BlueSteel Cybersecurity

Everything we do, in the order people buy it.

Nearly every engagement starts with an assessment, because you cannot price or plan the rest without one. What follows depends on what it finds.

Core services

Specialist services

Bought for a specific reason rather than as a general program. Often alongside one of the above, sometimes on their own.

  • Compliance Preparation

    Everything needed to stand up a compliance focused security program.

    Organisations that know which framework they need and want the program built rather than described.

  • Application Security and Penetration Testing

    Test against the benchmark your assessor will use.

    Teams shipping software that holds sensitive data, teams whose customers now require a third party penetration test before they will sign, and teams that need an Authority to Operate to host on a DoD system.

  • AI Compliance

    AI security and AI compliance now sit with our sister practice, BlueSteel AI.

Who we work with

  • Healthcare Cybersecurity

    Protect patient data without stopping care delivery.

  • Defense and Government Services

    GSA Schedule, cleared facility, and ten years of ATOs inside the IC.

    GSA Schedule 47QTCA23D000B · Cleared facility, Secret level · Fixed price, simplified acquisition friendly

Frameworks we take clients through

Framework Who it applies to Time to ready
SOC 2 Type II · AICPA TSC SaaS and service providers holding customer data 8 to 12 weeks to audit ready
HIPAA Security Rule · 45 CFR 164 Providers, payers, and the vendors who touch their data 6 to 10 weeks to a defensible posture
CMMC Level 2 · NIST SP 800-171 Defense contractors and subs handling CUI 4 to 9 months, driven by your SPRS gap
ISO 27001 ISO/IEC 27001:2022 Organisations selling internationally or to enterprise buyers 6 to 12 months to certification

Also supported

  • FedRAMP

    Cloud services selling to federal agencies. 12 to 18 months, sponsor dependent.

  • HITRUST

    Healthcare organisations and their vendors. 9 to 18 months for r2, less for e1 and i1.

  • NIST SP 800-171

    Contractors and subcontractors handling CUI. 3 to 9 months depending on the current SPRS gap.

  • NIST SP 800-53

    Federal systems and the contractors operating them. 6 to 18 months, driven by baseline and boundary.

  • NIST SP 800-218

    Software producers selling to the federal government. 2 to 6 months depending on pipeline maturity.

  • NIST CSF

    Any organisation wanting a defensible security programme. 2 to 4 months to a current and target profile.

If your framework is not listed, ask. The control work overlaps more than the framework names suggest.

5.0 out of 5

Across 17 verified client reviews on Clutch.

  • Quality 4.9
  • Schedule 5.0
  • Cost 4.9
  • Willing to refer 5.0

Not sure which one you need?

That is what the call is for. Bring the framework, the deadline, and who is asking for it, and we will tell you which of these applies and what it costs.

hello@bluesteelcyber.com or (301) 531-4254