SOC 2, ISO 27001, HIPAA, CMMC

Compliance & Audit Readiness

We run the certification, not just advise on it: scoping, control design, evidence, auditor management and the operating rhythm that keeps you compliant in year two without another fire drill.

The situation

Compliance is blocking revenue, and the deadline is real

  • A customer contract or an investor is gating on SOC 2, ISO 27001 or HIPAA attestation.
  • You bought a compliance automation platform and discovered it doesn't do the work for you.
  • Last year's audit was survived, not run, and nobody wants to repeat it.

What we do

  • Scope the audit honestly: the right systems, the right boundary, the right trust criteria
  • Perform gap analysis against the target framework with a remediation plan you can staff
  • Design controls that fit how your team actually works, so they survive year two
  • Write the policy set, procedures and system description
  • Build the evidence pipeline and automate collection where it is worth automating
  • Configure and actually operate Vanta, Drata, Secureframe or your GRC platform of choice
  • Select and manage the auditor, and run the fieldwork so your engineers stay shipping
  • Handle customer security questionnaires, CAIQ, HECVAT and enterprise vendor reviews
Deliverables

What you actually receive.

Artefacts your team can operate after we leave, not a slide deck and a wave goodbye.

DeliverableWhat it contains
Readiness assessmentGap-by-control view with effort estimates and a critical path to audit date
Control set and policy libraryMapped across every framework you carry, written once
Evidence systemOwners, cadence, automation and a repository the auditor can walk
Auditor managementSelection, scoping, fieldwork coordination and finding response
Trust packagePublic trust page content, security whitepaper and standard questionnaire answers
Sustainment planThe annual calendar that keeps the certificate without the fire drill
Coverage

Frameworks we take clients through.

Carrying several of these should not mean maintaining several control sets. We map once and reuse the evidence.

SOC 2 Type I & IIISO/IEC 27001:2022ISO/IEC 27701ISO/IEC 42001HIPAA / HITECHHITRUSTCMMC Level 1 & 2NIST SP 800-171NIST CSF 2.0PCI DSS 4.0GDPRCCPA / CPRAFedRAMP readinessTX-RAMP / StateRAMP
Ways to engage

Sized to the problem in front of you.

3–6 weeks

Readiness sprint

Gap analysis, scoping and a costed plan to your audit date.

3–9 months

Certification program

We run the whole thing from kickoff to clean report.

Annual

Sustainment retainer

Continuous monitoring, evidence upkeep and surveillance audits.

Talk it through with someone senior

Thirty minutes on your situation specifically, what is driving the timeline, what you have already tried, and what we would do first.