Service

Readiness Assessment

The map before the march.

You know an audit is coming; you don't know how far away you are. Auditors charge fieldwork rates to find out, platforms give you a red-yellow-green guess, and quotes for 'the full program' arrive before anyone has measured the gap they're pricing.

Book a Call
How We Work
  1. 01

    Evidence-based review

    We connect read-only to your stack and review your actual state — access, policies, infrastructure, vendors — against the target framework. Real configuration, not questionnaire self-reporting.

  2. 02

    Gap scoring

    Every control gap scored by audit impact and remediation effort, separating the two-hour fixes from the two-month projects.

  3. 03

    The sequenced plan

    A dated remediation plan with owners, mapped to your deal deadline — plus a straight recommendation on operating model: DIY with automation, or done-for-you, with the real number for each.

Deliverables
  • Gap assessment report scored by impact and effort
  • Sequenced remediation plan with owners and dates
  • Audit-timeline projection against your target date
  • Fixed quote for the done-for-you path, if you want it

Two weeks from access to delivered plan

Who It's For
  • Teams facing a first audit who need the size of the problem before choosing a path
  • Companies with a stalled program that need a restart plan, not more software
  • Buyers comparing DIY vs done-for-you with real numbers instead of vendor decks
Encoded by YOU

Every compliance journey has a first honest question: how far are we, really? Everyone downstream of that question has an incentive to answer it vaguely — platforms round toward “closer than you think,” consultancies toward “further than you fear.” A fixed-price assessment with read-only access answers it with evidence, in two weeks, with a plan you own either way. Start here if you’re starting cold; start with the gap assessment glossary entry if you just want to understand the concept.

Powered by the Platform

Framework Implementation — Implement SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR from one control set. Cross-framework mapping eliminates duplicate evidence work as you expand.

Frequently Asked
Is this just a sales exercise for your bigger services?

The assessment is priced to stand alone and the plan is written to be executable by anyone — your team, another consultant, or us. About half of assessments convert to engagements; the other half execute the plan themselves, which we consider a success.

How is this different from an auditor's readiness assessment?

Auditors assess against their fieldwork checklist and stop at findings. We assess with implementation in mind — every gap comes with the fix's effort estimate — and we're allowed to help close them, which auditor independence rules prohibit.

Which frameworks does it cover?

SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and MAS TRM — or a combined assessment when you're sequencing two on one control set, which is usually the cheaper question to ask.