Engagement plans
Three ways to work with us.
Each plan is fixed-scope and quoted up front after a short discovery call. Start with the one that matches where you are — organizations often move from Blueprint to Keystone to Sentinel over time.
Blueprint
Know where you stand
A focused readiness engagement for organizations that need a clear answer and a credible plan.
- Scoping workshop and system inventory
- Gap assessment against one target framework
- Information security risk assessment
- Prioritized 12-month roadmap with effort estimates
- Executive readout and Q&A
Recommended
Keystone
Build it and prove it
Full program implementation from gap assessment to a clean audit, delivered hand-in-hand with your team.
- Everything in Blueprint
- Policy and procedure library tailored to you
- Control implementation with weekly working sessions
- Unified control set mapped across your frameworks
- Evidence repository and readiness testing
- Auditor coordination and fieldwork support
Sentinel
Your ongoing vCISO
Fractional security leadership and continuous risk monitoring for organizations that need the program to keep running.
- Named vCISO for strategy, board, and customer needs
- Monthly control health checks and KRI dashboard
- Quarterly risk review and executive report
- Annual risk assessment and policy refresh
- Security questionnaire and trust-request support
- Incident response tabletop exercise
Which plan fits?
A quick guide.
Choose Blueprint if…
- A customer or partner just asked for a SOC 2, ISO, or HITRUST report
- You need a budget number and a timeline for leadership
- You have internal capacity to execute, but want an expert plan
Choose Keystone if…
- You have an audit or certification date to hit
- You don’t have a dedicated security or compliance team
- You want the program built right the first time
Choose Sentinel if…
- You’re already certified and want to stay current
- Leadership or the board wants regular risk reporting
- You need senior security leadership without a full-time hire
Common questions
Before you reach out
How is pricing set?
Every plan is quoted as a fixed fee after a short discovery call. Scope drivers are the number of frameworks, the size of your environment, and how much implementation your team wants to own. You’ll have the number in writing before any work starts.
Can we combine frameworks?
Yes, and it’s usually the efficient choice. Because we build one unified control set, adding a second framework to Blueprint or Keystone increases scope far less than running two separate projects.
Do you perform the audit itself?
Certification audits and attestation reports are issued by independent firms (for example, a CPA firm for SOC 2 or an accredited certification body for ISO 27001). We prepare you, coordinate with them, and support you throughout. Where we offer assessment services, such as HITRUST, we keep advisory and assessment work separate as independence rules require.
What do you need from our team?
An executive sponsor, a day-to-day point of contact, and access to the people who run your systems. We work around your schedule and keep meetings short and purposeful.
Let’s find the right starting point.
Share a little about your situation and we’ll recommend a plan and give you a fixed quote.