What the work actually involves

Scope, deliverables and honest timelines for each service line. No packages, no tiers — the scope follows your audit date and your starting point.

PCI DSS readiness and advisory

For merchants and service providers preparing for a QSA assessment or completing a self-assessment questionnaire, led by a qualified PCI Internal Security Assessor.

Scope. Cardholder data environment definition, scoping and segmentation strategy, gap assessment against the current PCI DSS standard, remediation roadmap sequenced by assessor impact, compensating control worksheets where a requirement genuinely cannot be met, and evidence preparation ahead of fieldwork.

Deliverables. Scoping document and data-flow diagrams, requirement-by-requirement gap register with owner and target date, prioritized remediation plan, and an evidence index mapped to the assessor's request list.

Typical timeline. Four to ten weeks for a first assessment, depending on how well the environment is segmented. Segmentation is almost always where the schedule is won or lost.

The most expensive PCI mistake is a scope that quietly includes systems it should not. That gets settled first, before anyone writes a control.

SOC 1 and SOC 2 readiness

Getting a first SOC 2 through cleanly, or fixing a program that produced a qualified opinion or a long list of exceptions.

Scope. Trust Services Criteria selection, control design and description, readiness assessment against the criteria, remediation of design gaps, observation-period planning for a Type II, and management of the auditor relationship through fieldwork.

Deliverables. Control matrix mapped to the criteria, system description draft, readiness findings with remediation owners, evidence collection calendar for the observation window, and auditor request-list coordination.

Typical timeline. Six to twelve weeks to readiness for a Type I. A Type II adds the observation period, commonly three to twelve months, which cannot be compressed — only started earlier.

Companies that outgrow a compliance-automation platform usually do so at the same point: the tool collects evidence well but cannot tell them whether the control design will survive a skeptical auditor. That judgment is the work.

SOX ITGC program management

For public companies and pre-IPO companies standing up IT general controls for the first time, or cleaning up after a deficiency.

Scope. In-scope system and application identification, ITGC scoping across access, change and operations, control design and testing coordination, deficiency evaluation and remediation, and liaison with external audit and internal audit.

Deliverables. Scoping memo, ITGC control matrix by system, test plans and results, deficiency log with severity assessment and remediation tracking, and management reporting suitable for the audit committee.

Typical timeline. Ongoing through the fiscal year. A first-year build is normally three to six months ahead of the first testing cycle.

Most ITGC deficiencies are access-review deficiencies, and most access-review deficiencies are evidence-quality problems rather than control-design problems. Worth knowing before you rebuild the control.

ISO 27001 implementation and internal audit

Building an ISMS to ISO/IEC 27001:2022, and running the internal audits the standard requires you to run.

Scope. ISMS scope definition, risk assessment and treatment methodology, Statement of Applicability development against Annex A, policy and procedure architecture, management review support, internal audit across clauses 4 to 10 and Annex A, and nonconformity remediation ahead of a certification or surveillance audit.

Deliverables. ISMS documentation set, risk register and treatment plan, Statement of Applicability with justifications, internal audit plan and report, nonconformity register with root cause and corrective action.

Typical timeline. Three to six months to certification readiness from a standing start. A full-scope internal audit for an already-certified organization runs three to six weeks.

Surveillance-year clients frequently need two things at once: a nonconformity closed and a full-scope internal audit on the record. Those are usually run as a single pass rather than two engagements.

AI governance and compliance

EU AI Act readiness and NIST AI RMF alignment for companies that have deployed AI faster than they have governed it.

Covered in depth on the AI governance page.

Fractional compliance leadership

Senior GRC ownership on a recurring part-time basis, for companies that need the judgment of a compliance director without the cost of one.

Scope. Program ownership across your frameworks, audit calendar management, auditor and assessor relationships, board and customer-security-review communication, vendor risk oversight, and mentoring for an analyst or manager growing into the role.

Deliverables. A maintained compliance calendar, a single risk and issue register, recurring management reporting, and a named accountable owner for every open item.

Typical commitment. Recurring monthly, usually one to four days per month, on a defined term.

Risk assessments and program design

Enterprise and IT risk assessments built to drive decisions, plus common control framework design for companies carrying several frameworks at once.

Scope. Risk identification and scoring methodology, assessment execution, treatment recommendations tied to owners and budget, and design of a common control framework that maps one control set to every framework you are asked about.

Deliverables. Risk register with scoring rationale, prioritized treatment plan, and a control crosswalk showing which single test satisfies which requirements across PCI DSS, SOC 2, ISO 27001, SOX and NIST CSF.

A common control framework is the highest-leverage thing a multi-framework company can build. Testing one control once and satisfying five requirements is the difference between a compliance team that scales and one that burns out.

Not sure which of these you need?

That is a normal place to start. Describe the deadline and the trigger, and the scope usually becomes obvious in one call.

Start an inquiry