Engagement Plans

Blueprint, Keystone, and Sentinel — fixed-scope plans for every stage of your program.

Engagement plans

Three ways to work with us.

Each plan is fixed-scope and quoted up front after a short discovery call. Start with the one that matches where you are — organizations often move from Blueprint to Keystone to Sentinel over time.

Blueprint

Know where you stand

A focused readiness engagement for organizations that need a clear answer and a credible plan.

Typically 3–6 weeks · Anchor Path phases 1–2

  • Scoping workshop and system inventory
  • Gap assessment against one target framework
  • Information security risk assessment
  • Prioritized 12-month roadmap with effort estimates
  • Executive readout and Q&A

Sentinel

Your ongoing vCISO

Fractional security leadership and continuous risk monitoring for organizations that need the program to keep running.

Annual subscription · Anchor Path phase 5

  • Named vCISO for strategy, board, and customer needs
  • Monthly control health checks and KRI dashboard
  • Quarterly risk review and executive report
  • Annual risk assessment and policy refresh
  • Security questionnaire and trust-request support
  • Incident response tabletop exercise

Which plan fits?

A quick guide.

Choose Blueprint if…

  • A customer or partner just asked for a SOC 2, ISO, or HITRUST report
  • You need a budget number and a timeline for leadership
  • You have internal capacity to execute, but want an expert plan

Choose Keystone if…

  • You have an audit or certification date to hit
  • You don’t have a dedicated security or compliance team
  • You want the program built right the first time

Choose Sentinel if…

  • You’re already certified and want to stay current
  • Leadership or the board wants regular risk reporting
  • You need senior security leadership without a full-time hire

Common questions

Before you reach out

How is pricing set?

Every plan is quoted as a fixed fee after a short discovery call. Scope drivers are the number of frameworks, the size of your environment, and how much implementation your team wants to own. You’ll have the number in writing before any work starts.

Can we combine frameworks?

Yes, and it’s usually the efficient choice. Because we build one unified control set, adding a second framework to Blueprint or Keystone increases scope far less than running two separate projects.

Do you perform the audit itself?

Certification audits and attestation reports are issued by independent firms (for example, a CPA firm for SOC 2 or an accredited certification body for ISO 27001). We prepare you, coordinate with them, and support you throughout. Where we offer assessment services, such as HITRUST, we keep advisory and assessment work separate as independence rules require.

What do you need from our team?

An executive sponsor, a day-to-day point of contact, and access to the people who run your systems. We work around your schedule and keep meetings short and purposeful.

Let’s find the right starting point.

Share a little about your situation and we’ll recommend a plan and give you a fixed quote.