ISO/IEC 17020 accredited inspection body · Cleared facility (FCL)
Home / Services

Capabilities

Assessment and compliance services

Nine capabilities spanning the full life of an authorization, starting at the first gap assessment and continuing through penetration testing, remediation and monitoring.

Capabilities

Where we are engaged, and what we produce.

The two shapes of the work

A cycle to run, and a package to build.

1PREPARE2CATEGORIZE3SELECT4IMPLEMENT5ASSESS6AUTHORIZE7MONITORRMFSP 800-37 REV. 2STEP 7 IS CONTINUOUS
Assessment work follows the Risk Management Framework cycle.
SSPREV. 5 BASELINEFIPS 199CIS / CRMPoliciesISCPCMPIRPRules of BehaviorUser GuidePTA / PIAArchitectureConMon PlanInventory
Advisory work builds a package of interlocking documents.

Test once, report many

One system, several regimes.

A SaaS platform selling to a defense agency and a hospital network can face 800-53, 800-171 and the HIPAA Security Rule simultaneously. The controls overlap heavily; the templates do not.

  • We build a single control inventory and map it to every framework in scope
  • Evidence is collected once and reused across reports
  • Findings are written once, then expressed in each framework’s language
  • You stop paying three times to prove the same thing

Tell us what the contract requires. We’ll tell you what it takes.

A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.