---
title: "A Guide to Proving Compliance Through Control w… | Firevault"
description: "How Control Blueprint CP-06 uses Control Modules to demonstrate control rather than only document it, what good looks like, and how a deployment is scoped."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/proving-compliance-through-control-blueprint#webpage",
      "url": "https://fire-vault.com/learn/guides/proving-compliance-through-control-blueprint",
      "name": "A Guide to Proving Compliance Through Control w…",
      "description": "How Control Blueprint CP-06 uses Control Modules to demonstrate control rather than only document it, what good looks like, and how a deployment is scoped.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fproving-compliance-through-control-blueprint.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/proving-compliance-through-control-blueprint#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/proving-compliance-through-control-blueprint#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "A Guide to Proving Compliance Through Control with a Control Blueprint",
          "item": "https://fire-vault.com/learn/guides/proving-compliance-through-control-blueprint"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "A Guide to Proving Compliance Through Control with a Control Blueprint",
      "description": "How Control Blueprint CP-06 uses Control Modules to demonstrate control rather than only document it, what good looks like, and how a deployment is scoped.",
      "url": "https://fire-vault.com/learn/guides/proving-compliance-through-control-blueprint",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fproving-compliance-through-control-blueprint.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-27T22:40:59.012961+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/proving-compliance-through-control-blueprint"
      },
      "inLanguage": "en-GB",
      "articleSection": "Guides",
      "wordCount": 503,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

About this guideThe problem this blueprint addre…CP-06 at a glanceThe primary modulesThe supporting modulesWhat good looks likeHow the blueprint is deployedHow to scope itNext stepsMore

[Guides](/learn/knowledge?filter=guides)

Guides · 27 August 2026 

# A Guide to Proving Compliance Through Control with a Control Blueprint

How Control Blueprint CP-06 uses Control Modules to demonstrate control rather than only document it, what good looks like, and how a deployment is scoped.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fproving-compliance-through-control-blueprint)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fproving-compliance-through-control-blueprint&text=A%20Guide%20to%20Proving%20Compliance%20Through%20Control%20with%20a%20Control%20Blueprint%0A%0AHow%20Control%20Blueprint%20CP-06%20uses%20Control%20Modules%20to%20demonstrate%20control%20rather%20than%20only%20document%20it%2C%20what%20good%20looks%20like%2C%20and%20how%20a%20deployment%20is%20scoped.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fproving-compliance-through-control-blueprint)[](mailto:?subject=A%20Guide%20to%20Proving%20Compliance%20Through%20Control%20with%20a%20Control%20Blueprint&body=How%20Control%20Blueprint%20CP-06%20uses%20Control%20Modules%20to%20demonstrate%20control%20rather%20than%20only%20document%20it%2C%20what%20good%20looks%20like%2C%20and%20how%20a%20deployment%20is%20scoped.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fproving-compliance-through-control-blueprint)

![A Guide to Proving Compliance Through Control with a Control Blueprint](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fproving-compliance-through-control-blueprint.jpg)

Guides 

Why it matters

## What this means for organisations holding critical data

How Control Blueprint CP-06 uses Control Modules to demonstrate control rather than only document it, what good looks like, and how a deployment is scoped.

**On this page**[About this guide](#section-0)[The problem this blueprint addre…](#section-1)[CP-06 at a glance](#section-2)[The primary modules](#section-3)[The supporting modules](#section-4)[What good looks like](#section-5)[How the blueprint is deployed](#section-6)[How to scope it](#section-7)[Next steps](#section-8)

On this page

1.  [About this guide](#section-0)
2.  [The problem this blueprint addresses](#section-1)
3.  [CP-06 at a glance](#section-2)
4.  [The primary modules](#section-3)
5.  [The supporting modules](#section-4)
6.  [What good looks like](#section-5)
7.  [How the blueprint is deployed](#section-6)
8.  [How to scope it](#section-7)
9.  [Next steps](#section-8)

## About this guide

This guide is written for security, infrastructure and risk leaders who need to demonstrate control rather than only document it. It explains one Control Blueprint, CP-06, in plain terms: the failure it addresses, the Control Modules it uses, how those modules work together, and how a deployment is scoped.

Control by Firevault is a suite of nine purpose-built modules: a set of tools and techniques that give you physical control over the paths into and across your estate. A Control Blueprint is a proven combination of those modules assembled for a specific outcome. This guide covers one blueprint. The [Control overview](/control) covers the nine modules and the full set of blueprints.

## The problem this blueprint addresses

Audit findings rarely dispute that a policy exists. They dispute whether the policy was enforced on the day in question. Where enforcement lives only in configuration, the evidence trail is reconstructed after the fact rather than produced by the control itself.

## CP-06 at a glance

-   **Lead layer** VAULT
-   **Primary modules** Validate, Lock, Archive
-   **Supporting modules** Transfer, Relay, Execute, Firebreak
-   **Typical sectors** Financial services, healthcare, public sector and [critical infrastructure](/control-for-critical-infrastructure)

## The primary modules

These modules do the work the blueprint is named for.

-   **Validate** checks the request, command or identity before anything opens.
-   **Lock** holds access to the systems that matter behind identity and condition controls.
-   **Archive** preserves logs, records and evidence beyond the reach of the live estate.

## The supporting modules

These modules round out the pattern and are usually added as the deployment matures.

-   **Transfer** governs what data is allowed to move, in which direction, and when.
-   **Relay** opens a controlled, time-bound crossing and closes it again on schedule.
-   **Execute** fires the control action on signal, without waiting for a change window.
-   **Firebreak** physically breaks the connection path, so a route only exists when it is deliberately opened.

## What good looks like

-   Every request is checked before it proceeds, and the check is recorded.
-   Access restriction can be demonstrated, not asserted.
-   Records, logs and evidence are preserved outside the reach of the estate.
-   Auditors are shown control behaviour, not control intent.

## How the blueprint is deployed

Control Modules are a suite of tools and techniques deployed within your own estate and applied to the paths they govern: at a boundary, inside a zone, or at a third-party edge. Authorisation and evidence remain local, so losing connectivity to Firevault never opens a path.

Most deployments start with a single boundary or zone, prove the control behaviour, then extend the same blueprint across the estate. Modules can be customer-operated or co-managed.

## How to scope it

Scoping starts with the paths, not the product. A short discovery exercise identifies the boundaries that matter, who needs to cross them, how often, and what evidence is required. That produces the module count and placement, which in turn produces the price. Blueprints are combined where an estate has more than one problem to solve.

## Next steps

-   Read the full blueprint detail: [CP-06 blueprint](/control-blueprints/cp-06)
-   See all nine modules and the other blueprints: [Control by Firevault](/control)
-   Talk it through with our team: [contact Firevault](/contact)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Control by Firevault governs the physical paths into your systems.**[Explore Control →](/solutions/control)

Keep a clean copy**Offline Secure Storage® holds a copy no attacker can reach.**[Why #OSS →](/why-oss)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

## Continue learning

-   [
    
    ### Cyber Risk & Compliance Guide: Controls, Evidence and Resilience for GRC Leaders
    
    How risk and compliance leaders can move from control existence to control effectiveness: risk treatment, evidence, third-party assurance, exceptions and remediation that survive audit.
    
    Read guide ](/learn/guides/cyber-risk-and-compliance-guide)
-   [
    
    ### A Guide to Containing Active Breaches with a Control Blueprint
    
    How Control Blueprint CP-02 uses Control Modules to contain a live breach physically, immediately and provably, what good looks like, and how a deployment is scoped.
    
    Read guide ](/learn/guides/containing-active-breaches-control-blueprint)
-   [
    
    ### A Guide to Stopping Kill-Chain Ransomware with a Control Blueprint
    
    How Control Blueprint CP-01 uses Control Modules to stop ransomware moving, spreading or reaching the crown jewels, what good looks like, and how a deployment is scoped.
    
    Read guide ](/learn/guides/stopping-kill-chain-ransomware-control-blueprint)
-   [
    
    ### A Guide to Enforcing Physical Segmentation with a Control Blueprint
    
    How Control Blueprint CP-04 uses Control Modules to make segmentation physically enforceable rather than only logical, what good looks like, and how a deployment is scoped.
    
    Read guide ](/learn/guides/enforcing-physical-segmentation-control-blueprint)

Related Reading

## You may also find these useful

[

![Protecting Students, Peers and Partners: A Practical Education Data Briefing](/__l5e/assets-v1/6ecf6bfc-3d28-40a7-8a6a-2d42fe36a21a/safeguarding-education-data-2026-v2-2x.jpg)

Guides 

### Protecting Students, Peers and Partners: A Practical Education Data Briefing

A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.

29 Jul 2026 13 min 







](/news/guide-safeguarding-education-data)[

![Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye](/__l5e/assets-v1/084c38b8-253b-4cc2-9056-c78a2fbd36c3/urgent-warning-triangle-20260714-2x.jpg)

Guides 

### Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye

Practical steps for serving and former politicians, councillors, campaigners, journalists, executives, broadcasters and anyone in the public eye, covering email security, device hygiene, threat handling and offline secure storage.

14 Jul 2026 22 min 







](/news/urgent-guide-protecting-personal-data-high-profile-public-eye)[

![500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fcontrolled-access-buyers-guide.jpg)

Guides 

### 500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer's Guide

In April 2026, approved researchers exfiltrated the health records, genetic data, and medical histories of 500,000 UK Biobank volunteers through authorised access channels, then listed the data for sale on Alibaba. The breach was not caused by a hack. It was caused by a model that assumes licence agreements can prevent data theft. This guide covers why that model fails and what physical controls replace it.

23 Apr 2026 18 min 







](/news/controlled-access-buyers-guide-offline-secure-storage)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Control by Firevault governs the physical paths into your systems.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up