ONGOING COVERAGE
Everything needed to stand up a compliance focused security program.
What it is
Where the assessment tells you what is missing, compliance preparation builds it. We deliver the policies, procedures and technical solutions that address each control requirement, so your team is left implementing a program rather than authoring one from a blank page.
Who it is for. Organisations that know which framework they need and want the program built rather than described.
What is included
- Policies and procedures written against your actual control requirements, not a template pack
- Technical solutions mapped to each requirement so nothing is left as an unassigned line item
- A program your team can implement to satisfy the runtime evidence an assessor will ask for
- Expertise across the NIST 800 series, CMMC, SOC 2, STIG, OWASP, HITRUST, ISO 27001, Zero Trust, FedRAMP and HIPAA
What you end up with
A compliance program that exists as documents, controls and running processes rather than as an intention. Most clients then move it into managed compliance so it stays true.
How pricing works
Priced against the framework and the size of the environment it applies to. Quoted on the call and fixed from that point. If you are not yet sure which framework applies, start with an assessment.
- Your price is quoted on the free scoping call, not after we have started.
- Once quoted, it is fixed. No hourly billing and no change orders.
- Continue into a Virtual CISO or managed compliance engagement within 90 days and you take 25% off the first year of it.
Also available
Cybersecurity Assessment
Find out where you actually stand, in two to four weeks.
Virtual CISO
A security leader on your org chart, without the salary line.
Talk about a compliance program
Thirty minutes. Bring the framework, the deadline, and who is asking for it.