Back in June we wrote about our journey towards listing on the UK Government's G-Cloud framework, and promised to keep a live tracker of where each milestone stands. It's been a couple of months, so here's an honest account of what's moved since — and, just as importantly, what hasn't.
What's moved
Security review and hardening. This has been the bulk of the work, and it's the part that doesn't photograph well. We've run further structured reviews across the platform — server, database and mobile apps — and fixed what they turned up, each fix shipping with automated tests so the same problem can't quietly come back. Our test suite now stands at over 4,800 tests that run before anything is released.
We think it's worth being straightforward about what a security review is: it's a process that finds things. A supplier who tells you their review found nothing either hasn't looked properly or isn't telling you. What matters is whether problems get found, understood and closed — and whether there's a record of it. We keep one.
Up-to-date foundations. We've upgraded the cryptography and database libraries our server depends on to current, supported versions, and removed older components we no longer need. Running unsupported software is one of the things Cyber Essentials asks about directly, and it's a fair question — out-of-date libraries are one of the most common ways systems get compromised.
Information security policies. We've drafted our written policies covering access control, incident response, change management, and backup and recovery. These are the documents a buyer's information-governance team asks for, and we've deliberately kept them to what we genuinely do rather than what sounds impressive. A policy you don't follow is worse than no policy at all.
Resilience. Our server now runs as a managed service with unattended updates, and we've documented and tested the path to rebuild our infrastructure from scratch. That's the honest answer to "what happens if a server is lost", and it's evidence for the business-continuity plan rather than an assertion.
What hasn't moved — and why
The Cyber Essentials certificate. In June we said this was well underway. It still is, and it still isn't finished. Our self-assessment is essentially complete and most of the technical work behind it is done, but there are a handful of items we want genuinely closed rather than declared closed before we certify. Cyber Essentials is a self-assessment, which means the certificate is only worth what the honesty behind it is worth. We'd rather take a few more weeks than tick a box we can't stand behind.
The independent accessibility audit. Still to be commissioned. Public-sector software has to be usable by everyone, and an audit against WCAG 2.2 AA needs an external specialist and real lead time. Our accessibility statement is already published and describes where our apps stand today, including known issues.
Terms and conditions. With a solicitor. Not something we can hurry, and not something we should.
On the timing
The current application window has closed and the framework goes live in September 2026, reopening to new suppliers at intervals after that. We'll apply at the very next opportunity.
That gives us real runway, and we'd rather use it than waste it. There's a version of this project where we rush the paperwork to be "ready" months early, and the certificates and legal reviews then age while we wait. The more useful version is the one we're doing: get the substantive work right, keep the security and accessibility improvements landing in the product where they benefit crews today, and have the time-limited pieces current when the window actually opens.
None of this work is wasted if the timetable moves. Better data protection, a tighter security posture and a more accessible app are worth having whether or not a framework listing ever follows.
Where to check
Our progress tracker is public and shows every milestone with its current status — complete, in progress, or still to come. It's at 74% by our own count, and we're not going to round that up. We update it as things land, and we'll post again when the Cyber Essentials certificate is in hand.
If you're at a fire & rescue service or coastguard team and want to talk about any of this — including the parts that aren't finished — we're happy to. Get in touch at hello@ifireapp.org.