CLOUDMECHANIX
Fixed scope · 5 business days

Azure Environment Review

A fixed-scope, read-only assessment of your Azure estate against the Microsoft Well-Architected Framework, with an eye to ISO 27001 and NIS2. You get a written report, a prioritised remediation plan, and a walkthrough. We change nothing in your environment — this is an assessment, not a project.

Fixed scope, fixed price — quoted on enquiry.

Who it's for

You'll recognise the situation.

  • You're in Azure but nobody is sure it's built right.
  • The board or an auditor is asking NIS2 or security questions you cannot yet answer.
  • You're about to migrate more workloads and want to fix the foundation first.
  • You've inherited an Azure estate and need an honest picture of it.
Scope

How it runs.

Five business days from the day read-only access is granted. The walkthrough is on day five.

  1. Day 1 — Kick-off

    We confirm scope, take read-only access, and agree the subscriptions and workloads in scope.

  2. Days 2–3 — Assessment

    We work through the five Well-Architected pillars — reliability, security, cost optimisation, operational excellence, performance efficiency — plus identity, networking and governance.

  3. Day 4 — Analysis

    We turn findings into a prioritised remediation plan, ranked by risk and effort.

  4. Day 5 — Report & walkthrough

    You get the written report and plan, and we walk your team through it on a call.

What you get

The deliverable.

  • A written report: findings by Well-Architected pillar, with evidence and a risk rating for each.
  • A prioritised remediation plan: what to fix, why it matters, and the rough effort.
  • A 60–90 minute walkthrough call with your team.
  • The raw findings, so nothing is hidden behind a summary.
Report outline

What's in it.

  1. 01Executive summary
  2. 02Scope and method
  3. 03Findings by Well-Architected pillar
  4. 04Identity and access
  5. 05Networking and segmentation
  6. 06Security operations and logging
  7. 07Cost
  8. 08Governance and policy
  9. 09Prioritised remediation plan
  10. 10Appendix — evidence
What we need

Prerequisites.

  • Reader and Security Reader access to the subscriptions in scope.
  • A named technical contact for the kick-off and any questions.
  • Any existing architecture documentation, if you have it.
Out of scope

What it isn't.

  • We make no changes — the review is read-only.
  • It is not a penetration test.
  • It is not a full ISO 27001 audit or NIS2 certification — it tells you where you stand.
  • Delivering the remediation is a separate engagement, at your option.
Afterwards

What happens next.

You own the report. Fix it with your own team, or we can deliver the remediation as a separate fixed-scope engagement. There is no obligation either way.

Questions

Frequently asked.

Do you change anything in our environment?
No. The review is read-only. We take Reader-level access and make no changes.
Who from our side needs to be involved?
One named technical contact for the kick-off and to grant access. Beyond that, we work independently until the walkthrough.
What access do you need?
Reader and Security Reader on the subscriptions in scope. Nothing that lets us make changes.
Is this a penetration test?
No. It is an architecture and configuration review against the Well-Architected Framework, not an offensive security test.
Does it certify us for NIS2 or ISO 27001?
No. It tells you where you stand against them and what to fix. Certification is a separate, formal process.
What does it cost?
Fixed scope, fixed price — quoted on enquiry. Larger or multi-tenant estates are scoped and quoted accordingly.
What if we have several subscriptions or tenants?
We agree the scope up front. A larger estate takes more time, and that is reflected in the quote before we start.
Can you fix what you find?
Yes — as a separate engagement, with no obligation. Many clients fix the quick wins themselves and bring us in for the harder items.

Azure Environment Review — start with a conversation.

Fixed scope, fixed price — quoted on enquiry.