Fixed scope where we can, honest judgment where we can't
Every engagement starts with a clear question: what does your contract, your customer, or your regulator actually require, and what's the fastest defensible way to get there? We price the answerable parts up front and scope the rest once we've seen your systems.
Start here
Compliance Snapshot Assessment
$9,500 fixed price. Delivered in 2 to 3 weeks.
A bounded engagement that tells you exactly where you stand before you commit to anything larger. We run a gap analysis against the one or two frameworks that matter most to your contracts or customers, whether that's CMMC, SOC 2, ISO 27001, GDPR, HIPAA, or an AI governance program, and hand you a prioritized findings report plus a scoped roadmap and quote for remediation.
No bundled retainer, no pressure to hire us for the next phase. If you'd rather self-remediate or bring in your own team, the Snapshot gives them a map instead of a blank page.
What's included
- Gap analysis against 1-2 relevant frameworks
- Prioritized findings, ranked by risk and effort
- Scoped remediation roadmap with a real quote
- A working session to walk through results
Framework implementation & remediation
Once you know the gaps, someone has to close them. This is where most of our work happens, and it's scoped to your findings rather than sold as a fixed package, because a 15-person SaaS startup closing its first SOC 2 and a 200-person defense contractor chasing CMMC Level 2 need very different amounts of work.
Policy & control design
Written policies and procedures that describe what your systems actually do, plus the technical controls (access management, logging, encryption, change control) that make the policy true.
Assessment & certification prep
Self-assessment documentation, SPRS posting guidance, and C3PAO or auditor readiness, including mock assessments before the real one.
Evidence & renewal
A control-to-evidence map so year-two renewals reuse what you already produce instead of restarting the audit as a side project.
AI governance advisory
If your product or your internal workflows use AI, the governance question is no longer optional. We help you build a program around ISO 42001 and the NIST AI RMF, and flag where sector-specific rules (state AI laws, the EU AI Act if you have EU exposure, bar association standards if your customers are law firms) stack on top.
- AI system inventory & risk tiering: what AI you're actually running, what data it touches, and what happens if it's wrong.
- ISO 42001 AIMS design: an AI management system built to pass certification, not just a policy PDF.
- Vendor AI risk review: the questions to ask an AI vendor before their model becomes your liability.
- Disclosure & documentation: the paper trail regulators and customers are starting to ask for.
Security assessments
Compliance frameworks describe the minimum. Security assessments tell you where the actual risk sits, which is usually the more useful conversation.
Threat modeling & architecture review
A structured look at what could go wrong before it does, tied to your real architecture rather than a generic checklist.
Penetration test coordination
We scope the engagement with a qualified testing firm, then turn findings into a prioritized backlog your engineers will actually work through instead of a PDF that sits in a shared drive.
Fractional & advisory CTO
For teams that need standards-literate technical leadership on an ongoing basis, not just a point-in-time assessment. Architecture, roadmap, reliability, and technical due diligence, with the same evidence-first discipline we bring to compliance work.
How we work
Discover
Stakeholder interviews, system walkthrough, and a review of what evidence already exists versus what's missing.
Assess
Gap analysis against the relevant framework, with findings ranked by real risk and real effort, not alphabetical order.
Remediate
We pair with your team on implementation where you want the help, and hand off clean documentation where you don't.
Sustain
A control-to-evidence map and an annual rhythm so the next renewal or reassessment isn't a fire drill.
Single source of truth: if it's not in your issue tracker, repo, or system of record, it doesn't exist for planning purposes. We meet you in the tools you already use.
Not sure which service fits?
Start with a short conversation. We'll point you at the Snapshot, a specific framework, or the CTO practice, whichever actually matches your situation.