Compliance readiness scoped to the controls auditors actually check.
SOC 2 Type II, HIPAA, and PCI-DSS v4 — mapped to the environment you actually run, not a generic template. We've sat on both sides of that table.
- SOC 2 Type II · HIPAA · PCI-DSS v4
- gap analysis · evidence inventory · remediation plan
- audit firm coordination
- readiness · not the audit itself
Compliance Readiness, in plain terms.
We start with the framework you're being asked to meet and walk your environment against it: access controls, change management, logging, encryption, vendor management, incident response, backup and recovery, and the evidence trail for each. The output is a gap list, an evidence inventory, and a sequenced plan to close gaps in the order an auditor will look for them.
Our focus is SOC 2 Type II, HIPAA, and PCI-DSS v4. For ISO 27001 or NIST CSF we'll either tell you we can help or refer you to a partner — we'd rather lose the engagement than fake depth. We don't issue audit opinions. We get you ready, then hand off to your audit firm or CPA. If you don't have one, we'll introduce you to firms we've worked with cleanly.
Where it makes sense, we help you avoid compliance theater. A SOC 2 with weak controls and strong documentation passes the audit but doesn't protect anyone. We push for controls that do the security work and produce evidence as a byproduct — not the other way around.
Common triggers for this engagement.
- 01A customer is asking for SOC 2 Type II and you don't yet have one
- 02You handle PHI or cardholder data and need HIPAA or PCI-DSS readiness before the next contract
- 03You've started a compliance project internally and hit gaps you don't know how to close
- 04Your current SOC 2 passed but the controls feel performative and you want them to actually do work
Questions teams ask before signing.
Do you write the SOC 2 controls or just review them?
Both, depending on where you are. If you're starting from zero, we draft a control set that fits your environment and your team. If you have controls already, we review them against current practice and your actual operations, then close the gaps.
Do you issue the audit report?
No. We're a readiness firm. The audit opinion has to come from a licensed CPA firm — that independence requirement exists for a reason. We get you ready, broker the auditor relationship if you need one, and stay engaged during the audit to handle questions.
How long does SOC 2 Type II readiness take?
From a cold start, expect three to six months to readiness plus the Type II observation window — typically three to twelve months depending on the auditor and what you negotiate. We can compress readiness if your environment is already in reasonable shape.
What if our infrastructure or colocation provider needs to be in scope?
Then their compliance posture matters. We review the controls inheritance — what their SOC 2 or HIPAA attestation actually covers and what's left to you. If we run your network or colo, we provide our own attestation evidence directly.
Frequently scoped alongside this work.
Cybersecurity Consulting
Architecture review, control-gap analysis, and incident readiness — paired with operators who understand the network the controls run on. We tell you which fixes are real and which are theater.
Security Architecture Review
A structured read of how identity, network, and data controls actually fit together — not how the policy says they should. We surface the gaps before a real attacker, or an auditor, does.
Penetration Testing
Hands-on adversarial testing of the systems your team relies on. We report what we found, how we got in, and what to fix first — in language an engineer can act on.
Data Center Colocation
Carrier-neutral colocation with the network already terminated. Tier III facilities, HIPAA-ready environments, and an engineer to point at the cage.