START HERE
Cybersecurity Assessment
Find out where you actually stand, in two to four weeks.
Starting at $15,000 · 2 to 4 weeks
BlueSteel takes healthcare and defense organizations from gap assessment to attestation. We build the evidence as the work happens, so nobody spends the week before fieldwork reconstructing a year of access reviews.
| Framework | Who it applies to | What triggers the call | Time to ready |
|---|---|---|---|
| SOC 2 Type II · AICPA TSC | SaaS and service providers holding customer data | An enterprise prospect's security review stalled the deal | 8 to 12 weeks to audit ready |
| HIPAA Security Rule · 45 CFR 164 | Providers, payers, and the vendors who touch their data | A BAA, a health-system security review, or a reported incident | 6 to 10 weeks to a defensible posture |
| CMMC Level 2 · NIST SP 800-171 | Defense contractors and subs handling CUI | A CMMC clause appeared in a solicitation or a prime's flow-down | 4 to 9 months, driven by your SPRS gap |
| ISO 27001 ISO/IEC 27001:2022 | Organisations selling internationally or to enterprise buyers | A customer, often outside the US, asked for the certificate | 6 to 12 months to certification |
Also FedRAMP, HITRUST, NIST CSF, and NIST SP 800-171, 800-53 and 800-218. See all frameworks.
Nearly every engagement begins the same way: a scored picture of where you actually stand, at a fixed price, with no obligation to do anything next. What comes after depends on what it finds.
START HERE
Find out where you actually stand, in two to four weeks.
Starting at $15,000 · 2 to 4 weeks
ONGOING COVERAGE
A security leader on your org chart, without the salary line.
From $3,000 per month · Monthly, no long term lock in
ONGOING COVERAGE
Stay compliant between audits, without hiring a team to do it.
From $5,500 per month · Monthly, no long term lock in
The same four phases regardless of framework. What changes is the boundary, the control set, and who signs at the end.
Most cost overruns are scoping failures. We narrow what is in scope, including systems, data, people and subcontractors, before touching a single control. On CMMC this one decision routinely removes months.
A real gap assessment against the actual control set, scored, with the uncomfortable findings written down. You get the list your assessor will produce, before they produce it.
We fix what is broken and wire up the evidence at the same time. Access reviews, change records, log retention and vendor reviews should generate their own artifacts on a schedule.
Auditor or C3PAO coordination through fieldwork, then a maintenance cadence so the next cycle is a review rather than a rebuild.
Providers, digital health platforms and the vendors who sit inside their data flows. The work is usually a Security Rule risk analysis that will hold up under scrutiny, a defensible ePHI inventory, and a BAA process that is not a folder of signed PDFs nobody has read.
Primes and subcontractors with a CMMC clause in a solicitation and a SPRS score that will not survive contact with a C3PAO. We scope the enclave, close the practices that reliably fail, and author the SSP that carries the assessment.
If AI tools are already inside your scope, and in most organizations they are, our sister practice BlueSteel AI handles AI security assessments, fractional AI security officers and AI engineering builds. Same firm, same fixed pricing approach.
Notes from assessments, written for the person who has to implement the control.
Our full article archive lives in The Vault, which stays on its existing home while the rest of the site moves. Every article is where it has always been.
Thirty minutes. Bring the framework, the deadline, and who is asking for it. You will leave with a scope, a rough timeline and an honest answer about whether the deadline is reachable.
Prefer to write first? Send a note instead.