AI assessments · Secure portal · Expert review

From assessment to action — everything in one platform

Fortify gives your business structured AI-guided assessments that tell you exactly where you stand, and a secure workspace to manage findings, track your roadmap, and get expert guidance. Free to start.

fortify.bluecipher.co.uk/portal/org/acme
Acme Corp Ltd
Overview
Findings
Roadmap
Risk Register
Policies
Supply Chain
Incidents
Audits
Agreements
Action Plan
Ask Alex
Team

Overview

Essential
2 critical CVEs affecting your software stack — action requiredView →
Findings
14
Critical
2
Open
8
Score
62

Next 30 days

Enable MFA on all admin accounts
Document incident response plan
Review vendor CVE exposure
Complete ISO 27001 audit section A.8

Free to start

No credit card required

50+ frameworks

Covered in Compliance Navigator

5 assessment types

DR, GDPR, Compliance, CE+, DORA

Human review

Available on all paid assessments

Assessments

Know exactly where your business stands

Four structured assessments covering the areas that matter most. Each starts free or is available on request — no lengthy questionnaires, just an honest conversation.

Digital ResilienceAssessment

How well can your business withstand digital threats and disruption?

A structured AI conversation across five core areas — cyber security, operational resilience, digital maturity, cloud infrastructure, and business continuity. Free to start, with human expert review available at paid tiers.

  • Covers cyber security, cloud, operations, and business continuity
  • AI-guided conversation — no forms, no jargon
  • Personalised PDF report with prioritised next steps
  • Human consultant review at paid tiers
  • Findings sync directly into the Fortify Portal
Start free assessmentFree · No sign-up required
Alex · Digital ResilienceStep 3 of 5
AM

Do you have a documented incident response process — for example, a plan that sets out what to do if you're hit by ransomware or a data breach?

We have a rough process but it's not formally documented anywhere...

AM

That's a common starting point. Does your team know who to contact first if something goes wrong — like a suspected phishing attack?

Type your answer...
GDPR ComplianceAssessment

Does your business have GDPR blind spots that could cost you?

A structured GDPR assessment that identifies your exposure across all accountability requirements — from a quick free check to a full compliance programme suitable for investor due diligence and ICO scrutiny.

  • Structured across all GDPR accountability requirements
  • Identifies high-risk gaps with plain-English explanations
  • Human Data Protection Consultant review at paid tiers
  • Investor and auditor-ready outputs at Tier 2 and above
  • Findings sync directly to the Fortify Portal
Start free GDPR checkFree · No sign-up required
Morgan · GDPR AssessmentStep 2 of 6
MC

Do you maintain a Record of Processing Activities — a ROPA — documenting the personal data your organisation holds, its purpose, and legal basis?

We have a spreadsheet but it hasn't been updated in about 18 months...

MC

An outdated ROPA is a common gap. Does it cover the key elements — data categories, retention periods, and third-party transfers?

Type your answer...
Compliance NavigatorFree tool

Which regulations and certifications actually apply to your business?

Answer a few questions about your industry, location, and data handling and the Compliance Navigator maps your obligations across 50+ UK, EU, and US frameworks — GDPR, NIS2, EU AI Act, HIPAA, SOC 2, ISO 27001, and more. Free and instant.

  • 50+ regulations and certifications checked in one pass
  • UK, EU, and US coverage simultaneously
  • Personalised AI explanations for each applicable framework
  • Instant results — no account required
Map my compliance obligationsFree · No sign-up required

Compliance Navigator — Acme Corp Ltd

Technology · UK + EU operations · Handles personal data · 12 employees

50+ frameworks checked · 5 apply · 2 require investigation · Results instant, no sign-up

UK GDPR

Personal data processing

Applies

ICO Registration

Data controller registration

Required

NIS2 Directive

Digital infrastructure — check scope

Check required

ISO 27001

Information security management

Recommended

EU AI Act

AI systems deployed to EU users

Applies

PECR

Electronic communications + cookies

Applies

HIPAA

US health information

Not applicable

SOC 2

Enterprise customer requirements

Check required
DORA ReadinessAssessment

Is your organisation ready for DORA regulatory scrutiny?

DORA (Regulation (EU) 2022/2554) applies to financial entities and their ICT service providers across the EU and EEA from January 2025. Our structured readiness assessment covers all five DORA pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and intelligence sharing — and gives you a control-level gap analysis before regulators come knocking.

  • Covers all five DORA pillars across 22 specific controls
  • Scope-tailored for financial entities or ICT third-party providers
  • Control-level verdicts: compliant, partial, or non-compliant
  • Evidence vault for policies, configurations, and test results
  • Unlimited re-assessments included in your portal plan
Access via portalStrategic and above · See /pricing

DORA Readiness Assessment

Financial Entity · Five pillars · 25 controls

52% complete

ICT Risk Management

DORA-RM · 8/8 controls

Complete

Incident Management

DORA-IR · 5/5 controls

Complete

Resilience Testing

DORA-RT · 2/4 controls

In progress

Third-Party Risk

DORA-TP · 0/6 controls

Not started

Intelligence Sharing

DORA-IS · 0/2 controls

Not started
Cyber Essentials Plus ReadinessAssessment

Are you ready for Cyber Essentials Plus certification?

Cyber Essentials Plus (CE+) is the UK government's independently verified cyber security certification — required for government contracts and a mark of credibility for any business handling sensitive data. Our CE+ Readiness Assessment evaluates your business against all five technical control areas so you know exactly what needs to be fixed before the formal certification audit.

  • Assessed against all five CE+ technical control areas
  • Firewalls, secure configuration, user access, malware protection, patching
  • Gap analysis report identifying audit-fail risks
  • Prioritised remediation plan with timelines
  • Human-reviewed by a certified CE+ practitioner
Access via portalEssential and above · See /pricing

CE+ Readiness Assessment

Five technical control areas · Certified practitioner review

Firewalls

Boundary and software firewalls configured correctly

Pass

Secure configuration

Default passwords changed, unnecessary software removed

Pass

User access control

Admin rights limited, accounts reviewed

Pass

Malware protection

Antivirus active and up to date on all devices

Gap found

Patch management

OS and software patched within 14 days of release

Gap found
Fortify Portal

A secure workspace to manage everything after your assessment

The Fortify Portal is where the real work happens. Import your assessment findings, work through a prioritised action roadmap, upload evidence, collaborate with your team, and ask Alex for guidance — all in one place. Free to access with any Fortify assessment.

Structured findings management
30/60/90-day action roadmap
Ask Alex for guidance
Team collaboration
Evidence uploads
Policy engine (Strategic and above)
Incident log & playbooks (Strategic and above)
Vendor register (Strategic and above)
Supply chain risk — Vendor Risk module (Advanced)
Compliance Audits — CE+, DORA, ISO 27001 (Strategic and above)
ISO 27001 toolkit — SoA, risk register, internal audits (Strategic and above)
Agreement & Contract Intelligence — NDA, DPA, MSA (Strategic and above)
Sector benchmarks (Strategic and above)
Action Plan & Gantt (Advanced)
fortify.bluecipher.co.uk/portal
Acme Corp Ltd
Overview
Findings
Roadmap
Policies
Ask Alex
Team

Overview

Total
14
Open
5
Resolved
3

Next 30 days

Enable MFA on all admin accounts
Document incident response plan
Review vendor access controls
Portal features

Everything you need to act on your assessment

The portal turns a static PDF report into a living programme. Manage findings, track actions, collaborate with your team, and keep the evidence that proves you did it.

Findings management

Every finding from your assessment is imported into a structured workspace. Filter by risk level, status, or area. Add notes, attach evidence, and update status as you work through remediations.

Findings

14 total · 10 open
AllCriticalHighMediumLow
Search findings...
Critical

Enable MFA on all admin accounts

Cyber Security

Open
High

Patch Apache Log4j (CVE-2021-44228)

Cloud

In Progress
High

Document incident response process

Operations

Open
Medium

Review vendor access controls

Governance

In Review
Low

Update staff security awareness training

People

Planned

30/60/90-day action roadmap

Findings are automatically prioritised into a time-bound roadmap. The 30-day plan addresses critical items; 60- and 90-day phases cover the medium and longer-term work. Drag to reprioritise or mark items complete as you go.

Action Roadmap

8 actions · prioritised by risk and effort

30 days

Enable MFA on admin accounts

Critical

Patch Apache Log4j

Critical

Review firewall rules

High

60 days

Document IR process

High

BCP testing exercise

High

CE+ readiness check

Medium

90 days

Vendor access audit

Medium

Staff security training

Low

Ask Alex — your on-demand advisor

Ask Alex directly from the portal for specific, context-aware guidance on any finding. Alex knows your assessment results and gives actionable answers — not generic advice.

AX

Ask Alex

Context: F-003 · Undocumented incident response process

Where do I start with writing an incident response plan?

AX

Based on your assessment — Acme Corp Ltd

1. Assign an Incident Coordinator — a named person who owns response, not just IT. For your size, this is likely the CEO or IT lead.

2. Define four severity tiers — P1 (business-stopping), P2 (major impact), P3 (minor disruption), P4 (near-miss). This shapes your notification duties.

3. Map your notification requirements — ICO within 72h for P1/P2 data breaches. NCSC for ransomware. These are legal obligations, not optional.

Ask about this finding...

Evidence uploads

Attach policies, certificates, screenshots, or any supporting document directly to a finding. Evidence is stored securely and available to auditors, investors, or clients. Strategic and above includes bulk ZIP export.

Evidence

F-002 · Patch management process

3 files

patch-policy-v2.pdf

128 KB · Added 14 Jun

wsus-config-screenshot.png

340 KB · Added 14 Jun

approved-by-cto.docx

45 KB · Added 12 Jun

Drop files here or browse

Team collaboration

Invite colleagues, consultants, or board members with role-based access. Owners and admins manage the workspace; contributors update statuses and add notes; read-only members view everything without changes.

Team

3 members
JG

Jason Gillan

jason@acme.co.uk

Owner
SC

Sarah Chen

sarah@acme.co.uk

Admin
TR

Tom Richards

tom@acme.co.uk

Contributor
colleague@company.com
Role ▾
Invite

Sector benchmarks & quarterly review (Strategic and above)

See how your scores compare to similar businesses in your industry. A quarterly PDF review is automatically generated so you can track progress over time and share results with stakeholders.

Sector Benchmarks

Technology · SME · UK · Digital Resilience

Your score62/100
Sector average58/100
Top quartile78/100

Q2 2026 Review

Ready

Your quarterly PDF report includes score progression, peer comparison, and a prioritised recommendation summary for stakeholders.

Download Q2 PDF
Policy EngineStrategic · Advanced

AI-generated policies that stay current with your regulatory obligations

The Policy Engine generates complete, section-structured policy documents — Privacy Policies, Data Protection Policies, Incident Response Plans, and more — tailored to your organisation and regulation scope. When the ICO, NCSC, or FCA publishes guidance updates, Fortify flags the affected sections and offers AI-suggested patches you can review, accept, or dismiss.

  • Generate 20+ policy types from your organisation profile and regulation scope
  • Every section tagged to specific frameworks — UK GDPR, CE+, ISO 27001, and more
  • Weekly regulation monitoring — ICO, NCSC, and FCA feeds tracked automatically
  • AI-suggested edits when regulation guidance changes — accept or dismiss per section
  • Configurable review cycles — monthly, quarterly, or annual reminders
  • Approval workflow before publishing — designate a reviewer or approve as owner

Strategic and above · See full pricing

Privacy Policy

UK GDPR · PECR · Version 1 · Annual review

Draft
Publish

Regulation update — ICO updated consent guidance · 2 sections flagged for review

Review →

Sections · 5

Introduction
Lawful basis for processing
Consent & cookies
Your data rights
Contact & complaints
+ Add section
uk-gdprpecr

This Privacy Policy describes how Acme Corp Ltd (“we”, “us”) collects, uses, and protects your personal data under the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR).

We are the data controller for the purposes of UK GDPR. Our registered office is at 12 Innovation Street, London, EC1A 1BB.

Next review: Jun 2027
Incident LogStrategic · Advanced

Log, investigate, and close incidents — with AI-guided response at every step

When something goes wrong, the clock starts immediately. The Incident Log gives you a structured workspace to capture what happened, assign follow-up actions, track resolution, and meet notification deadlines. When you need guidance fast, the AI assistant analyses the incident and returns immediate steps, root cause hypotheses, regulatory notification requirements, and a resolution checklist — specific to your incident type and severity.

  • Log any incident type — breach, outage, phishing, ransomware, compliance
  • Full status lifecycle: Open → Investigating → Contained → Resolved → Closed
  • Follow-up action management — corrective steps with due dates and owners
  • AI response advisory: immediate steps, root causes, and recommended follow-up actions
  • ICO, NCSC, and FCA notification requirements flagged automatically
  • Resolution checklist and timeline of events
View portal plansStrategic and above · See full pricing
Incident Log
2 open1 investigating
high

Phishing email opened by staff member

Phishing Attack · 2 follow-ups

investigating
critical

CRM access from unknown IP address

Unauthorized Access

open
medium

AWS S3 bucket misconfiguration

Security Incident · 3 follow-ups

contained
low

Third-party supplier data request

Compliance Violation · 1 follow-up

resolved

AI response advisory — CRM access from unknown IP

⚡ Immediate: Terminate active sessions, force password reset, enable MFA

📣 Notify: ICO notification required within 72h if PII accessed

🔧 Follow-up: Implement geo-restriction on CRM access · Audit login history

PlaybooksStrategic · Advanced

Response playbooks: your team always knows what to do

Playbooks are step-by-step response templates for specific incident types — Ransomware, Data Breach, Phishing, System Outage, and more. Assign a playbook when you log an incident so your team has a clear, consistent response from the first minute. Build your own, or use Fortify system playbooks as a starting point.

  • Create playbooks for any incident type
  • Multi-step templates with role assignments
  • Fortify system playbooks included — ready to use
  • Attach a playbook at incident creation or any time during investigation

Ransomware Response playbook

✓

Isolate affected systems

IT Manager
✓

Notify key stakeholders

CEO / DPO
3

Preserve forensic evidence

IT Manager
4

Assess encryption scope

IT Manager
5

Report to NCSC / ICO if required

DPO
6

Begin recovery from clean backups

IT Manager
Continuity BuilderStrategic · Advanced

From nothing to a tested business continuity plan — without a continuity consultant

Describe the business in plain English and Fortify drafts a realistic first Business Continuity Policy — critical functions, recovery targets, and continuity arrangements, based on standard practice for similar businesses. From there, four dedicated areas let you go deeper than a single generated document ever could: lead a proper Business Impact Analysis, set Recovery Time and Recovery Point Objectives per function, write genuine technical continuity plans linked to your incident playbooks, and build a testing programme — with each area able to push its detail straight back into the policy itself.

  • Guided plan generation from a plain-English business description — no continuity knowledge needed
  • AI-led Business Impact Analysis — identifies critical functions and assesses real impact
  • Recovery Objectives per function, with AI guidance on genuine regulatory constraints
  • Technical continuity plans, each optionally linked to an incident response playbook
  • Auto-generated testing schedule, AI-built exercise scenarios, and a results log
  • Every area can push its detail straight back into the Business Continuity Policy

Strategic and above · See full pricing

Continuity

Business Impact Analysis6 functions
Recovery Objectives4 of 6 set
Plans5 plans
Testing3 tests scheduled
Supply Chain RiskVendor Risk add-on

Know exactly which vendors put you at risk — and when a new CVE changes that

Supply chain breaches are increasingly the root cause of compliance failures and operational outages — and most businesses have no visibility of the risk sitting in their vendor stack. The Vendor Risk add-on monitors your third parties for CVE exposure, analyses vulnerabilities with AI, maintains your ROPA for GDPR purposes, and gives you a structured vendor risk register that's always up to date.

  • Vendor risk register — document, categorise, and score all third parties
  • Threat monitoring — tracked vulnerabilities mapped to your vendor software stack
  • AI CVE analysis — instant risk assessment and remediation guidance per CVE
  • ROPA management — Record of Processing Activities for GDPR accountability
  • Automated CVE alerts — notified when a critical vulnerability affects a vendor
  • Supply chain assessment reports — export for auditors, investors, or clients
View portal plansIncluded in Advanced · See full pricing

Supply Chain Risk

5 vendors · 4 CVEs tracked

Log4Shell (CVE-2021-44228) affects 1 vendor — patch required immediately

Triage →
AW

AWS

Cloud

Low
SA

Salesforce

CRM

1 CVEMedium
LO

Log4j dependency

Dev tooling

3 CVEsCritical
ST

Stripe

Payments

Low
SL

Slack

Comms

Low

ISO 27001 Readiness Audit

Acme Corp Ltd · ISO 27001 controls · 5 sections shown

48% complete

Information Security Policies

A.5 · 4/4 controls

Complete

Organisation of Info Security

A.6 · 7/7 controls

Complete

Asset Management

A.8 · 5/8 controls

In progress

Access Control

A.9 · 0/14 controls

Not started

Operations Security

A.12 · 0/14 controls

Not started
Compliance AuditsStrategic · Advanced

Structured compliance audits — self-assessment built for certification readiness

Compliance Audits gives you a formal, control-level audit workspace for the frameworks that matter most to UK businesses — ISO 27001, Cyber Essentials Plus (CE+), and DORA. Work through each section systematically, attach evidence, track progress, and produce an audit-ready report when you're done. Run as many times as you need — every re-assessment tracks your progress over time.

  • ISO 27001, Cyber Essentials Plus (CE+), and DORA — frameworks updated regularly
  • Section-by-section structure with control-level verdicts
  • Evidence vault — attach policies and configurations to each control
  • Progress tracking — completion percentage and gap summary at a glance
  • Audit-ready export — PDF report with control verdicts and evidence index
  • Unlimited re-assessments — track your posture quarter by quarter
View portal plansStrategic and above · See full pricing
ISO 27001 Certification ToolkitStrategic · Advanced

Every tool ISO 27001 requires — built into the platform

Certification requires more than a gap assessment. The ISO 27001 Certification Toolkit gives you a fully integrated set of tools covering every clause: risk register with AI generation and response planning, Statement of Applicability with PDF export ready for your certification body, internal audits, leadership review records, security goals, and information asset register. Everything connected in one place, not spread across spreadsheets.

  • Risk Register — AI-generated from your findings and sector profile, with asset-linked risks and PDF response plan export
  • Statement of Applicability — all 93 ISO 27001 controls reviewed, applicability decisions recorded, PDF export included
  • Internal Audits — AI-guided audit items with evidence links and report download
  • Leadership Reviews — structured records covering all required review inputs, AI pre-populated from live platform data
  • Security Goals — measurable targets with owner assignment, progress tracking, and monitoring type configuration
  • Information Asset Register — assets classified by type, criticality, owner, and processing location
View portal plansStrategic and above · See full pricing

ISO 27001 ISMS

Acme Corp Ltd · 2026 programme

ISMS maturity72%
RR

Risk Register

14 risks tracked

3 critical
SoA

Statement of Applicability

93 controls reviewed

89 applicable
AP

Internal Audits

2026 programme active

4 / 8 items done
LR

Leadership Reviews

Quarterly checkpoint

Q2 due soon

SoA export ready

All 93 ISO 27001 controls reviewed · PDF available for your certification body

Agreements

4 agreements · 1 pending

Helix Partners NDA expired 4 Dec 2025 — renewal required

NDA

Apex Technologies Ltd

12 Mar 2026

Active
DPA

Salesforce Inc

1 Jan 2026

Active
MSA

Orbit Digital Ltd

18 Jul 2026

Pending signature
NDA

Helix Partners

4 Dec 2025

Expired

AI extraction active

Key terms, dates, and obligations extracted from uploaded documents — confidence-scored for review

Agreement & Contract IntelligenceStrategic · Advanced

Upload, extract, draft, and e-sign NDAs, DPAs, and MSAs — all in one place

Agreements & Contract Intelligence gives you a single workspace for every NDA, DPA, and MSA your business manages. Upload existing documents and let AI extract key terms, dates, and obligations — confidence-scored so you know what to verify. Draft new NDAs and DPAs in seconds from your organisation profile. Send for e-signing without leaving the platform. DPAs link directly to your ROPA for GDPR accountability.

  • Upload any PDF or DOCX agreement — AI extracts key terms, dates, and obligations with confidence scoring
  • AI draft generation — produce NDA or DPA documents tailored to your organisation in seconds
  • E-signing built in — send signature requests and track sign-off without leaving Fortify
  • Agreement types: NDA, mutual NDA, DPA, data sharing, processing agreement, MSA, service agreement
  • ROPA integration — DPAs automatically linked to your Record of Processing Activities
  • Expiry tracking — alerts when agreements are approaching renewal or have lapsed
View portal plansStrategic and above · See full pricing
Action PlanAdvanced only

Turn your roadmap into an accountable plan — with Gantt timelines and resource allocation

The action roadmap gives every business a prioritised list of what to do next. The Action Plan takes that further — it's a formal programme management layer where you assign tasks to named team members, allocate time, set deadlines, and track progress on a Gantt timeline. Built for businesses that need to show stakeholders, auditors, or investors that remediation is actively resourced and progressing.

  • Gantt timeline view — tasks scheduled across weeks and months
  • Resource allocation — assign to team members with time estimates
  • Deadline tracking — surface overdue and at-risk tasks automatically
  • Milestone markers for certification, audit, and review dates
  • Progress reports — exportable for board, investor, or stakeholder updates
Start Advanced planFrom £649/mo org base + £100/user · See full pricing

Action Plan — Q3 2026

Advanced
Resources:Jason G. — 6h allocatedSarah C. — 6h allocatedTom R. — 3h allocated

Enable MFA on all admin accounts

Jason G.2h
75%

Document incident response plan

Sarah C.4h
30%

CE+ firewall configuration review

Tom R.3h
10%

Staff security awareness training

Sarah C.2h
0%
Pricing

Simple, transparent pricing across everything

All assessments and workspace tools are bundled into portal plans. Start free with Foundation, or unlock diagnostics, compliance audits, and expert tools from Essential upwards.

Digital Resilience Assessment

Cyber security, operational resilience, cloud, and digital maturity across your business.

Foundations Check

Free

Get an instant picture of your digital resilience

  • AI-guided assessment across 5 areas
  • Automated score and findings report
  • Prioritised action checklist
  • Delivered by email in minutes

Report: Automated summary

Start free check
Most popular

Essential Diagnostic

Included

Included in the Essential portal plan · See /pricing for full details

  • Deeper AI assessment — 15–20 questions
  • Human-reviewed findings and interpretation
  • 2–3 page report with top 5 risks and quick wins
  • Optional 20-minute follow-up call

Report: 2–3 page findings report

Review: Light review (30–45 mins)

Session: Optional 20-min call

View portal plans

Strategic Resilience Diagnostic

Included

Included in the Strategic portal plan · See /pricing for full details

  • Structured AI assessment — 25–35 questions
  • Full expert review (3–5 hours)
  • 5–7 page strategic roadmap with 30/60/90-day priorities
  • 60–90 minute founder session

Report: 5–7 page strategic roadmap

Review: Full expert review (3–5 hours)

Session: 60–90 min founder session

View portal plans

Advanced Resilience Diagnostic

Included

Included in the Advanced portal plan · See /pricing for full details

  • Deep AI assessment with implementation scoping
  • Full expert review and implementation planning
  • 8–10 page roadmap with detailed 90-day plan
  • Two sessions: diagnostic and implementation

Report: 8–10 page roadmap and implementation plan

Review: Full review + implementation planning

Session: Two sessions: diagnostic + implementation

View portal plans

GDPR Compliance Assessment

From a quick exposure check to a full compliance programme ready for investor due diligence.

Are we exposed?

Free

Find out in 10 minutes whether your business has GDPR blind spots

  • AI-guided check across 5 GDPR areas
  • Automated compliance score and findings
  • Prioritised action checklist
  • Delivered by email in minutes

Report: Automated summary

Start free GDPR check
Most popular

Are we doing the basics right?

Included

Included in the Essential portal plan · See /pricing for full details

  • Structured assessment across 6 GDPR areas
  • Human-reviewed compliance gap report
  • 2–3 page findings with prioritised actions
  • Governance and accountability review included

Report: 2–3 page gap report

Review: Light review (30–45 mins)

View portal plans

Are we safe to grow?

Included

Included in the Strategic portal plan · See /pricing for full details

  • Comprehensive review across 8 GDPR areas
  • Full expert review (2–3 hours)
  • 5–7 page compliance roadmap
  • Processor management and DPIA guidance included

Report: 5–7 page compliance roadmap

Review: Full expert review (2–3 hours)

Session: 60-minute review session

View portal plans

Are we investor and audit ready?

Included

Included in the Advanced portal plan · See /pricing for full details

  • Complete assessment across 10 GDPR areas
  • Full review and implementation planning
  • 8–10 page compliance programme report
  • DPO readiness and Article 37 assessment included

Report: 8–10 page compliance programme

Review: Full review + implementation planning

Session: Two sessions: assessment and planning

View portal plans

Cyber Essentials Plus Readiness Assessment

CE+ readiness audit built into the Fortify Portal — evaluate all five control areas and know exactly what to fix before certification.

CE+ Readiness Assessment

Cyber Essentials Plus is the UK government's independently verified cyber security certification — required for public sector contracts and widely recognised as the credibility benchmark for handling sensitive data. Our CE+ Readiness module evaluates your organisation against all five technical control areas — firewalls, secure configuration, user access, malware protection, and patch management — so you know exactly what needs to be fixed before the formal certification audit.

Five CE+ control areas

  • Firewalls — Boundary and software firewalls configured and properly maintained
  • Secure configuration — Default passwords changed, unnecessary software removed
  • User access control — Admin rights limited, accounts reviewed, MFA enforced
  • Malware protection — Antivirus active and up to date on all in-scope devices
  • Patch management — OS and application software patched within 14 days of release

Included in portal plan

From £149 / month org base

Essential and above · Unlimited re-assessments · Evidence vault included · See full pricing

Access via portal

What's included

  • AI-guided readiness assessment

    An AI practitioner works through all five CE+ control areas with your team, gathering evidence of your current configuration and controls.

  • Control-level verdicts

    Each control area is assessed as pass, gap, or partial — with structured notes on what is missing and why it matters.

  • Gap analysis report

    A prioritised remediation report identifying every control that would fail the formal CE+ audit and what to do to fix it.

  • Evidence vault

    Attach screenshots, policies, and configuration exports directly to each control area within the portal.

  • Remediation tracking

    Work through identified gaps in the portal, attaching evidence and updating status as you close each one.

  • Unlimited re-assessments

    Run a new CE+ readiness check at any time — useful after remediation work or prior to booking your formal certification audit.

Who needs CE+?

Any UK business bidding for public sector or government contracts must hold Cyber Essentials Plus certification. It is also increasingly required by enterprise clients and insurance underwriters as a condition of cover.

Digital Operational Resilience Act (DORA)

Structured AI-guided readiness assessment across all five DORA pillars. Applicable from January 2025.

DORA Readiness Assessment

DORA (Regulation (EU) 2022/2554) has applied since January 2025 and covers financial entities — banks, payment institutions, insurers, investment firms, crypto-asset service providers — and the ICT providers that supply them. Our assessment evaluates your readiness across all five DORA pillars and gives you a clear picture of what needs to be in place before regulatory scrutiny.

The five DORA pillars

  • ICT Risk Management — Governance, asset inventory, protection, detection, and recovery
  • Incident Management & Reporting — Classification, regulatory notification, and post-incident review
  • Resilience Testing — Vulnerability assessments, scenario testing, and TLPT where applicable
  • Third-Party Risk — Due diligence, contracts, concentration risk, and exit strategies
  • Intelligence Sharing — Threat information sharing arrangements and agreements

Included in portal plan

From £349 / month org base

Strategic and above · Unlimited audits · See full pricing

Access via portal

What's included

  • Scope selection

    Tailored for financial entities or ICT third-party service providers — the assessment adapts to your regulatory position.

  • Five-pillar AI assessment

    An AI compliance specialist (Morgan) works through each DORA pillar section by section, gathering evidence of your current controls.

  • Control-level verdicts

    Each of the 22 controls is assessed as compliant, partial, or non-compliant, with structured notes.

  • Evidence vault

    Attach policy documents, screenshots, and configuration exports directly to each control within the portal.

  • Readiness score

    An overall DORA readiness score and per-pillar breakdown, updated as you work through sections.

  • Unlimited re-assessments

    Run a new audit at any time — useful after remediation work or prior to a regulatory inspection.

Who is DORA for?

DORA applies to regulated financial entities operating in the EU/EEA, and to ICT service providers that supply critical or important functions to those entities — regardless of where the ICT provider is based.

Fortify Portal

All assessments are bundled into portal plans. Start free with Foundation, or unlock diagnostics, compliance audits, and expert tools from Essential upwards.

Foundation

£0forever

Org workspace included

  • 5 Ask Alex messages / month
  • 30-day roadmap view
  • Import any Fortify assessment
  • Basic findings list
  • DR / GDPR diagnostics
  • Compliance audits
  • Evidence uploads
  • Policy engine
  • Incident log
Get started free
Most popular

Essential

£149/ month org base

+ £50/user/month · annual · or £179/mo monthly

  • DR Essential Diagnostic included
  • GDPR Tier 1 included
  • 1 compliance audit
  • 20 Ask Alex messages / month
  • Full 30/60/90-day roadmap
  • Evidence uploads
  • Team collaboration
  • Import any Fortify assessment
  • Policy engine
  • Incident log
  • Sector benchmarks
  • Action Plan & Gantt
Start Essential

Strategic

£349/ month org base

+ £75/user/month · annual · or £419/mo monthly

  • DR Strategic Diagnostic included
  • GDPR Tier 2 included
  • 2 compliance audits
  • 200 Ask Alex messages / month
  • Full 30/60/90-day roadmap
  • Evidence uploads + ZIP export
  • Policy engine — up to 10 active policies
  • AI patch suggestions — 10 per month
  • Incident log and playbooks
  • Vendor register — document, categorise, and score third parties
  • Compliance Audits (CE+, DORA, ISO 27001)
  • ISO 27001 toolkit — SoA, risk register, internal audits
  • Agreement & Contract Intelligence — NDA, DPA, MSA
  • Sector benchmarks
  • Quarterly review PDF
  • Team collaboration
Start Strategic

Advanced

£649/ month org base

+ £100/user/month · annual · or £779/mo monthly

  • DR Advanced Diagnostic included
  • GDPR Tier 3 included
  • All 4 compliance audits
  • Unlimited Ask Alex messages
  • Everything in Strategic
  • Vendor Risk module included — Threat monitoring, AI analysis, ROPA, questionnaires + reports
  • Action Plan with Gantt timeline and resource planning
  • Regulation change email briefings
Start Advanced

Annual commitment prices shown — monthly billing available at a higher rate. Prices exclude VAT. See full pricing for complete tier comparison.

Know where you stand. Start today — free.

An honest, expert-quality picture of your business in under ten minutes. No sign-up, no credit card, no jargon.

Already have an account? Sign in to the portal →