Service
Compliance Readiness
Get ready for a customer, insurer, SOC 2 or HIPAA review.
- Starting price
- From $7,500
- How it works
- One-time project, usually six to ten weeks
- What changes the price
- Scoped by framework, number of systems in scope and how much documentation already exists. Multi-framework work is quoted individually.
What problem this solves
For a SOC 2, HIPAA or customer security review that is now standing between you and a deal. We work out the distance between where you are and what the reviewer expects, then build a plan with names, order and realistic dates against your deadline. We don’t issue certificates and we are not your auditor.
What we take off your team's plate
- 01
What’s missing, item by item
We go through the checklist line by line and mark each one done, half-done or missing, with the proof noted.
- 02
Your written policies
What you have, what’s out of date, what was never signed off, and what a reviewer will ask for first.
- 03
A plan with names on it
Work in order, with who does what, how long it takes, and what has to happen first — all against your date.
- 04
A routine for keeping proof
A simple habit for collecting and storing proof, so nobody is rebuilding it in a panic the week before the review.
- 05
We’ll talk to the auditor or customer
We can sit in on the auditor’s calls, or help answer the customer’s security questions with your team.
This is right if
- A real deadline: an audit date, a big customer’s review, a condition on your insurance renewal
- Companies that have received a questionnaire and don't know how to answer half of it
- Teams who need gathering the paperwork to be somebody’s actual job
This is the wrong choice if
- Anyone wanting a guarantee they’ll pass — nobody can honestly promise that
- Companies with no deadline and nobody asking; finding and fixing the biggest security gaps is the better first step
- The formal sign-off itself, which has to come from a licensed audit firm
How it goes
- Step 1
Agree what’s covered: which systems, which information, which review, what date.
- Step 2
Work out what’s missing across systems, policies and paperwork.
- Step 3
Build the plan and walk leadership through it, including what won’t be ready in time.
- Step 4
Optional: we help do the work up to the deadline.
Questions we get
- Do you guarantee we'll pass?
- No. Passing depends on an independent auditor and on your team doing the work. We will tell you clearly which gaps are likely to block you and which aren’t.
- Do you have HIPAA experience?
- Yes — we work with clinics and other businesses that handle health records. The specifics are best covered on the call.
- Can you use our existing compliance platform?
- Usually yes. If you already pay for one of the common compliance tools, we work inside it rather than tracking things twice.
Not sure what you need?
Answer a few questions and we'll suggest the service that fits — or tell you plainly if we're not the right company for this.