What a technology assessment actually involves

Every provider offers one. Not every provider means the same thing by it. What a real assessment produces, what it costs, and the version that is actually a sales call wearing a different name.

A checklist on a clipboard on an office desk

Two things called an assessment

"Book a free assessment" and "book a technology assessment" get used almost interchangeably in this industry, and they are not the same offer. One is a sales conversation — thirty minutes, a few questions, a proposal by the end of the week. The other is an actual audit: someone inventories your environment, tests specific claims rather than accepting them, and hands you a written position on where you stand.

Neither is dishonest. The problem is the label does not tell you which one you are booking, and a thirty-minute call dressed up as an "assessment" sets an expectation it was never built to meet.

What a real assessment actually produces

A genuine technology assessment produces a document, not an impression. At minimum it should give you: a real asset inventory — every device, identity, licence and control actually in use, not assumed; a backup test, not a backup status check, because a backup job reporting "success" and a backup that actually restores are different claims; and a score against a named framework, in our case the Essential Eight, so "your security is weak" becomes "you are at maturity level zero on application control and patch timeframes, specifically."

If what comes back is a slide deck of general recommendations with no numbers attached to your specific environment, it was a sales conversation, whatever it was called when you booked it.

What the two weeks actually involve

Our own assessment runs two weeks, and the time is not padding. Week one is discovery: every asset, identity and licence catalogued against what is actually deployed, not what a purchasing record says should be there — the two regularly disagree. A restore test runs against your actual backups, not a status dashboard. Week two is scoring and writing: the Essential Eight assessment against the eight strategies and three maturity levels, and a written position with the findings, prioritised by what actually creates risk rather than listed alphabetically.

Why you keep the report either way

The report is yours whether or not you engage the provider that produced it. That detail matters more than it sounds: it changes what the assessor is actually incentivised to find. An assessment structured as a precursor to a sale is incentivised to find just enough to justify one. An assessment you keep regardless is not — which is also why it is reasonable to expect to pay a fixed fee for one rather than get it "free," and reasonable to be suspicious of an assessment that costs nothing and somehow always concludes you need everything the provider sells.

How to tell which one you are being offered

  • Ask what document you receive at the end, specifically — a written report with your data in it, or a proposal.
  • Ask whether it is free, and if so, ask directly what the incentive is to find problems rather than reassurance.
  • Ask if backups are actually restored during the assessment, or only checked for a "success" status in a dashboard.
  • Ask what framework the security scoring uses, by name. "We'll review your security posture" with no named framework behind it usually means no scoring at all.

Questions

How long should a genuine technology assessment take?

For a typical small-to-mid-sized organisation, around two weeks. Longer for multi-site or heavily regulated environments, and meaningfully shorter than that is usually a sign of a lighter-touch review than the name implies.

Should a technology assessment be free?

It can reasonably be either, but the price tells you something about the incentive. A fixed fee that produces a report you keep regardless of what you decide afterwards is a cleaner arrangement than a free assessment offered by the same organisation that is hoping to sell you the fix.

Do we need a technology assessment if we already have an IT provider?

It is often more useful in that situation, not less — an independent assessment is the way to verify what your current provider has been reporting, rather than take the monthly dashboard on faith.

Two weeks, a fixed fee, and a report that is yours either way

If we are not the right fit afterwards, you still keep the written position on your environment.