AI assessments · Secure portal · Expert review

From assessment to action — everything in one platform

Fortify gives your business structured AI-guided assessments that tell you exactly where you stand, and a secure workspace to manage findings, track your roadmap, and get expert guidance. Free to start.

fortify.bluecipher.co.uk/portal/org/acme
Acme Corp Ltd
Overview
Findings
Roadmap
Risk Register
Policies
Supply Chain
Incidents
Audits
Agreements
Action Plan
Ask Alex
Team

Overview

Pro
2 critical CVEs affecting your software stack — action requiredView →
Findings
14
Critical
2
Open
8
Score
62

Next 30 days

Enable MFA on all admin accounts
Document incident response plan
Review vendor CVE exposure
Complete ISO 27001 audit section A.8

Free to start

No credit card required

50+ frameworks

Covered in Compliance Navigator

5 assessment types

DR, GDPR, Compliance, CE+, DORA

Human review

Available on all paid assessments

Assessments

Know exactly where your business stands

Four structured assessments covering the areas that matter most. Each starts free or is available on request — no lengthy questionnaires, just an honest conversation.

Digital ResilienceAssessment

How well can your business withstand digital threats and disruption?

A structured AI conversation across five core areas — cyber security, operational resilience, digital maturity, cloud infrastructure, and business continuity. Free to start, with human expert review available at paid tiers.

  • Covers cyber security, cloud, operations, and business continuity
  • AI-guided conversation — no forms, no jargon
  • Personalised PDF report with prioritised next steps
  • Human consultant review at paid tiers
  • Findings sync directly into the Fortify Portal
Start free assessmentFree · No sign-up required
Alex Morgan · Digital ResilienceStep 3 of 5
AM

Do you have a documented incident response process — for example, a plan that sets out what to do if you're hit by ransomware or a data breach?

We have a rough process but it's not formally documented anywhere...

AM

That's a common starting point. Does your team know who to contact first if something goes wrong — like a suspected phishing attack?

Type your answer...
GDPR ComplianceAssessment

Does your business have GDPR blind spots that could cost you?

A structured GDPR assessment that identifies your exposure across all accountability requirements — from a quick free check to a full compliance programme suitable for investor due diligence and ICO scrutiny.

  • Structured across all GDPR accountability requirements
  • Identifies high-risk gaps with plain-English explanations
  • Human Data Protection Consultant review at paid tiers
  • Investor and auditor-ready outputs at Tier 2 and above
  • Findings sync directly to the Fortify Portal
Start free GDPR checkFree · No sign-up required
Morgan Clarke · GDPR AssessmentStep 2 of 6
MC

Do you maintain a Record of Processing Activities — a ROPA — documenting the personal data your organisation holds, its purpose, and legal basis?

We have a spreadsheet but it hasn't been updated in about 18 months...

MC

An outdated ROPA is a common gap. Does it cover the key elements — data categories, retention periods, and third-party transfers?

Type your answer...
Compliance NavigatorFree tool

Which regulations and certifications actually apply to your business?

Answer a few questions about your industry, location, and data handling and the Compliance Navigator maps your obligations across 50+ UK, EU, and US frameworks — GDPR, NIS2, EU AI Act, HIPAA, SOC 2, ISO 27001, and more. Free and instant.

  • 50+ regulations and certifications checked in one pass
  • UK, EU, and US coverage simultaneously
  • Personalised AI explanations for each applicable framework
  • Instant results — no account required
Map my compliance obligationsFree · No sign-up required

Compliance Navigator — Acme Corp Ltd

Technology · UK + EU operations · Handles personal data · 12 employees

50+ frameworks checked · 5 apply · 2 require investigation · Results instant, no sign-up

UK GDPR

Personal data processing

Applies

ICO Registration

Data controller registration

Required

NIS2 Directive

Digital infrastructure — check scope

Check required

ISO 27001

Information security management

Recommended

EU AI Act

AI systems deployed to EU users

Applies

PECR

Electronic communications + cookies

Applies

HIPAA

US health information

Not applicable

SOC 2

Enterprise customer requirements

Check required
DORA ReadinessAssessment

Is your organisation ready for DORA regulatory scrutiny?

DORA (Regulation (EU) 2022/2554) applies to financial entities and their ICT service providers across the EU and EEA from January 2025. Our structured readiness assessment covers all five DORA pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and intelligence sharing — and gives you a control-level gap analysis before regulators come knocking.

  • Covers all five DORA pillars across 22 specific controls
  • Scope-tailored for financial entities or ICT third-party providers
  • Control-level verdicts: compliant, partial, or non-compliant
  • Evidence vault for policies, configurations, and test results
  • Unlimited re-assessments included in the subscription
Access via portal£99 / month · 12-month subscription

DORA Readiness Assessment

Financial Entity · Five pillars · 25 controls

52% complete

ICT Risk Management

DORA-RM · 8/8 controls

Complete

Incident Management

DORA-IR · 5/5 controls

Complete

Resilience Testing

DORA-RT · 2/4 controls

In progress

Third-Party Risk

DORA-TP · 0/6 controls

Not started

Intelligence Sharing

DORA-IS · 0/2 controls

Not started
Cyber Essentials Plus ReadinessAssessment

Are you ready for Cyber Essentials Plus certification?

Cyber Essentials Plus (CE+) is the UK government's independently verified cyber security certification — required for government contracts and a mark of credibility for any business handling sensitive data. Our CE+ Readiness Assessment evaluates your business against all five technical control areas so you know exactly what needs to be fixed before the formal certification audit.

  • Assessed against all five CE+ technical control areas
  • Firewalls, secure configuration, user access, malware protection, patching
  • Gap analysis report identifying audit-fail risks
  • Prioritised remediation plan with timelines
  • Human-reviewed by a certified CE+ practitioner
Access via portalPro and Annual plans · From £99 / month

CE+ Readiness Assessment

Five technical control areas · Certified practitioner review

Firewalls

Boundary and software firewalls configured correctly

Pass

Secure configuration

Default passwords changed, unnecessary software removed

Pass

User access control

Admin rights limited, accounts reviewed

Pass

Malware protection

Antivirus active and up to date on all devices

Gap found

Patch management

OS and software patched within 14 days of release

Gap found
Fortify Portal

A secure workspace to manage everything after your assessment

The Fortify Portal is where the real work happens. Import your assessment findings, work through a prioritised action roadmap, upload evidence, collaborate with your team, and ask Alex for guidance — all in one place. Free to access with any Fortify assessment.

Structured findings management
30/60/90-day action roadmap
Ask Alex for guidance
Team collaboration
Evidence uploads
Policy engine (Pro)
Incident log & playbooks (Pro)
Vendor register (Pro+)
Supply chain risk — Vendor Risk add-on
Compliance Audits — CE+, DORA, ISO 27001 (Pro)
ISO 27001 ISMS toolkit — SoA, risk register, audit programme (Pro)
Agreement & Contract Intelligence — NDA, DPA, MSA (Pro)
Sector benchmarks (Pro)
Action Plan & Gantt (Annual)
fortify.bluecipher.co.uk/portal
Acme Corp Ltd
Overview
Findings
Roadmap
Policies
Ask Alex
Team

Overview

Total
14
Open
5
Resolved
3

Next 30 days

Enable MFA on all admin accounts
Document incident response plan
Review vendor access controls
Portal features

Everything you need to act on your assessment

The portal turns a static PDF report into a living programme. Manage findings, track actions, collaborate with your team, and keep the evidence that proves you did it.

Findings management

Every finding from your assessment is imported into a structured workspace. Filter by risk level, status, or area. Add notes, attach evidence, and update status as you work through remediations.

Findings

14 total · 10 open
AllCriticalHighMediumLow
Search findings...
Critical

Enable MFA on all admin accounts

Cyber Security

Open
High

Patch Apache Log4j (CVE-2021-44228)

Cloud

In Progress
High

Document incident response process

Operations

Open
Medium

Review vendor access controls

Governance

In Review
Low

Update staff security awareness training

People

Planned

30/60/90-day action roadmap

Findings are automatically prioritised into a time-bound roadmap. The 30-day plan addresses critical items; 60- and 90-day phases cover the medium and longer-term work. Drag to reprioritise or mark items complete as you go.

Action Roadmap

8 actions · prioritised by risk and effort

30 days

Enable MFA on admin accounts

Critical

Patch Apache Log4j

Critical

Review firewall rules

High

60 days

Document IR process

High

BCP testing exercise

High

CE+ readiness check

Medium

90 days

Vendor access audit

Medium

Staff security training

Low

Ask Alex — your on-demand advisor

Ask Alex directly from the portal for specific, context-aware guidance on any finding. Alex knows your assessment results and gives actionable answers — not generic advice.

AX

Ask Alex

Context: F-003 · Undocumented incident response process

Where do I start with writing an incident response plan?

AX

Based on your assessment — Acme Corp Ltd

1. Assign an Incident Coordinator — a named person who owns response, not just IT. For your size, this is likely the CEO or IT lead.

2. Define four severity tiers — P1 (business-stopping), P2 (major impact), P3 (minor disruption), P4 (near-miss). This shapes your notification duties.

3. Map your notification requirements — ICO within 72h for P1/P2 data breaches. NCSC for ransomware. These are legal obligations, not optional.

Ask about this finding...

Evidence uploads

Attach policies, certificates, screenshots, or any supporting document directly to a finding. Evidence is stored securely and available to auditors, investors, or clients. Pro and Annual plans include bulk ZIP export.

Evidence

F-002 · Patch management process

3 files

patch-policy-v2.pdf

128 KB · Added 14 Jun

wsus-config-screenshot.png

340 KB · Added 14 Jun

approved-by-cto.docx

45 KB · Added 12 Jun

Drop files here or browse

Team collaboration

Invite colleagues, consultants, or board members with role-based access. Owners and admins manage the workspace; contributors update statuses and add notes; read-only members view everything without changes.

Team

3 members
JG

Jason Gillan

jason@acme.co.uk

Owner
SC

Sarah Chen

sarah@acme.co.uk

Admin
TR

Tom Richards

tom@acme.co.uk

Contributor
colleague@company.com
Role ▾
Invite

Sector benchmarks & quarterly review (Pro)

See how your scores compare to similar businesses in your industry. A quarterly PDF review is automatically generated so you can track progress over time and share results with stakeholders.

Sector Benchmarks

Technology · SME · UK · Digital Resilience

Your score62/100
Sector average58/100
Top quartile78/100

Q2 2026 Review

Ready

Your quarterly PDF report includes score progression, peer comparison, and a prioritised recommendation summary for stakeholders.

Download Q2 PDF
Policy EnginePro · Annual

AI-generated policies that stay current with your regulatory obligations

The Policy Engine generates complete, section-structured policy documents — Privacy Policies, Data Protection Policies, Incident Response Plans, and more — tailored to your organisation and regulation scope. When the ICO, NCSC, or FCA publishes guidance updates, Fortify flags the affected sections and offers AI-suggested patches you can review, accept, or dismiss.

  • Generate 20+ policy types from your organisation profile and regulation scope
  • Every section tagged to specific frameworks — UK GDPR, CE+, ISO 27001, and more
  • Weekly regulation monitoring — ICO, NCSC, and FCA feeds tracked automatically
  • AI-suggested edits when regulation guidance changes — accept or dismiss per section
  • Configurable review cycles — monthly, quarterly, or annual reminders
  • Approval workflow before publishing — designate a reviewer or approve as owner
Start with Pro planFrom £99 / month · Pro and Annual plans

Privacy Policy

UK GDPR · PECR · Version 1 · Annual review

Draft
Publish

Regulation update — ICO updated consent guidance · 2 sections flagged for review

Review →

Sections · 5

Introduction
Lawful basis for processing
Consent & cookies
Your data rights
Contact & complaints
+ Add section
uk-gdprpecr

This Privacy Policy describes how Acme Corp Ltd (“we”, “us”) collects, uses, and protects your personal data under the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR).

We are the data controller for the purposes of UK GDPR. Our registered office is at 12 Innovation Street, London, EC1A 1BB.

Next review: Jun 2027
Incident LogPro · Annual

Log, investigate, and close incidents — with AI-guided response at every step

When something goes wrong, the clock starts immediately. The Incident Log gives you a structured workspace to capture what happened, assign CAPA (Corrective and Preventive Actions), track resolution, and meet notification deadlines. When you need guidance fast, the AI assistant analyses the incident and returns immediate steps, root cause hypotheses, regulatory notification requirements, and a resolution checklist — specific to your incident type and severity.

  • Log any incident type — breach, outage, phishing, ransomware, compliance
  • Full status lifecycle: Open → Investigating → Contained → Resolved → Closed
  • CAPA management — corrective and preventive actions with due dates
  • AI response advisory: immediate steps, root causes, CAPA suggestions
  • ICO, NCSC, and FCA notification requirements flagged automatically
  • Resolution checklist and timeline of events
Start with Pro planFrom £99 / month · Pro and Annual plans
Incident Log
2 open1 investigating
high

Phishing email opened by staff member

Phishing Attack · 2 CAPA

investigating
critical

CRM access from unknown IP address

Unauthorized Access

open
medium

AWS S3 bucket misconfiguration

Security Incident · 3 CAPA

contained
low

Third-party supplier data request

Compliance Violation · 1 CAPA

resolved

AI response advisory — CRM access from unknown IP

⚡ Immediate: Terminate active sessions, force password reset, enable MFA

📣 Notify: ICO notification required within 72h if PII accessed

🔧 CAPA: Implement geo-restriction on CRM access · Audit login history

PlaybooksPro · Annual

Response playbooks: your team always knows what to do

Playbooks are step-by-step response templates for specific incident types — Ransomware, Data Breach, Phishing, System Outage, and more. Assign a playbook when you log an incident so your team has a clear, consistent response from the first minute. Build your own, or use Fortify system playbooks as a starting point.

  • Create playbooks for any incident type
  • Multi-step templates with role assignments
  • Fortify system playbooks included — ready to use
  • Attach a playbook at incident creation or any time during investigation

Ransomware Response playbook

Isolate affected systems

IT Manager

Notify key stakeholders

CEO / DPO
3

Preserve forensic evidence

IT Manager
4

Assess encryption scope

IT Manager
5

Report to NCSC / ICO if required

DPO
6

Begin recovery from clean backups

IT Manager
Supply Chain RiskVendor Risk add-on

Know exactly which vendors put you at risk — and when a new CVE changes that

Supply chain breaches are increasingly the root cause of compliance failures and operational outages — and most businesses have no visibility of the risk sitting in their vendor stack. The Vendor Risk add-on monitors your third parties for CVE exposure, analyses vulnerabilities with AI, maintains your ROPA for GDPR purposes, and gives you a structured vendor risk register that's always up to date.

  • Vendor risk register — document, categorise, and score all third parties
  • Threat monitoring — tracked vulnerabilities mapped to your vendor software stack
  • AI CVE analysis — instant risk assessment and remediation guidance per CVE
  • ROPA management — Record of Processing Activities for GDPR accountability
  • Automated CVE alerts — notified when a critical vulnerability affects a vendor
  • Supply chain assessment reports — export for auditors, investors, or clients
Start with Pro plan£49/month add-on · Requires Pro or above · Included on Annual

Supply Chain Risk

5 vendors · 4 CVEs tracked

Log4Shell (CVE-2021-44228) affects 1 vendor — patch required immediately

Triage →
AW

AWS

Cloud

Low
SA

Salesforce

CRM

1 CVEMedium
LO

Log4j dependency

Dev tooling

3 CVEsCritical
ST

Stripe

Payments

Low
SL

Slack

Comms

Low

ISO 27001 Readiness Audit

Acme Corp Ltd · Annex A controls · 5 sections shown

48% complete

Information Security Policies

A.5 · 4/4 controls

Complete

Organisation of Info Security

A.6 · 7/7 controls

Complete

Asset Management

A.8 · 5/8 controls

In progress

Access Control

A.9 · 0/14 controls

Not started

Operations Security

A.12 · 0/14 controls

Not started
Compliance AuditsPro · Annual

Structured compliance audits — self-assessment built for certification readiness

Compliance Audits gives you a formal, control-level audit workspace for the frameworks that matter most to UK businesses — ISO 27001, Cyber Essentials Plus (CE+), and DORA. Work through each section systematically, attach evidence, track progress, and produce an audit-ready report when you're done. Run as many times as you need — every re-assessment tracks your progress over time.

  • ISO 27001 (Annex A controls), Cyber Essentials Plus (CE+), and DORA — frameworks updated regularly
  • Section-by-section structure with control-level verdicts
  • Evidence vault — attach policies and configurations to each control
  • Progress tracking — completion percentage and gap summary at a glance
  • Audit-ready export — PDF report with control verdicts and evidence index
  • Unlimited re-assessments — track your posture quarter by quarter
Start with Pro planFrom £99 / month · Pro and Annual plans
ISO 27001 ISMS ToolkitPro · Annual

Every tool ISO 27001 requires — built into the platform

Certification requires more than a gap assessment. The ISO 27001 ISMS Toolkit gives you a fully integrated set of tools covering every clause: risk register with AI generation and treatment planning, Statement of Applicability with PDF export ready for your certification body, internal audit programme, management review records, IS objectives, and information asset register. Everything connected in one place, not spread across spreadsheets.

  • Risk Register — AI-generated from your findings and sector profile, with asset-linked risks and PDF treatment plan export
  • Statement of Applicability — all 93 Annex A controls reviewed, applicability decisions recorded, PDF export included
  • Internal Audit Programme — ISO 27001 Clause 9.2, AI-guided audit items with evidence links and report download
  • Management Reviews — structured records covering all 10 Clause 9.3 inputs, AI pre-populated from live platform data
  • IS Objectives — measurable targets with owner assignment, progress tracking, and monitoring type configuration
  • Information Asset Register — assets classified by type, criticality, owner, and processing location
Start with Pro planFrom £99 / month · Pro and Annual plans

ISO 27001 ISMS

Acme Corp Ltd · 2026 programme

ISMS maturity72%
RR

Risk Register

14 risks tracked

3 critical
SoA

Statement of Applicability

93 controls reviewed

89 applicable
AP

Audit Programme

2026 programme active

4 / 8 items done
MR

Management Reviews

ISO 27001 Cl 9.3

Q2 due soon

SoA export ready

All 93 Annex A controls reviewed · PDF available for your certification body

Agreements

4 agreements · 1 pending

Helix Partners NDA expired 4 Dec 2025 — renewal required

NDA

Apex Technologies Ltd

12 Mar 2026

Active
DPA

Salesforce Inc

1 Jan 2026

Active
MSA

Orbit Digital Ltd

18 Jul 2026

Pending signature
NDA

Helix Partners

4 Dec 2025

Expired

AI extraction active

Key terms, dates, and obligations extracted from uploaded documents — confidence-scored for review

Agreement & Contract IntelligencePro · Annual

Upload, extract, draft, and e-sign NDAs, DPAs, and MSAs — all in one place

Agreements & Contract Intelligence gives you a single workspace for every NDA, DPA, and MSA your business manages. Upload existing documents and let AI extract key terms, dates, and obligations — confidence-scored so you know what to verify. Draft new NDAs and DPAs in seconds from your organisation profile. Send for e-signing without leaving the platform. DPAs link directly to your ROPA for GDPR accountability.

  • Upload any PDF or DOCX agreement — AI extracts key terms, dates, and obligations with confidence scoring
  • AI draft generation — produce NDA or DPA documents tailored to your organisation in seconds
  • E-signing built in — send signature requests and track sign-off without leaving Fortify
  • Agreement types: NDA, mutual NDA, DPA, data sharing, processing agreement, MSA, service agreement
  • ROPA integration — DPAs automatically linked to your Record of Processing Activities
  • Expiry tracking — alerts when agreements are approaching renewal or have lapsed
Start with Pro planFrom £99 / month · Pro and Annual plans
Action PlanAnnual only

Turn your roadmap into an accountable plan — with Gantt timelines and resource allocation

The action roadmap gives every business a prioritised list of what to do next. The Action Plan takes that further — it's a formal programme management layer where you assign tasks to named team members, allocate time, set deadlines, and track progress on a Gantt timeline. Built for businesses that need to show stakeholders, auditors, or investors that remediation is actively resourced and progressing.

  • Gantt timeline view — tasks scheduled across weeks and months
  • Resource allocation — assign to team members with time estimates
  • Deadline tracking — surface overdue and at-risk tasks automatically
  • Milestone markers for certification, audit, and review dates
  • Progress reports — exportable for board, investor, or stakeholder updates
Start Annual plan£3,999 / year · Includes all Pro features

Action Plan — Q3 2026

Annual
Resources:Jason G. — 6h allocatedSarah C. — 6h allocatedTom R. — 3h allocated

Enable MFA on all admin accounts

Jason G.2h
75%

Document incident response plan

Sarah C.4h
30%

CE+ firewall configuration review

Tom R.3h
10%

Staff security awareness training

Sarah C.2h
0%
Pricing

Simple, transparent pricing across everything

Every assessment starts free. Paid tiers add human expert review and strategic outputs. The portal is free to access and scales with your team.

Digital Resilience Assessment

Cyber security, operational resilience, cloud, and digital maturity across your business.

Foundations Check

Free

Get an instant picture of your digital resilience

  • AI-guided assessment across 5 areas
  • Automated score and findings report
  • Prioritised action checklist
  • Delivered by email in minutes

Report: Automated summary

Start free check
Most popular

Essential Diagnostic

£500one-off + VAT

AI assessment with human-verified findings and quick wins

  • Deeper AI assessment — 15–20 questions
  • Human-reviewed findings and interpretation
  • 2–3 page report with top 5 risks and quick wins
  • Optional 20-minute follow-up call

Report: 2–3 page findings report

Review: Light review (30–45 mins)

Session: Optional 20-min call

Get started

Strategic Resilience Diagnostic

£2,500one-off + VAT

Full expert review with a founder session and strategic roadmap

  • Structured AI assessment — 25–35 questions
  • Full expert review (3–5 hours)
  • 5–7 page strategic roadmap with 30/60/90-day priorities
  • 60–90 minute founder session
  • 30 days free Pro Portal access

Report: 5–7 page strategic roadmap

Review: Full expert review (3–5 hours)

Session: 60–90 min founder session

Book diagnostic

Advanced Resilience Diagnostic

£5,000one-off + VAT

Deep diagnostic plus hands-on implementation planning

  • Deep AI assessment with implementation scoping
  • Full expert review and implementation planning
  • 8–10 page roadmap with detailed 90-day plan
  • Two sessions: diagnostic and implementation
  • 30 days free Pro Portal access

Report: 8–10 page roadmap and implementation plan

Review: Full review + implementation planning

Session: Two sessions: diagnostic + implementation

Get started

GDPR Compliance Assessment

From a quick exposure check to a full compliance programme ready for investor due diligence.

Are we exposed?

Free

Find out in 10 minutes whether your business has GDPR blind spots

  • AI-guided check across 5 GDPR areas
  • Automated compliance score and findings
  • Prioritised action checklist
  • Delivered by email in minutes

Report: Automated summary

Start free GDPR check
Most popular

Are we doing the basics right?

£500one-off + VAT

Structured review of your GDPR foundations with human-verified findings

  • Structured assessment across 6 GDPR areas
  • Human-reviewed compliance gap report
  • 2–3 page findings with prioritised actions
  • Governance and accountability review included

Report: 2–3 page gap report

Review: Light review (30–45 mins)

Get started

Are we safe to grow?

£1,500one-off + VAT

Assess whether your data practices are ready to scale safely

  • Comprehensive review across 8 GDPR areas
  • Full expert review (2–3 hours)
  • 5–7 page compliance roadmap
  • Processor management and DPIA guidance included
  • 30 days free Pro Portal access

Report: 5–7 page compliance roadmap

Review: Full expert review (2–3 hours)

Session: 60-minute review session

Book assessment

Are we investor and audit ready?

£3,000one-off + VAT

Full compliance programme ready for due diligence, audits, and ICO scrutiny

  • Complete assessment across 10 GDPR areas
  • Full review and implementation planning
  • 8–10 page compliance programme report
  • DPO readiness and Article 37 assessment included
  • 30 days free Pro Portal access

Report: 8–10 page compliance programme

Review: Full review + implementation planning

Session: Two sessions: assessment and planning

Get started

Cyber Essentials Plus Readiness Assessment

CE+ readiness audit built into the Fortify Portal — evaluate all five control areas and know exactly what to fix before certification.

CE+ Readiness Assessment

Cyber Essentials Plus is the UK government's independently verified cyber security certification — required for public sector contracts and widely recognised as the credibility benchmark for handling sensitive data. Our CE+ Readiness module evaluates your organisation against all five technical control areas — firewalls, secure configuration, user access, malware protection, and patch management — so you know exactly what needs to be fixed before the formal certification audit.

Five CE+ control areas

  • FirewallsBoundary and software firewalls configured and properly maintained
  • Secure configurationDefault passwords changed, unnecessary software removed
  • User access controlAdmin rights limited, accounts reviewed, MFA enforced
  • Malware protectionAntivirus active and up to date on all in-scope devices
  • Patch managementOS and application software patched within 14 days of release

Included in portal subscription

£99 / month

or £3,999 / year

Pro and Annual plans · Unlimited re-assessments · Evidence vault included

Access via portal

What's included

  • AI-guided readiness assessment

    An AI practitioner works through all five CE+ control areas with your team, gathering evidence of your current configuration and controls.

  • Control-level verdicts

    Each control area is assessed as pass, gap, or partial — with structured notes on what is missing and why it matters.

  • Gap analysis report

    A prioritised remediation report identifying every control that would fail the formal CE+ audit and what to do to fix it.

  • Evidence vault

    Attach screenshots, policies, and configuration exports directly to each control area within the portal.

  • Remediation tracking

    Work through identified gaps in the portal, attaching evidence and updating status as you close each one.

  • Unlimited re-assessments

    Run a new CE+ readiness check at any time — useful after remediation work or prior to booking your formal certification audit.

Who needs CE+?

Any UK business bidding for public sector or government contracts must hold Cyber Essentials Plus certification. It is also increasingly required by enterprise clients and insurance underwriters as a condition of cover.

Digital Operational Resilience Act (DORA)

Structured AI-guided readiness assessment across all five DORA pillars. Applicable from January 2025.

DORA Readiness Assessment

DORA (Regulation (EU) 2022/2554) has applied since January 2025 and covers financial entities — banks, payment institutions, insurers, investment firms, crypto-asset service providers — and the ICT providers that supply them. Our assessment evaluates your readiness across all five DORA pillars and gives you a clear picture of what needs to be in place before regulatory scrutiny.

The five DORA pillars

  • ICT Risk ManagementGovernance, asset inventory, protection, detection, and recovery
  • Incident Management & ReportingClassification, regulatory notification, and post-incident review
  • Resilience TestingVulnerability assessments, scenario testing, and TLPT where applicable
  • Third-Party RiskDue diligence, contracts, concentration risk, and exit strategies
  • Intelligence SharingThreat information sharing arrangements and agreements

Subscription

£99 / month

12-month commitment · Unlimited audits · Cancel on renewal

Access via portal

What's included

  • Scope selection

    Tailored for financial entities or ICT third-party service providers — the assessment adapts to your regulatory position.

  • Five-pillar AI assessment

    An AI compliance specialist (Morgan Clarke) works through each DORA pillar section by section, gathering evidence of your current controls.

  • Control-level verdicts

    Each of the 22 controls is assessed as compliant, partial, or non-compliant, with structured notes.

  • Evidence vault

    Attach policy documents, screenshots, and configuration exports directly to each control within the portal.

  • Readiness score

    An overall DORA readiness score and per-pillar breakdown, updated as you work through sections.

  • Unlimited re-assessments

    Run a new audit at any time — useful after remediation work or prior to a regulatory inspection.

Who is DORA for?

DORA applies to regulated financial entities operating in the EU/EEA, and to ICT service providers that supply critical or important functions to those entities — regardless of where the ICT provider is based.

Fortify Portal

Track findings, manage your roadmap, collaborate with your team. Free to access with any assessment.

Free

£0forever

1 user included

  • 5 Ask Alex messages / month
  • 30-day roadmap view
  • Import any Fortify assessment
  • Basic findings list
  • Evidence uploads
  • Policy engine
  • Incident log
  • Sector benchmarks
  • Quarterly PDF
Get started

Lite

£49/ month

1 seat included · +£49/mo per extra

  • 20 Ask Alex messages / month
  • Full 30/60/90-day roadmap
  • Evidence uploads
  • Team collaboration
  • Import any Fortify assessment
  • Policy engine
  • Incident log
  • Sector benchmarks
  • Quarterly PDF
  • ZIP evidence export
Start Lite
Most popular

Pro

£99/ month

1 seat included · +£99/mo per extra

  • 200 Ask Alex messages / month
  • Full 30/60/90-day roadmap
  • Evidence uploads + ZIP export
  • Policy engine — up to 10 active policies
  • AI patch suggestions — 10 per month
  • Incident log and playbooks
  • Vendor register — document, categorise, and score third parties
  • Vendor Risk add-on available — Threat monitoring, ROPA + reports (+£49/mo)
  • Compliance Audits (CE+, DORA, ISO 27001)
  • Risk register and ISMS toolkit — SoA, audit programme, asset register, management reviews
  • Agreement & Contract Intelligence — extract, draft, and e-sign NDAs, DPAs, and MSAs
  • Sector benchmarks
  • Quarterly review PDF
  • Team collaboration
Start Pro

Annual

£3,999/ year

1 seat included · +£250/mo per extra

  • Everything in Pro
  • Unlimited Ask Alex messages
  • Unlimited policies and AI patch suggestions
  • Incident log and playbooks
  • Vendor Risk module included — Threat monitoring, AI analysis, ROPA, questionnaires + reports
  • Compliance Audits (CE+, DORA, ISO 27001)
  • Action Plan with Gantt timeline and resource planning
  • Regulation change email briefings
  • Sector benchmarks
  • Quarterly review PDF
  • Team collaboration
Start Annual

Portal prices exclude VAT. Seats can be added or removed at any time — Stripe prorates the charge automatically.

Know where you stand. Start today — free.

An honest, expert-quality picture of your business in under ten minutes. No sign-up, no credit card, no jargon.

Already have an account? Sign in to the portal →