Is this you?

  • A customer’s security questionnaire asked for a SOC 2 report you do not have yet.
  • You spend on security but cannot say what it buys you.
  • New leadership, an acquisition or an incident means you need an honest baseline.
  • You are about to buy a security product and want an independent opinion first.

What you get

  • A gap assessment against the framework that matters to you: SOC 2, NIST CSF 2.0, CMMC or your own objectives
  • A prioritized remediation roadmap with owners, effort and cost
  • SOC 2 readiness: scoping, control design, policies and evidence collection
  • Support through the audit, working alongside your CPA firm
  • Budget right-sizing: your tools, people and contracts measured against your objectives
  • Independent verification and validation (IV&V) of security technology before you buy it

How it works

  1. Step 1: Frame

    Agree on the yardstick and the decisions the assessment has to support.

  2. Step 2: Assess

    Interviews, configuration reviews and evidence sampling.

  3. Step 3: Prioritize

    Findings ranked by risk and effort, written in plain language.

  4. Step 4: Close

    Fix, document and get ready for the auditor or the board.

Every step follows Cyber BAMCIS, our planning method.

Related work

  • Global connectivity provider

    CMMC gap assessment, expanded to SOC 2

    A CMMC gap assessment across five global locations and a Google Cloud, AWS and Google Workspace estate, expanded to add SOC 2 Type 2 readiness.

  • State government

    An endpoint security rollout across 25 agencies

    Rollout planning and tracking for 60,000 endpoints moving to a new endpoint detection and response platform, agency by agency.

Questions

Can you perform our SOC 2 audit?

No. SOC 2 reports are issued by independent CPA firms. We get you ready for the audit and support you while it happens.

Type 1 or Type 2?

A Type 1 report looks at whether your controls are designed properly at a point in time. A Type 2 report tests whether they operated effectively over a period, usually several months. Most customers eventually ask for Type 2.

What does budget right-sizing involve?

We inventory your security tools, staff and contracts, map them to your objectives, and show where money is duplicated, missing or pointed at the wrong risk.

Other services

Tell us what’s driving the deadline

One short call is enough to know whether we’re the right fit and what the work would take.