The deliverable

Evidence, not opinions.

Most Microsoft 365 assessments hand you a Secure Score screenshot and a spreadsheet. Mine produces a complete, evidence-backed assessment package — board summary, technical findings, compliance crosswalks, and a remediation roadmap — generated by a proprietary PowerShell engine that collects evidence directly from your tenant.

Why this matters

NIS2 is in force. “We think we’re secure” no longer counts.

Portugal’s Cybersecurity Legal Framework (Decree-Law 125/2025) took effect on 3 April 2026, transposing the EU NIS2 Directive and bringing an estimated 7,000–9,000 organisations into scope — most for the first time. It requires you to demonstrate your security posture with evidence, not assertion: risk-management measures, incident reporting on tight deadlines, supply-chain security, and personal, non-delegable accountability for the management body — with fines up to €10 million or 2% of worldwide turnover. That is exactly what this assessment produces: a reproducible, framework-mapped evidence base you can put in front of a regulator, an auditor, or your board.

Mapped to NIS2 Art. 21(2), ISO/IEC 27001:2022 and CIS.

Technical readiness — not legal advice.

What you receive

One assessment, every audience.

The same evidence, rendered for the people who need to act on it — from the board to the engineer. Delivered as HTML and Word, with CSV and JSON evidence.

Board

Executive Board Summary

Risk posture, top exposures, and investment priorities — in business language.

WordHTML
Leadership

Executive Report

Prioritised findings, risk themes, and a phased remediation roadmap.

WordHTML
Engineers

Technical Findings

Every finding with severity, evidence, Zero Trust pillar, remediation and required licence.

HTMLCSV
Identity

Identity Governance & CA

Privileged access, governance gaps, and Conditional Access optimisation.

HTML
Compliance

Crosswalk & NIS2 Readiness

Technical-readiness mapping to NIS2 Art.21(2), ISO 27001, CIS, CISA SCuBA and EIDSCA — readiness, not a legal compliance verdict.

WordHTML
Security

Attack Surface Exposure

External and configuration exposure across the tenant.

HTML
Finance

Licence Optimisation & Sizing

Licence waste, right-sizing, and managed-services scope.

HTMLCSV
Maturity

Zero Trust & Azure

CISA five-pillar Zero Trust maturity, plus Azure infrastructure assessment.

WordHTML
Why it holds up

A methodology you can defend to an auditor.

01

Evidence-backed

Thousands of items collected directly from your tenant. Every finding traces to evidence, not guesswork.

02

Coverage-aware

“Not Assessed” is never reported as Pass, Fail, or Zero. If something can’t be collected, the report says so and caps confidence.

No false clean bill of health
03

Framework-aligned

Rules mapped to CIS, CISA SCuBA, EIDSCA, ORCA and Maester.

04

Secure by design

App + certificate authentication. Read-only. No stored credentials.

05

Built for delivery

Every finding carries its remediation and the exact licence it requires — so the roadmap is actionable.

The engagement

From scoping call to board-ready in days.

01

Scoping call (30 min)

we agree scope (M365, Azure, or both) and confirm access.

02

Read-only access

you grant delegated, read-only app + certificate access. No stored credentials; nothing is written to your tenant.

03

Evidence collection

the engine runs 228 curated checks, collecting thousands of configuration items directly from your tenant. Anything it can’t reach is recorded as “not assessed” — never guessed.

04

Validation & reporting

I review every finding, map it to NIS2 / ISO 27001 / CIS, and write the board summary, technical findings and remediation roadmap.

05

Walkthrough

a findings call to talk through the report, priorities and next steps. Delivered in days.

See it

Look at the actual output.

You don’t have to take the methodology on faith. See a full sample report — the executive summary, the coverage model, and the findings — before you ever sign anything.

Executive summary dashboard: security posture score, findings by severity, and collection coverage
Assessment dashboards hub linking every report in the package
Zero Trust maturity: CISA five-pillar radar with not-assessed pillars shown distinctly

A live sample from a demo tenant is available on request. No client data is ever shown.

Ready when you are

Know exactly where your Microsoft environment stands.