Internal compliance assessment

Your policies, procedures, controls, and systems, traced from policy to evidence.

I review your policies, procedures, controls, and systems against the framework, tracing each requirement from policy to procedure to evidence in whatever system you use today. Deepest on AWS, fully capable on Azure, GCP, and hybrid.

It includes the external compliance assessment, so the report shows whether your controls work, not just whether they are written down.

Timeline
Two weeks
You get
  • A gap and readiness report: what exists, what is missing, and what needs strengthening
  • An evidence-mapping matrix: each criterion mapped to the evidence that supports it
  • A prioritized remediation roadmap, with owners and sequencing
  • Sample policies

Frameworks

What I assess, and who does the final step.

An assessment is not a certification, and I do not issue one.

SOC 2

Readiness for a Type 1 or Type 2 report.

Final stepA CPA firm issues the report.

HIPAA

Security Rule risk analysis and evaluation.

Final stepAn outside firm, often a CPA firm, can issue a certificate or attestation. HHS does not recognize any certification as official.

HITRUST

Readiness for e1, i1, or r2.

Final stepAn authorized External Assessor validates, and HITRUST certifies.

ISO 27001

Readiness, including the management-system clauses.

Final stepAn accredited certification body certifies.

PCI DSS

Readiness, or help completing a self-assessment questionnaire. The external assessment is not an ASV scan and does not replace one.

Final stepA Qualified Security Assessor assesses larger merchants.

NIST CSF 2.0 and SP 800-53

Gap assessment.

Final stepNone. There is no certification.

The business case

Enterprise customers ask for a SOC 2 report or a completed security questionnaire before they sign. Finding the gaps first means you fix them on your schedule, not in the middle of a deal.

The compliance case

Supporting evidence for:

  • SOC 2 CC3.2, CC4.1
  • HIPAA §164.308(a)(1)(ii)(A), §164.308(a)(8)
  • ISO 27001 A.5.35
  • NIST CSF ID.IM-01
  • NIST 800-53 CA-2

References are to the 2017 Trust Services Criteria for SOC 2, the HIPAA Security Rule at 45 CFR Part 164, ISO/IEC 27001:2022 Annex A, NIST CSF 2.0, and NIST SP 800-53 Rev. 5.

Pricing

A fixed fee, quoted after a 30-minute scoping call.

What moves the price:

  • The framework
  • Company size, and how many systems, cloud accounts, or domains are in scope
  • Whether there are policies to review, or policies to write

Start with a conversation.

The right engagement depends on what you’re building and where the gaps are. A 30-minute call gets us to whether and how I can help.