A customer asks for a SOC 2 report, your patients are covered by HIPAA, your acquirer wants current PCI DSS validation, and an overseas procurement team wants an ISO/IEC 27001 certificate. Each framework has its own rules and its own independent party at the end: a service auditor, a federal regulator, your payment assessor or your own self-assessment, the body that issues the certificate. We do the work before that step. We scope the system or environment, find the gaps against the standard your customers actually name, build and document the controls with named owners, write the policies, and organize the evidence so it is ready to hand over. Where two frameworks ask for the same control, we map it once and prove it everywhere. Every engagement runs Scope, Assess, Report, Validate, and we never sit on the assessor side for a client we prepared.
A GOOD FIT WHEN
SaaS and managed service providers answering customer security questionnaires, healthcare covered entities and business associates, merchants and payment service providers, and companies whose international customers ask for an ISO/IEC 27001 certificate. Most arrive with a contract clause, a renewal date, or a regulator letter already in hand.
THE WORK BEHIND THE SERVICE
What we do. What you can use.
01
Pick the framework and the boundary
We start with the document that created the requirement: the customer contract, the business associate agreement, the acquirer letter, the tender. From it we fix which framework, which edition, which system or environment, and which independent party sits at the end. The scoping memo names in-scope systems, outside vendors, and the observation or reporting period.
02
Assess against the criteria, then fix
We walk each criterion, standard, or requirement with its control owner and inspect the live configuration of your identity provider, cloud accounts, source control, and ticketing systems rather than trusting a questionnaire. Each gap gets an owner, a fix written for that owner, and a note of the evidence that will show it was closed.
03
Hand over evidence built for the assessor
You keep a control matrix, a policy set, and an evidence index keyed to the framework’s own numbering, plus a readiness memo that states what is done, what is open, and what to expect from the independent examination or audit. After remediation we retest the closed items and update the index with dated evidence.
An accurate and thorough Security Rule risk analysis, safeguard gap assessment, and OCR-ready documentation for covered entities and business associates.
ePHI asset inventory and data-flow map covering clinical records, billing, cloud file shares, email, backups, medical devices, and remote access
Enterprise-wide risk analysis documented per asset group, following federal risk analysis guidance
Gap assessment of every administrative, physical, and technical safeguard the Security Rule requires