of compliance tooling also creates a risk that certification is treated as proof an organisation cannot be breached. Cyber Essentials is intended as a baseline against common attacks, while ISO 27001 demonstrates an information-security management system; neither removes operational cyber risk.
The value lies partly in consistency. A recognised standard gives buyers a common framework for assessing suppliers and can reduce the repeated questionnaires that otherwise accompany every commercial relationship.
Automation can lower the cost of maintaining that evidence if it remains connected to the systems being assessed rather than becoming another static repository.
OneClickComply currently employs 12 people and Mercia says the company has doubled monthly recurring revenue in six months. The new funding will support product development, sales, customer service, and additional hiring.
The opportunity is being created by two related pressures: businesses face more security requirements from customers and regulators, while teams have limited appetite for the manual work those requirements create. Software can narrow the gap, but only if automated compliance remains a reflection of the underlying security controls rather than a substitute for them.












