START HERE
Cybersecurity Assessment
Find out where you actually stand, in two to four weeks.
Starting at $15,000
Nearly every engagement starts with an assessment, because you cannot price or plan the rest without one. What follows depends on what it finds.
START HERE
Find out where you actually stand, in two to four weeks.
Starting at $15,000
ONGOING COVERAGE
A security leader on your org chart, without the salary line.
From $3,000 per month
ONGOING COVERAGE
Stay compliant between audits, without hiring a team to do it.
From $5,500 per month
Bought for a specific reason rather than as a general program. Often alongside one of the above, sometimes on their own.
Everything needed to stand up a compliance focused security program.
Organisations that know which framework they need and want the program built rather than described.
Test against the benchmark your assessor will use.
Teams shipping software that holds sensitive data, teams whose customers now require a third party penetration test before they will sign, and teams that need an Authority to Operate to host on a DoD system.
AI security and AI compliance now sit with our sister practice, BlueSteel AI.
Protect patient data without stopping care delivery.
GSA Schedule, cleared facility, and ten years of ATOs inside the IC.
GSA Schedule 47QTCA23D000B · Cleared facility, Secret level · Fixed price, simplified acquisition friendly
| Framework | Who it applies to | Time to ready |
|---|---|---|
| SOC 2 Type II · AICPA TSC | SaaS and service providers holding customer data | 8 to 12 weeks to audit ready |
| HIPAA Security Rule · 45 CFR 164 | Providers, payers, and the vendors who touch their data | 6 to 10 weeks to a defensible posture |
| CMMC Level 2 · NIST SP 800-171 | Defense contractors and subs handling CUI | 4 to 9 months, driven by your SPRS gap |
| ISO 27001 ISO/IEC 27001:2022 | Organisations selling internationally or to enterprise buyers | 6 to 12 months to certification |
Cloud services selling to federal agencies. 12 to 18 months, sponsor dependent.
Healthcare organisations and their vendors. 9 to 18 months for r2, less for e1 and i1.
Contractors and subcontractors handling CUI. 3 to 9 months depending on the current SPRS gap.
Federal systems and the contractors operating them. 6 to 18 months, driven by baseline and boundary.
Software producers selling to the federal government. 2 to 6 months depending on pipeline maturity.
Any organisation wanting a defensible security programme. 2 to 4 months to a current and target profile.
If your framework is not listed, ask. The control work overlaps more than the framework names suggest.
That is what the call is for. Bring the framework, the deadline, and who is asking for it, and we will tell you which of these applies and what it costs.
hello@bluesteelcyber.com or (301) 531-4254