From gap assessment to audit day, done for you.
Eight frameworks taken end to end. We build the controls, do the remediation ourselves, and coordinate your auditor directly.
Compliance arrives as a condition of something you want.
Compliance shows up as a condition of something you want: an enterprise deal that requires SOC 2, an insurer asking questions, a contract that names HIPAA or PCI DSS. Most consultants hand you a findings report and leave the work with you. We do it the other way around: the gap assessment maps what has to change, our engineers make the changes, evidence is collected as we go, and the audit becomes a review of work already done.
Gap assessment
We audit your posture against the framework and map exactly what needs to change, in plain language and in priority order.
Remediation, by us
Our engineers implement the controls. You get the work done for you, not a to-do list to staff on your own.
Audit preparation
We prepare the documentation and evidence pack and coordinate with your auditor directly.
Ongoing maintenance
Controls and evidence are maintained year round, so renewal is a review rather than a second project.
Every audit we run, in plain language.
Who each framework is for, what the audit involves, and what we do. Open the one your contract names.
SOC 2 Type I & IISAAS AND SERVICE PROVIDERS SELLING TO ENTERPRISE
An independent CPA attestation that your security controls are designed properly (Type I) and operate over time (Type II). Usually triggered by an enterprise customer's procurement process.
- Design the control set and implement it in your actual stack
- Wire evidence collection into the tools you already run
- Coordinate the auditor and answer the technical questions
HIPAAHEALTHCARE BUSINESSES AND THEIR VENDORS
The security and privacy safeguards required around protected health information, resting on a documented risk analysis. Applies to practices and to the business associates that serve them.
- Run the security risk analysis and fix what it finds
- Encrypt devices, control EHR access, and log activity on PHI systems
- Keep BAAs, training records, and evidence audit-ready
PCI DSSANY BUSINESS THAT TAKES CARD PAYMENTS
The card networks' security standard. Your merchant level and setup decide the questionnaire and scanning you owe; a wrong answer becomes your liability after a breach.
- Determine your actual SAQ scope, then shrink it with segmentation
- Harden and monitor everything that touches card data
- Run the quarterly ASV scans and remediate findings
ISO 27001BUSINESSES WITH INTERNATIONAL CLIENTS
The international standard for an information security management system, certified by an accredited body and maintained through surveillance audits.
- Scope the ISMS and build the risk register
- Write the policy set to match how you actually operate
- Prepare and support the certification and surveillance audits
NIST CSFFEDERAL-ADJACENT WORK, INSURERS, BOARDS
Not a certification but the reference framework most US security questionnaires and cyber insurers reason from. A maturity baseline the rest of your program can hang off.
- Assess current posture against the framework functions
- Prioritise the gaps by real risk, not checkbox order
- Deliver a roadmap the board and the insurer can read
CMMCDOD CONTRACTORS AND SUBCONTRACTORS
The Department of Defense's certification for handling federal contract information and CUI. Your contracts dictate the level; assessment is by a certified third party.
- Determine the level your contracts actually require
- Implement the NIST 800-171 controls and score honestly in SPRS
- Prepare the environment and evidence for the C3PAO assessment
FedRAMPCLOUD PRODUCTS SOLD TO FEDERAL AGENCIES
The federal authorization program for cloud services. A long, sponsored process, and the honest first step is finding out whether you need it at all or can land under a partner's authorization.
- Assess readiness and the realistic path, including partner options
- Build the technical baseline toward the required controls
- Support the documentation package and assessment process
GDPRANYONE HANDLING EU PERSONAL DATA
The EU's data protection regulation. For a US small business it mostly means knowing what personal data you hold, answering subject requests on time, and having the right terms with processors.
- Map the personal data you actually hold and why
- Stand up a subject-request process your team can follow
- Put DPAs and transfer terms in place with your vendors
Asked before they start.
What owners ask us about this service. The rest is on the full FAQ page.