IT Compliance

Compliance You Can Actually Evidence

HIPAA, PCI-DSS, SOC 2, and the cyber insurance questionnaire that now decides your premium. The controls matter, but so does the paperwork proving they exist — and that is the part most businesses discover they are missing at the worst possible moment.

Evidence Pack
MFA
Access Controls Documented
Policy · Screenshot · Date · Owner
● READY
Written Policies On File
Reviewed annually, not written once
Backup Restores Tested
With a report you can hand an auditor
PROOF
Not just good intentions
KEPT
Current between audits
HIPAA
Medical & Dental
PCI
Card Payments
SOC 2
Client Questionnaires
Cyber
Insurance Applications
Kept
Current, Not Crammed
Where It Goes Wrong

Having the Controls Is Not the Same as Proving You Have Them

Most businesses we assess are in better shape technically than they are on paper. The firewall is fine. The backups run. What does not exist is anything written down, dated, and owned — which is exactly what an auditor, an insurer, or a client’s security questionnaire asks for.

The Paperwork Does Not Exist

“We do that” is not evidence. Policies, procedures, and records have to be written, dated, and reviewed — and produced on request without a week of scrambling.

Your Insurer Is Asking Harder Questions

Cyber insurance applications now ask whether you enforce MFA, segment your network, and test restores. Answering optimistically is how claims get denied after an incident.

Clients Audit You Now

Corporate customers send security questionnaires before they sign. If you cannot answer them credibly, the deal stalls with procurement and you never find out why.

Frameworks

What We Help You Meet and Maintain

We are not auditors, and we do not certify anyone — that is deliberately somebody else’s job. What we do is build and run the technical controls these frameworks require, and keep the evidence current so your assessment is a review rather than an excavation.

HIPAA

For medical, dental, and any business handling protected health information. Access controls, audit logging, encryption at rest and in transit, business associate agreements, and the risk analysis that HIPAA actually requires you to perform and document.

PCI-DSS

For anyone taking card payments. Network segmentation that keeps payment traffic away from the guest Wi-Fi and the back office, documented access control, and the evidence your acquirer asks for at self-assessment time.

SOC 2 & Client Security Reviews

For businesses whose customers audit them. We implement and evidence the technical controls — access management, change control, monitoring, incident response — and help you answer questionnaires without guessing.

Cyber Insurance Requirements

The application is a compliance exercise whether you call it one or not. We make sure the answers you give are true, documented, and still true a year later when you need to make a claim.

What We Actually Do

The Controls, and the Evidence of Them

Compliance work splits into two halves. Everyone sells the first half. The second half is what gets you through the audit.

  • Risk assessment — what data you hold, where it lives, who can reach it, and what would happen if it leaked
  • Technical controls — MFA, endpoint protection, email security, encryption, network segmentation, and logging
  • Written policies — acceptable use, access control, incident response, and data retention, in language your staff can follow
  • Tested backups — restores actually performed and documented, because an untested backup is a hope, not a control
  • Access reviews — who has access to what, reviewed on a schedule, with departures actually removed
  • An evidence pack — kept current between audits, so producing it is a download rather than a fire drill
FAQ

Common Questions About Compliance

What business owners ask us when an audit, an insurer, or a client starts asking questions.

Are you auditors? Can you certify us?+
No, and be careful with anyone who says they can do both. Certification and attestation are performed by independent auditors and assessors precisely because they have to be independent of whoever built the controls. Our role is the other side: implementing and operating the technical controls, and keeping the evidence organized so the assessment goes smoothly.
We are a small practice. Does HIPAA really apply to us?+
Yes. HIPAA does not have a small-business exemption, and enforcement actions against small practices are common. The security rule requires a documented risk analysis regardless of headcount, and “we are too small for anyone to care” has never worked as a defense.
Our cyber insurance renewal is asking questions we cannot answer. Can you help?+
That is one of the most common reasons people call us. We go through the application with you, establish what is actually true today, close the gaps that need closing, and document the rest — so the answers you submit are accurate. Answering optimistically to get a policy issued is how claims get denied later.
A client sent us a security questionnaire. Is that the same thing?+
Same muscles, different paperwork. Enterprise customers increasingly audit their vendors, and the questionnaires borrow heavily from SOC 2 and NIST. We help you answer them truthfully and fix what the answers reveal, which is often the more useful outcome.
Is compliance included in managed IT, or is it extra?+
The technical controls are part of managed IT — MFA, monitoring, patching, backup, and email security are things we do for every client regardless. The compliance-specific work, like a formal risk analysis, policy documentation, and maintaining an evidence pack, is scoped per framework because the effort genuinely varies.
How long does it take to get compliant?+
It depends where you are starting and which framework. A gap review takes a couple of weeks and tells you honestly how far the distance is. Closing straightforward technical gaps is usually fast; building documentation that has never existed takes longer. We would rather give you a real timeline after looking than a reassuring one before.
Next Step

Find the Gaps Before Someone Else Does

A compliance gap review tells you what you can evidence today, what you cannot, and what it takes to close the difference — before an auditor, an insurer, or a prospective client asks.