Patching inside fourteen days, operating system in support, firewall on. Answered honestly across the fleet.
Are critical and high-severity vulnerabilities patched within fourteen days, is the operating system in support, and is the firewall on?
The IT Operations Engine answers it from the device-management and endpoint-protection data your tenant already holds, and says plainly where the data does not exist.
What an honest fleet report has to do
The engine enumerates every managed device, separates laptops from phones, tablets and desktops on model evidence, and records operating system, version, last check-in, compliance state and encryption state for each. It then pulls per-device vulnerability exposure from your endpoint-protection service, applies the Cyber Essentials in-scope definition and the fourteen-day patching window, and reports each device as compliant, non-compliant, or unable to assess. Devices on end-of-life operating systems are flagged separately. Host firewall status is checked by every available method before it is reported.
Where data cannot be retrieved, the device is recorded as unable to assess and never assumed compliant. Where a permission is missing, the report names it, and the assessment can be re-run once it is granted.
Can you answer it honestly across the whole fleet today?
Read-only access to your device-management and endpoint-protection tenant. First report usually within days.
We have run this on our own fleet. On yours, we would run it read-only first, then agree the remediation path for the devices that fall short.
Access to your device-management and endpoint-protection tenant. The engine reads what is already held there rather than installing anything.
Compliant, non-compliant, or unable to assess. The fourteen-day window and the in-scope definition applied as the scheme states them.
A prioritised list of the devices that fall short, worked by your device team or ours under your approval.
The engine produces the evidence and the prioritised list. Your device team or ours acts on it under your approval.
You gain:
FAQ
It covers the device-level technical controls that live in your management and protection tooling. The organisational controls remain yours to evidence.