Diagnostic · Pre-audit

Know your gaps before the audit clock starts

A structured readiness and gap assessment: where controls and evidence stand today, what buyers will ask, and a prioritized plan toward SOC 2 or ISO 27001.

Controls, evidence, and buyer posture

Review policies, access, change, vendor, and security testing posture against your target framework. Output is a gap list, risk-ranked priorities, and recommended next programs—not a certificate.

Discover → score → plan

Kickoff and document/access review, collaborative scoring of control maturity, then a readout with owners and sequencing (testing, remediation, readiness, or vCISO). Typical inputs: current policies, architecture overview, prior pentest reports if any.

What you leave with

Prioritized gaps, evidence checklist, and a recommended path to SOC 2, ISO 27001, PTaaS, one-time pentests, or vCISO. CREST-aligned technical input when testing history is reviewed. Our testers hold OSCP and CREST certifications.

Common questions

No—it is a diagnostic before or between audits.

We can frame gaps for either or both targets in one engagement.

Usually documents and interviews first; technical testing is scoped separately.

Often readiness retainers, PTaaS, or one-time pentests—we sequence with you.

Book a readiness & gap assessment

Book an assessment