Compliance wins work 

Five phases to get compliant.
Ongoing management to stay that way.

Each framework has its own controls, but the path to compliance follows the same five phases. After that, we manage your systems day to day so they stay compliant.

01

Assessment

We review what's required under your specific framework and where your current environment stands against it.

02

Infrastructure

We build or adjust the technical environment your framework requires.

03

Controls

We put the policies, procedures, monitoring, training, and documentation in place to close the remaining gaps.

04

Verification

Before anything goes in front of an auditor, client, or regulator, we confirm the evidence is there. (If your framework requires one.)

05

Audit

For frameworks that require formal third-party verification, we support you directly through that audit, using the evidence and documentation already built during the Verification step.

06

Ongoing Management

Standards don't stay still, and neither does your business. We maintain the environment and the documentation so you're not starting over every time something changes.

Which of these applies to you?

Find your industry below. Seeing more than one is common, and many controls overlap between frameworks.

Airplane in a factory setting

CMMC

For companies in the DoD supply chain that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), at any tier. Without a current self-assessment on file, you can’t be awarded work that requires it. More information.

salesperson in a car showroom at a car dealer

FTC Safeguards Rule

The FTC Safeguards Rule covers financial institutions that aren't overseen by another federal regulator. That includes many businesses that don't think of themselves as financial, like tax preparers, car dealers with in-house financing, mortgage brokers, and more. If your business handles non-public personal information and falls under the rule, the FTC can enforce it against you directly. 

Doctors discussing patient medical records

HIPAA

For healthcare providers, including chiropractors, dental offices, naturopathic physicians, psychologists, and others, and for any vendor or business associate handling protected health information on their behalf. Violations can lead to federal enforcement, and a breach of unsecured patient data requires notifying every affected individual.

IT security review in an office

ISO 27001

For businesses that need a recognized, internationally accepted information security management standard, often required as a condition of the deal itself. Certification frequently shortens the vendor security review that would otherwise hold up a contract.

IMO

For ships on international voyages, including cargo ships over 500 gross tons.  The IMO requires cyber risk across IT and OT systems to be managed in each ship’s safety management system. Ignoring it can leave a vessel considered unseaworthy.

government contractor reviewing document

NIST 800-171

The security standard for protecting Controlled Unclassified Information (CUI). It’s mandatory for companies whose contracts require NIST standard implementation, and falling short puts that contract at risk on its own, regardless of what certification process is or isn’t attached to it.

Person working as security officer on a vessel

U.S. Coast Guard

For U.S.-flagged vessels and MTSA-regulated facilities. The Coast Guard requires a Cybersecurity Plan covering IT and OT, and falling short can bring civil penalties or operating restrictions. 

Not sure which applies? We sort that out on the first call, then build the controls and records each one asks for.

The contract you have and the next one both depend on this

Compliance FAQs

Your systems may run well, and a client’s security review can still fail you. Reviews ask for written policies and records tied to a specific framework. We manage both, so the evidence is there.

Probably, if you handle customers’ non-public personal information and no other financial regulator oversees you. Car dealers with in-house financing and tax preparers are both covered. We’ll confirm your status on the first call and, if you’re covered, build the written security program the rule requires.

The Act protects how businesses collect, share, and use consumer health data, and it gives individual consumers a private right of action, meaning they can sue a business directly over a violation.. A Washington business has already faced a class action lawsuit filed under this exact provision.

No, it’s voluntary. But it’s frequently required as a condition of the deal itself, particularly by larger clients or partners who want a recognized, internationally accepted security standard in place before they’ll sign.

It depends on the framework. The FTC Safeguards Rule relies on self-certification, and ISO 27001 certification requires an external auditor. We complete the internal assessment and build the evidence. Where an audit is required, we prepare you and support you through it. Where it isn’t, we’ll tell you whether one is worth it.

The first sign is often a client’s security questionnaire, or an insurance renewal with questions you can’t answer. By then the deadline is theirs. Starting early lets you set the pace.

Why Businesses Trust Us

Not sure if your IT is truly supporting your growth?