Compliance / CORE SERVICE

Commercial & Industry

SOC 2, HIPAA, PCI DSS, and ISO 27001 readiness consulting, with gap assessments, control design, and evidence preparation for independent review.

THE WORK, IN CONTEXT

Commercial & Industry, with a clear purpose.

A customer asks for a SOC 2 report, your patients are covered by HIPAA, your acquirer wants current PCI DSS validation, and an overseas procurement team wants an ISO/IEC 27001 certificate. Each framework has its own rules and its own independent party at the end: a service auditor, a federal regulator, your payment assessor or your own self-assessment, the body that issues the certificate. We do the work before that step. We scope the system or environment, find the gaps against the standard your customers actually name, build and document the controls with named owners, write the policies, and organize the evidence so it is ready to hand over. Where two frameworks ask for the same control, we map it once and prove it everywhere. Every engagement runs Scope, Assess, Report, Validate, and we never sit on the assessor side for a client we prepared.

A GOOD FIT WHEN

SaaS and managed service providers answering customer security questionnaires, healthcare covered entities and business associates, merchants and payment service providers, and companies whose international customers ask for an ISO/IEC 27001 certificate. Most arrive with a contract clause, a renewal date, or a regulator letter already in hand.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Pick the framework and the boundary

We start with the document that created the requirement: the customer contract, the business associate agreement, the acquirer letter, the tender. From it we fix which framework, which edition, which system or environment, and which independent party sits at the end. The scoping memo names in-scope systems, outside vendors, and the observation or reporting period.

Assess against the criteria, then fix

We walk each criterion, standard, or requirement with its control owner and inspect the live configuration of your identity provider, cloud accounts, source control, and ticketing systems rather than trusting a questionnaire. Each gap gets an owner, a fix written for that owner, and a note of the evidence that will show it was closed.

Hand over evidence built for the assessor

You keep a control matrix, a policy set, and an evidence index keyed to the framework’s own numbering, plus a readiness memo that states what is done, what is open, and what to expect from the independent examination or audit. After remediation we retest the closed items and update the index with dated evidence.

FIND YOUR FOCUS

Specific services.
Substantive answers.

01 / Commercial & Industry

SOC 2 Type II Readiness

Control design, a draft system description, and an evidence index for a SOC 2 Type II examination, built before the observation period starts.

  • System boundary, product lines, and trust services categories fixed against the contracts that drive the request
  • Gap walkthrough of every Trust Services Criterion with its control owner, including the categories your contracts require
  • Configuration review of identity provider, source control, cloud consoles, ticketing, and endpoint management for control evidence

From $7,500

Scope, pricing & FAQs
02 / Commercial & Industry

HIPAA Security Readiness

An accurate and thorough Security Rule risk analysis, safeguard gap assessment, and OCR-ready documentation for covered entities and business associates.

  • ePHI asset inventory and data-flow map covering clinical records, billing, cloud file shares, email, backups, medical devices, and remote access
  • Enterprise-wide risk analysis documented per asset group, following federal risk analysis guidance
  • Gap assessment of every administrative, physical, and technical safeguard the Security Rule requires

From $4,500

Scope, pricing & FAQs
03 / Commercial & Industry

PCI DSS Readiness

Scope reduction, validation-path selection, and a gap assessment against every PCI DSS requirement before your assessor arrives.

  • Account data discovery across every payment channel, with cardholder data-flow and network diagrams
  • Connected and security-impacting systems identified, with segmentation boundaries drawn and documented
  • Merchant level and validation path confirmed with your acquirer, from self-assessment through full Report on Compliance

From $4,500

Scope, pricing & FAQs
04 / Commercial & Industry

ISO/IEC 27001 Readiness

ISMS scoping, risk treatment, Statement of Applicability, and internal audit ahead of Stage 1 and Stage 2 certification audits to ISO/IEC 27001:2022.

  • Information security management system scope and context, including the required climate consideration
  • Gap assessment of the full management system and all of the standard’s security controls
  • Risk methodology, risk register, acceptance criteria, and a documented risk treatment plan

From $18,000

Scope, pricing & FAQs
WHAT YOU TAKE FORWARD

Built to support the next decision.

  • Gap report organized by the framework’s own criteria, standards, or requirements, each with an owner and a fix
  • Control matrix and evidence index that map one control to every framework it satisfies
  • Policy and procedure set written for the people who run the controls, with owners and review dates
  • Readiness memo for whoever performs the independent examination or audit, plus retest evidence after remediation

The selected services, deliverables, access requirements, and any follow-up validation are agreed in your engagement scope.

INFORMED BY RECOGNIZED GUIDANCE
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security