Fortify gives your business structured AI-guided assessments that tell you exactly where you stand, and a secure workspace to manage findings, track your roadmap, and get expert guidance. Free to start.
Overview
ProNext 30 days
Free to start
No credit card required
50+ frameworks
Covered in Compliance Navigator
5 assessment types
DR, GDPR, Compliance, CE+, DORA
Human review
Available on all paid assessments
Four structured assessments covering the areas that matter most. Each starts free or is available on request — no lengthy questionnaires, just an honest conversation.
A structured AI conversation across five core areas — cyber security, operational resilience, digital maturity, cloud infrastructure, and business continuity. Free to start, with human expert review available at paid tiers.
Do you have a documented incident response process — for example, a plan that sets out what to do if you're hit by ransomware or a data breach?
We have a rough process but it's not formally documented anywhere...
That's a common starting point. Does your team know who to contact first if something goes wrong — like a suspected phishing attack?
A structured GDPR assessment that identifies your exposure across all accountability requirements — from a quick free check to a full compliance programme suitable for investor due diligence and ICO scrutiny.
Do you maintain a Record of Processing Activities — a ROPA — documenting the personal data your organisation holds, its purpose, and legal basis?
We have a spreadsheet but it hasn't been updated in about 18 months...
An outdated ROPA is a common gap. Does it cover the key elements — data categories, retention periods, and third-party transfers?
Answer a few questions about your industry, location, and data handling and the Compliance Navigator maps your obligations across 50+ UK, EU, and US frameworks — GDPR, NIS2, EU AI Act, HIPAA, SOC 2, ISO 27001, and more. Free and instant.
Compliance Navigator — Acme Corp Ltd
Technology · UK + EU operations · Handles personal data · 12 employees
50+ frameworks checked · 5 apply · 2 require investigation · Results instant, no sign-up
UK GDPR
Personal data processing
AppliesICO Registration
Data controller registration
RequiredNIS2 Directive
Digital infrastructure — check scope
Check requiredISO 27001
Information security management
RecommendedEU AI Act
AI systems deployed to EU users
AppliesPECR
Electronic communications + cookies
AppliesHIPAA
US health information
Not applicableSOC 2
Enterprise customer requirements
Check requiredDORA (Regulation (EU) 2022/2554) applies to financial entities and their ICT service providers across the EU and EEA from January 2025. Our structured readiness assessment covers all five DORA pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and intelligence sharing — and gives you a control-level gap analysis before regulators come knocking.
DORA Readiness Assessment
Financial Entity · Five pillars · 25 controls
ICT Risk Management
DORA-RM · 8/8 controls
Incident Management
DORA-IR · 5/5 controls
Resilience Testing
DORA-RT · 2/4 controls
Third-Party Risk
DORA-TP · 0/6 controls
Intelligence Sharing
DORA-IS · 0/2 controls
Cyber Essentials Plus (CE+) is the UK government's independently verified cyber security certification — required for government contracts and a mark of credibility for any business handling sensitive data. Our CE+ Readiness Assessment evaluates your business against all five technical control areas so you know exactly what needs to be fixed before the formal certification audit.
CE+ Readiness Assessment
Five technical control areas · Certified practitioner review
Firewalls
Boundary and software firewalls configured correctly
Secure configuration
Default passwords changed, unnecessary software removed
User access control
Admin rights limited, accounts reviewed
Malware protection
Antivirus active and up to date on all devices
Patch management
OS and software patched within 14 days of release
The Fortify Portal is where the real work happens. Import your assessment findings, work through a prioritised action roadmap, upload evidence, collaborate with your team, and ask Alex for guidance — all in one place. Free to access with any Fortify assessment.
Overview
Next 30 days
The portal turns a static PDF report into a living programme. Manage findings, track actions, collaborate with your team, and keep the evidence that proves you did it.
Every finding from your assessment is imported into a structured workspace. Filter by risk level, status, or area. Add notes, attach evidence, and update status as you work through remediations.
Findings
14 total · 10 openEnable MFA on all admin accounts
Cyber Security
Patch Apache Log4j (CVE-2021-44228)
Cloud
Document incident response process
Operations
Review vendor access controls
Governance
Update staff security awareness training
People
Findings are automatically prioritised into a time-bound roadmap. The 30-day plan addresses critical items; 60- and 90-day phases cover the medium and longer-term work. Drag to reprioritise or mark items complete as you go.
Action Roadmap
8 actions · prioritised by risk and effort
30 days
Enable MFA on admin accounts
CriticalPatch Apache Log4j
CriticalReview firewall rules
High60 days
Document IR process
HighBCP testing exercise
HighCE+ readiness check
Medium90 days
Vendor access audit
MediumStaff security training
LowAsk Alex directly from the portal for specific, context-aware guidance on any finding. Alex knows your assessment results and gives actionable answers — not generic advice.
Ask Alex
Context: F-003 · Undocumented incident response process
Where do I start with writing an incident response plan?
Based on your assessment — Acme Corp Ltd
1. Assign an Incident Coordinator — a named person who owns response, not just IT. For your size, this is likely the CEO or IT lead.
2. Define four severity tiers — P1 (business-stopping), P2 (major impact), P3 (minor disruption), P4 (near-miss). This shapes your notification duties.
3. Map your notification requirements — ICO within 72h for P1/P2 data breaches. NCSC for ransomware. These are legal obligations, not optional.
Attach policies, certificates, screenshots, or any supporting document directly to a finding. Evidence is stored securely and available to auditors, investors, or clients. Pro and Annual plans include bulk ZIP export.
Evidence
F-002 · Patch management process
patch-policy-v2.pdf
128 KB · Added 14 Jun
wsus-config-screenshot.png
340 KB · Added 14 Jun
approved-by-cto.docx
45 KB · Added 12 Jun
Drop files here or browse
Invite colleagues, consultants, or board members with role-based access. Owners and admins manage the workspace; contributors update statuses and add notes; read-only members view everything without changes.
Team
3 membersJason Gillan
jason@acme.co.uk
Sarah Chen
sarah@acme.co.uk
Tom Richards
tom@acme.co.uk
See how your scores compare to similar businesses in your industry. A quarterly PDF review is automatically generated so you can track progress over time and share results with stakeholders.
Sector Benchmarks
Technology · SME · UK · Digital Resilience
Q2 2026 Review
ReadyYour quarterly PDF report includes score progression, peer comparison, and a prioritised recommendation summary for stakeholders.
The Policy Engine generates complete, section-structured policy documents — Privacy Policies, Data Protection Policies, Incident Response Plans, and more — tailored to your organisation and regulation scope. When the ICO, NCSC, or FCA publishes guidance updates, Fortify flags the affected sections and offers AI-suggested patches you can review, accept, or dismiss.
Privacy Policy
UK GDPR · PECR · Version 1 · Annual review
Regulation update — ICO updated consent guidance · 2 sections flagged for review
Review →Sections · 5
This Privacy Policy describes how Acme Corp Ltd (“we”, “us”) collects, uses, and protects your personal data under the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR).
We are the data controller for the purposes of UK GDPR. Our registered office is at 12 Innovation Street, London, EC1A 1BB.
When something goes wrong, the clock starts immediately. The Incident Log gives you a structured workspace to capture what happened, assign CAPA (Corrective and Preventive Actions), track resolution, and meet notification deadlines. When you need guidance fast, the AI assistant analyses the incident and returns immediate steps, root cause hypotheses, regulatory notification requirements, and a resolution checklist — specific to your incident type and severity.
Phishing email opened by staff member
Phishing Attack · 2 CAPA
CRM access from unknown IP address
Unauthorized Access
AWS S3 bucket misconfiguration
Security Incident · 3 CAPA
Third-party supplier data request
Compliance Violation · 1 CAPA
AI response advisory — CRM access from unknown IP
⚡ Immediate: Terminate active sessions, force password reset, enable MFA
📣 Notify: ICO notification required within 72h if PII accessed
🔧 CAPA: Implement geo-restriction on CRM access · Audit login history
Playbooks are step-by-step response templates for specific incident types — Ransomware, Data Breach, Phishing, System Outage, and more. Assign a playbook when you log an incident so your team has a clear, consistent response from the first minute. Build your own, or use Fortify system playbooks as a starting point.
Ransomware Response playbook
Isolate affected systems
Notify key stakeholders
Preserve forensic evidence
Assess encryption scope
Report to NCSC / ICO if required
Begin recovery from clean backups
Supply chain breaches are increasingly the root cause of compliance failures and operational outages — and most businesses have no visibility of the risk sitting in their vendor stack. The Vendor Risk add-on monitors your third parties for CVE exposure, analyses vulnerabilities with AI, maintains your ROPA for GDPR purposes, and gives you a structured vendor risk register that's always up to date.
Supply Chain Risk
5 vendors · 4 CVEs trackedLog4Shell (CVE-2021-44228) affects 1 vendor — patch required immediately
Triage →AWS
Cloud
Salesforce
CRM
Log4j dependency
Dev tooling
Stripe
Payments
Slack
Comms
ISO 27001 Readiness Audit
Acme Corp Ltd · Annex A controls · 5 sections shown
Information Security Policies
A.5 · 4/4 controls
Organisation of Info Security
A.6 · 7/7 controls
Asset Management
A.8 · 5/8 controls
Access Control
A.9 · 0/14 controls
Operations Security
A.12 · 0/14 controls
Compliance Audits gives you a formal, control-level audit workspace for the frameworks that matter most to UK businesses — ISO 27001, Cyber Essentials Plus (CE+), and DORA. Work through each section systematically, attach evidence, track progress, and produce an audit-ready report when you're done. Run as many times as you need — every re-assessment tracks your progress over time.
Certification requires more than a gap assessment. The ISO 27001 ISMS Toolkit gives you a fully integrated set of tools covering every clause: risk register with AI generation and treatment planning, Statement of Applicability with PDF export ready for your certification body, internal audit programme, management review records, IS objectives, and information asset register. Everything connected in one place, not spread across spreadsheets.
ISO 27001 ISMS
Acme Corp Ltd · 2026 programme
Risk Register
14 risks tracked
Statement of Applicability
93 controls reviewed
Audit Programme
2026 programme active
Management Reviews
ISO 27001 Cl 9.3
SoA export ready
All 93 Annex A controls reviewed · PDF available for your certification body
Agreements
4 agreements · 1 pendingHelix Partners NDA expired 4 Dec 2025 — renewal required
Apex Technologies Ltd
12 Mar 2026
Salesforce Inc
1 Jan 2026
Orbit Digital Ltd
18 Jul 2026
Helix Partners
4 Dec 2025
AI extraction active
Key terms, dates, and obligations extracted from uploaded documents — confidence-scored for review
Agreements & Contract Intelligence gives you a single workspace for every NDA, DPA, and MSA your business manages. Upload existing documents and let AI extract key terms, dates, and obligations — confidence-scored so you know what to verify. Draft new NDAs and DPAs in seconds from your organisation profile. Send for e-signing without leaving the platform. DPAs link directly to your ROPA for GDPR accountability.
The action roadmap gives every business a prioritised list of what to do next. The Action Plan takes that further — it's a formal programme management layer where you assign tasks to named team members, allocate time, set deadlines, and track progress on a Gantt timeline. Built for businesses that need to show stakeholders, auditors, or investors that remediation is actively resourced and progressing.
Action Plan — Q3 2026
AnnualEnable MFA on all admin accounts
Document incident response plan
CE+ firewall configuration review
Staff security awareness training
Every assessment starts free. Paid tiers add human expert review and strategic outputs. The portal is free to access and scales with your team.
Cyber security, operational resilience, cloud, and digital maturity across your business.
Foundations Check
Get an instant picture of your digital resilience
Report: Automated summary
Essential Diagnostic
AI assessment with human-verified findings and quick wins
Report: 2–3 page findings report
Review: Light review (30–45 mins)
Session: Optional 20-min call
Strategic Resilience Diagnostic
Full expert review with a founder session and strategic roadmap
Report: 5–7 page strategic roadmap
Review: Full expert review (3–5 hours)
Session: 60–90 min founder session
Advanced Resilience Diagnostic
Deep diagnostic plus hands-on implementation planning
Report: 8–10 page roadmap and implementation plan
Review: Full review + implementation planning
Session: Two sessions: diagnostic + implementation
From a quick exposure check to a full compliance programme ready for investor due diligence.
Are we exposed?
Find out in 10 minutes whether your business has GDPR blind spots
Report: Automated summary
Are we doing the basics right?
Structured review of your GDPR foundations with human-verified findings
Report: 2–3 page gap report
Review: Light review (30–45 mins)
Are we safe to grow?
Assess whether your data practices are ready to scale safely
Report: 5–7 page compliance roadmap
Review: Full expert review (2–3 hours)
Session: 60-minute review session
Are we investor and audit ready?
Full compliance programme ready for due diligence, audits, and ICO scrutiny
Report: 8–10 page compliance programme
Review: Full review + implementation planning
Session: Two sessions: assessment and planning
CE+ readiness audit built into the Fortify Portal — evaluate all five control areas and know exactly what to fix before certification.
CE+ Readiness Assessment
Cyber Essentials Plus is the UK government's independently verified cyber security certification — required for public sector contracts and widely recognised as the credibility benchmark for handling sensitive data. Our CE+ Readiness module evaluates your organisation against all five technical control areas — firewalls, secure configuration, user access, malware protection, and patch management — so you know exactly what needs to be fixed before the formal certification audit.
Included in portal subscription
£99 / month
or £3,999 / yearPro and Annual plans · Unlimited re-assessments · Evidence vault included
Access via portalAI-guided readiness assessment
An AI practitioner works through all five CE+ control areas with your team, gathering evidence of your current configuration and controls.
Control-level verdicts
Each control area is assessed as pass, gap, or partial — with structured notes on what is missing and why it matters.
Gap analysis report
A prioritised remediation report identifying every control that would fail the formal CE+ audit and what to do to fix it.
Evidence vault
Attach screenshots, policies, and configuration exports directly to each control area within the portal.
Remediation tracking
Work through identified gaps in the portal, attaching evidence and updating status as you close each one.
Unlimited re-assessments
Run a new CE+ readiness check at any time — useful after remediation work or prior to booking your formal certification audit.
Who needs CE+?
Any UK business bidding for public sector or government contracts must hold Cyber Essentials Plus certification. It is also increasingly required by enterprise clients and insurance underwriters as a condition of cover.
Structured AI-guided readiness assessment across all five DORA pillars. Applicable from January 2025.
DORA Readiness Assessment
DORA (Regulation (EU) 2022/2554) has applied since January 2025 and covers financial entities — banks, payment institutions, insurers, investment firms, crypto-asset service providers — and the ICT providers that supply them. Our assessment evaluates your readiness across all five DORA pillars and gives you a clear picture of what needs to be in place before regulatory scrutiny.
Scope selection
Tailored for financial entities or ICT third-party service providers — the assessment adapts to your regulatory position.
Five-pillar AI assessment
An AI compliance specialist (Morgan Clarke) works through each DORA pillar section by section, gathering evidence of your current controls.
Control-level verdicts
Each of the 22 controls is assessed as compliant, partial, or non-compliant, with structured notes.
Evidence vault
Attach policy documents, screenshots, and configuration exports directly to each control within the portal.
Readiness score
An overall DORA readiness score and per-pillar breakdown, updated as you work through sections.
Unlimited re-assessments
Run a new audit at any time — useful after remediation work or prior to a regulatory inspection.
Who is DORA for?
DORA applies to regulated financial entities operating in the EU/EEA, and to ICT service providers that supply critical or important functions to those entities — regardless of where the ICT provider is based.
Track findings, manage your roadmap, collaborate with your team. Free to access with any assessment.
Free
1 user included
Lite
1 seat included · +£49/mo per extra
Pro
1 seat included · +£99/mo per extra
Annual
1 seat included · +£250/mo per extra
Portal prices exclude VAT. Seats can be added or removed at any time — Stripe prorates the charge automatically.
An honest, expert-quality picture of your business in under ten minutes. No sign-up, no credit card, no jargon.
Already have an account? Sign in to the portal →