Compliance & Consulting
Quoted on scope, fixed price.
Teams who have had us test their systems
What this covers
Compliance doesn't have to be a soul-crushing exercise in spreadsheet management. We help startups build security programs that actually work - policies you'll follow, controls you'll maintain, and evidence you can produce in hours, not weeks. Our consultants are former startup CTOs, security engineers, and compliance auditors who have been on both sides of the table. We don't hand you a template library and disappear. We work with your team to understand how you actually operate, then build a compliance program that fits your reality - not a Fortune 500 framework shoehorned into a 20-person startup. We specialize in ISO 27001, SOC 2 Type II, PCI-DSS, HIPAA, and GDPR readiness. Most engagements start with a gap analysis, move through control implementation, and end with audit support - we're in the room (virtually) with your auditors.
- Pass your certification audit on the first attempt
- Close enterprise deals with compliance-ready documentation
- Build a security program that satisfies auditors without slowing your team
- Stay compliant with continuous monitoring and quarterly reviews
Scope
What gets tested
Ten areas, agreed on the scoping call and written into the rules of engagement before anything starts.
ISO/IEC 27001:2022
Full ISMS implementation - 93 controls, gap analysis, internal mock audit.
ISO 27002 Internal Audit
Independent Annex A control testing, NCRs, corrective action planning.
PCI DSS v4.0.1
CDE scoping, 12 requirements, customized approach, RoC/SAQ readiness.
SWIFT CSP CSCF 2026
Architecture assessment, CSCF gap analysis, independent assessment readiness.
NCA ECC:2024
5 domains, 29 subdomains, 114 controls - national regulatory compliance.
SOC 2 Type 1 & Type 2
TSC determination, system description, control matrix, CPA preparation.
Policy & Control Build-Out
Custom policies, evidence collection workflows, continuous compliance.
Audit Support
In-room (virtual) audit assistance, auditor liaison, finding resolution.
Awareness Training
Role-based and general security awareness aligned to each framework.
Continuous Compliance
Maintenance planning, quarterly reviews, board/investor reporting.
Methodology
How the work is done
Repeatable, documented, and recorded step by step so you can see what has been looked at.
- 01
Gap Analysis
Review current policies, controls, and infrastructure against your target framework. Deliver prioritized gap list with effort estimates.
- 02
Control Build-Out
Work with your team to implement missing controls, write policies, and set up evidence collection. Hands-on, not advisory-only.
- 03
Pre-Audit Readiness
Internal mock audit to verify everything is working. Fix last gaps before the real thing. Brief your team on what auditors will ask.
- 04
Audit Support & Beyond
In the room (virtually) during your audit. Help answer auditor questions. Post-audit: maintain compliance with minimal overhead.
Why it matters
What you get out of it
Gap Analysis First
We audit your current state against your target framework and give you a prioritized gap list - so you know exactly what to fix and in what order.
Controls That Stick
We don't write policies you'll never read. We build controls that integrate with your existing tools (Jira, GitHub, Slack, AWS) and workflows.
Audit-Ready Evidence
We help you set up continuous evidence collection so when audit time comes, you produce evidence in hours - not frantic weeks.
Startup-Focused
We understand 20-person startups don't need the same controls as 5,000-person banks. Right-sized compliance that satisfies auditors and customers.
What you receive
Delivered as documents at the end of the engagement, with a call to walk your team through them.
- Gap analysis report - prioritized by risk, effort, and audit criticality
- Policy library - customized for your organization, not generic templates
- Control implementation - evidence collection, tool configuration, and process documentation
- Audit support - in-room (virtual) support during your certification audit
- Continuous compliance plan - how to stay compliant without a dedicated compliance team
Standards we test against
Coverage is recorded against these control by control, so “what did you actually check” has an answer.
- ISO 27001:2022
- ISO 27002
- PCI DSS v4.0.1
- SWIFT CSCF
- NCA ECC:2024
- SOC 2
- HIPAA
- GDPR
- NIST CSF
- CIS Controls
Pricing
What changes the price
Every engagement is quoted on scope rather than hours. These are the four things that move it, and they are what we work through on the call.
Framework
Which standard applies
Boundary
Systems inside the scope
Current state
What already exists
Support
Advice, or documents produced
FAQ
Questions about compliance & consulting
We're a 15-person startup - do we really need SOC 2?
If you sell to US enterprises, yes - SOC 2 is the most-requested security document in enterprise sales. It's not about your size; it's about your customers' requirements. A small team can achieve SOC 2 Type II by right-sizing the controls. A 15-person startup does not need the same control set as a bank - and auditors agree. We make sure you implement only what's required and nothing more.
How long does ISO 27001 / SOC 2 certification take?
Typical timeline is 3-6 months from kickoff to certification, depending on your starting point. Gap analysis takes 2-3 weeks. Control build-out takes 6-12 weeks depending on gaps. The audit itself takes 4-8 weeks (SOC 2 Type II requires a monitoring period). A team that already has strong engineering practices will sit at the shorter end of that range.
Do you work with our existing auditors, or do you provide auditors?
We work with your existing auditors - we're not an audit firm and don't provide audit services (that would be a conflict of interest). We prepare you for the audit, build your controls, and sit alongside you during the audit to answer questions. We can recommend audit firms if you don't have one, but we don't take referral fees for those recommendations.
Scope your compliance & consulting engagement.
Thirty minutes on a call and you have a fixed price, a start date and a clear picture of what the compliance & consulting will cover.





