Continuous Cyber Essentials Plus, for UK estates

Stay Cyber Essentials Plus Compliant

Ship the Fix, Not Just the Finding.

APaaS Assure maps every application and its real usage to live NIST NVD and CISA KEV vulnerabilities, holds each to the Cyber Essentials 14-day clock, then packages and deploys the remediation to Intune or Configuration Manager. One platform for the IT teams and service providers keeping UK estates certified.

NCSC CE+ aligned methodology · ISO 27001 hosting · UK data residency

One console - end to end

DetectReportPackageDeploy / AutomateGovern
Software Cyber Security Vulnerability Reporting CISA KEV & NVD Daily Reviews Executive Dashboards Application Rationalisation Automated Packaging (MSI, MST, EXE, PSADT) PSADT-Friendly Editor Automated Patching Intune & SCCM Automation Workplace Automation Licence Management Application Governance Security Patching Intune Deployment Health Checks ConfigMgr Deployment Health Checks
Product tour

See it in action

Unique to EUC and the modern IT workplace - from risk to resolution in one application.

Software Cyber Essentials risk register
Software Cyber Essentials Risk Register
Application governance and 5Rs
Application Governance & 5Rs
Licence management and savings
Licence Management & Savings
Automated app packaging MSI PSADT EXE
Automated App Packaging (MSI, PSADT, EXE)
PSADT editor - package to your standards
Package to Your Standards - PSADT Editor
Deploy straight to Intune and SCCM
Deploy Straight to Intune & SCCM
Workplace automation
Workplace Automation
Connect Intune SCCM and ITAM
Connect Intune, SCCM & ITAM
Security Patches dashboard - missing Windows Updates via the APaaS Assure agent
Security Patches - find & fix missing updates
Patch compliance report - found, installed and percentage improvement
Patch report - found, installed & % improvement
100 percent patch compliance after agent remediation
From exposed to 100% patch compliant

Trusted by UK enterprises

Water & utilities Infrastructure consultancy Defence & aerospace Transport & rail Built environment

Most tools tell you what's wrong. This one helps you fix it.

CE+ is a single point in time. Your estate isn't - and over 100 new CVEs are published every day. APaaS Assure closes the loop from exposure to packaged fix, in one console.

Unified estate inventory

Your ITAM, Intune MDM and our lightweight agent in one normalised view. Where ITAM reports "Edge v1", the agent fills in the full build - plus accurate per-application usage, so you can right-size licences and evidence real software savings. No CSV reconciliation, no blind spots.

KEV-aware risk register

CISA KEV + NIST NVD overlaid on your live estate every 4 hours, with an SLA clock mapped to the CE+ 14-day patch window and breach alerts against Annex A.

5Rs rationalisation

Per-app and per-version Retain · Reduce · Replace · Remove · Replatform plans driven by real usage data - on every product in the estate, catalogued or not. Manual override at any level, fully audited.

Automated packaging

Pick an app, and the platform downloads the latest release and wraps it in PSAppDeployToolkit v3 to your client standards - install logic, audit keys, hardening, documentation. The work an outsourced packaging house bills at £5,000 and a fortnight, your team completes in minutes - then deploys straight to Intune or Configuration Manager.

Version intelligence

A live answer to "is this actually the latest?" for every product. Semantic version comparison stops false "update available" noise, and you control the source for any app - point a monitor at a vendor page and pick the version with a click. No more guessing what's current.

Workplace automation & governance

Approve, reject or hold every product with a full decision trail - then let the agent do the legwork. Scheduled maintenance jobs keep devices clean and efficient (disk cleanup, update repair, housekeeping), while hardware-health monitoring catches failing disks, low space and battery wear and rolls out the fix automatically. One auditable console instead of four.

CE+ pre-assessment

Measure a client against the five Cyber Essentials Plus controls before the assessor does. Automated checks and agent probes score every device, show exactly what fails, and build the action plan and evidence trail to a pass.

Microsoft 365 licence optimisation

Cloud-side SAM through Microsoft Graph - who's using what, on desktop, mobile or web. Finds inactive licences, duplicate and unused seats, and desktop plans used only on the web, every finding costed in pounds. Reuses your Intune connection, read-only.

Endpoint protection health

Defender and anti-malware health from the agents - protection state, real-time scanning, signature age, tamper protection and risky exclusions, scored per device. Connect Defender for Endpoint for alerts, incidents and exposure.

What good looks like with APaaS Assure

Outcomes we underwrite in the contract - backed by continuous data refresh, the rationalisation engine and automated packaging.

14 days CE+ patch window tracked live against every KEV exposure
4 hrs Refresh cadence for CISA KEV & NIST NVD overlay
Minutes To package an app to your standards - vs. the ~2 weeks an outsourced house quotes
100+ New CVEs published every day - all correlated to your estate, not a generic feed
28% Typical software estate retired in year one
99.95% Platform uptime SLA, UK-region hosted
100% Audit-trail coverage on every 5Rs and governance decision
£150k+ Typical stitched-stack tooling spend displaced

Customer-specific outcomes vary by estate size, sector and existing tooling. We agree measurable targets up front during Pilot - what we don't hit, we don't bill for. Industry packaging cost based on outsourced day-rate quotes; CVE volume per NIST NVD (over 40,000 published in 2024).

CUSTOMER STORY

"We retired 137 apps with zero user complaints and shaved 31% off our software spend in the first quarter - and the repackaging that used to go out to a third party now happens in-house in an afternoon."

IT Director · UK water utility · 8,500 devices

Apps retired137
Spend saved31%
Time to first audit14 days
KEV exposures closed412

From exposure to packaged fix

Detection is table stakes. The platform takes you all the way to a deployable package.

  1. 1

    Connect

    Connect your ITAM / Intune / our agent in 60 minutes. We auto-discover every device and application.

  2. 2

    Correlate

    Your estate is matched against NIST NVD and CISA KEV every 4 hours, with the true latest version for each product.

  3. 3

    Prioritise

    The 5Rs engine ranks every product by usage and exposure. KEV-listed risks jump the SLA queue.

  4. 4

    Package

    Automate the fix: the platform fetches the latest release and wraps it in PSADT v3 to your client standards, documented.

  5. 5

    Deploy & evidence

    Deploy packages straight to Microsoft Intune and Configuration Manager, and export board- and auditor-ready CE+ evidence - the whole chain auditable end to end.

Replaces the stack - and the packaging house

Customers with 8,500 devices typically displace a four-tool stack costing £150k+ a year. The tools in that stack find the problem; none of them package the fix.

The stitched stack

  • Compliance automation (Drata, Vanta) · £40k
  • Vulnerability mgmt (Tenable, Qualys) · £55k
  • SAM & rationalisation (Flexera) · £120k
  • Patch & RMM (NinjaOne) · £141k
  • Outsourced packaging · £5k+ per app

Total: ~£356k / year + per-app fees

Five bills · four UIs · detection only

APaaS Assure

  • Continuous CE+ compliance & audit evidence
  • KEV-aware risk register with SLA clock
  • 5Rs rationalisation on the whole estate
  • Unified ITAM · MDM · agent inventory
  • Automated packaging to your standards

From £80k / year

One platform · one dashboard · finds and fixes · UK support

See where your estate is exposed today.

UK-based onboarding · No procurement friction

Book a demo