ESTABLISHED 2015 · LOS ANGELES, CAFREE 30 MINUTE ASSESSMENT · YOU KEEP THE FINDINGS GET YOURS →
HOME / SERVICES / COMPLIANCE AUDITS
SERVICE 03 · PROJECT ยท THEN ONGOING MAINTENANCE

From gap assessment to audit day, done for you.

Eight frameworks taken end to end. We build the controls, do the remediation ourselves, and coordinate your auditor directly.

8
FRAMEWORKS COVERED
IN-HOUSE
REMEDIATION
YEAR-ROUND
EVIDENCE UPKEEP
WHY IT MATTERS

Compliance arrives as a condition of something you want.

Compliance shows up as a condition of something you want: an enterprise deal that requires SOC 2, an insurer asking questions, a contract that names HIPAA or PCI DSS. Most consultants hand you a findings report and leave the work with you. We do it the other way around: the gap assessment maps what has to change, our engineers make the changes, evidence is collected as we go, and the audit becomes a review of work already done.

WHAT’S INCLUDED
Gap assessment and control mappingPROJECT START
Remediation, done by usINCLUDED
Evidence collection and document prepCONTINUOUS
Auditor coordinationPER AUDIT
Ongoing control maintenanceMONTHLY
WHAT YOU RECEIVE
Gap assessment and control mapPROJECT START
Policy set written for your stackMAINTAINED
Evidence pack for the auditorAUDIT-READY
Control maintenance logMONTHLY
← ALL SERVICES
HOW IT RUNS
STEP 01

Gap assessment

We audit your posture against the framework and map exactly what needs to change, in plain language and in priority order.

STEP 02

Remediation, by us

Our engineers implement the controls. You get the work done for you, not a to-do list to staff on your own.

STEP 03

Audit preparation

We prepare the documentation and evidence pack and coordinate with your auditor directly.

STEP 04

Ongoing maintenance

Controls and evidence are maintained year round, so renewal is a review rather than a second project.

THE FRAMEWORKS

Every audit we run, in plain language.

Who each framework is for, what the audit involves, and what we do. Open the one your contract names.

SOC 2 Type I & IISAAS AND SERVICE PROVIDERS SELLING TO ENTERPRISE

An independent CPA attestation that your security controls are designed properly (Type I) and operate over time (Type II). Usually triggered by an enterprise customer's procurement process.

WHAT WE DO
  • Design the control set and implement it in your actual stack
  • Wire evidence collection into the tools you already run
  • Coordinate the auditor and answer the technical questions
OUTCOME · TYPE I ON THE DEAL TIMELINE, TYPE II AS A FORMALITY AFTER
HIPAAHEALTHCARE BUSINESSES AND THEIR VENDORS

The security and privacy safeguards required around protected health information, resting on a documented risk analysis. Applies to practices and to the business associates that serve them.

WHAT WE DO
  • Run the security risk analysis and fix what it finds
  • Encrypt devices, control EHR access, and log activity on PHI systems
  • Keep BAAs, training records, and evidence audit-ready
OUTCOME · SAFEGUARDS IN PLACE, DOCUMENTATION AN AUDITOR OR INSURER ACCEPTS
PCI DSSANY BUSINESS THAT TAKES CARD PAYMENTS

The card networks' security standard. Your merchant level and setup decide the questionnaire and scanning you owe; a wrong answer becomes your liability after a breach.

WHAT WE DO
  • Determine your actual SAQ scope, then shrink it with segmentation
  • Harden and monitor everything that touches card data
  • Run the quarterly ASV scans and remediate findings
OUTCOME · A DEFENSIBLE SAQ, PASSING SCANS, AND A SMALLER CARD-DATA FOOTPRINT
ISO 27001BUSINESSES WITH INTERNATIONAL CLIENTS

The international standard for an information security management system, certified by an accredited body and maintained through surveillance audits.

WHAT WE DO
  • Scope the ISMS and build the risk register
  • Write the policy set to match how you actually operate
  • Prepare and support the certification and surveillance audits
OUTCOME · CERTIFICATION YOUR OVERSEAS CLIENTS RECOGNISE
NIST CSFFEDERAL-ADJACENT WORK, INSURERS, BOARDS

Not a certification but the reference framework most US security questionnaires and cyber insurers reason from. A maturity baseline the rest of your program can hang off.

WHAT WE DO
  • Assess current posture against the framework functions
  • Prioritise the gaps by real risk, not checkbox order
  • Deliver a roadmap the board and the insurer can read
OUTCOME · A DEFENSIBLE MATURITY PICTURE AND A COSTED PATH UP FROM IT
CMMCDOD CONTRACTORS AND SUBCONTRACTORS

The Department of Defense's certification for handling federal contract information and CUI. Your contracts dictate the level; assessment is by a certified third party.

WHAT WE DO
  • Determine the level your contracts actually require
  • Implement the NIST 800-171 controls and score honestly in SPRS
  • Prepare the environment and evidence for the C3PAO assessment
OUTCOME · AN ASSESSABLE ENVIRONMENT AND A SCORE YOU CAN STAND BEHIND
FedRAMPCLOUD PRODUCTS SOLD TO FEDERAL AGENCIES

The federal authorization program for cloud services. A long, sponsored process, and the honest first step is finding out whether you need it at all or can land under a partner's authorization.

WHAT WE DO
  • Assess readiness and the realistic path, including partner options
  • Build the technical baseline toward the required controls
  • Support the documentation package and assessment process
OUTCOME · A CLEAR GO OR NO-GO, AND REAL PROGRESS IF IT IS GO
GDPRANYONE HANDLING EU PERSONAL DATA

The EU's data protection regulation. For a US small business it mostly means knowing what personal data you hold, answering subject requests on time, and having the right terms with processors.

WHAT WE DO
  • Map the personal data you actually hold and why
  • Stand up a subject-request process your team can follow
  • Put DPAs and transfer terms in place with your vendors
OUTCOME · A RECORDS-OF-PROCESSING FILE AND A REQUEST PROCESS THAT WORKS
COMMON QUESTIONS

Asked before they start.

What owners ask us about this service. The rest is on the full FAQ page.

Which frameworks do you cover?
SOC 2 Type I and II, HIPAA, PCI DSS, ISO 27001, NIST CSF, CMMC, FedRAMP, and GDPR. If a client or regulator has named a framework we have not listed, ask: the underlying controls overlap far more than the acronyms suggest.
How long does it take to get through an audit?
It depends on the size of the gap, which is exactly what the assessment measures. At the end of it you get a realistic timeline for your environment rather than a generic promise. Fast-track work, for example a startup that needs SOC 2 Type I for a deal, is planned around the deal date.
Do you work with our auditor or bring your own?
Either. If you have an auditor we coordinate with them directly, and if you do not we help you select one. We prepare the evidence and answer the technical questions, so your team is not pulled into audit season.

Find out where you stand in 30 minutes.

NO COMMITMENT  ·  NO SALES PITCH  ·  THE FINDINGS ARE YOURS
Get your free assessment →
Call (213) 266-7279Free assessment →