Four phases. One program that actually holds up.
Every engagement, a full vCISO retainer or a focused SOC 2 sprint, moves through the same disciplined process, calibrated to your size and timeline.
Assess
Typically 1-3 weeks
We map your environment, identify the gaps against the framework, and give you a prioritized roadmap. Then we start fixing things — not just documenting them.
What you get
- Structured interviews with key stakeholders across engineering, IT, and leadership
- A review of your current controls, tools, and documentation
- Benchmarking against NIST CSF, SOC 2, ISO 27001, or the framework relevant to you
- A risk-ranked findings summary in plain English
What we need from you
- Access to relevant documentation and system diagrams
- 30-60 minutes from 2-4 key stakeholders
- A point of contact to coordinate scheduling
Plan
Typically 1-2 weeks
We build the implementation plan. Who does what, when, and how. Policies, controls, evidence collection, tool configuration. All mapped to your audit timeline.
What you get
- A prioritized 90-day and 12-month roadmap
- A board-ready executive summary deck
- Clear ownership recommendations for each initiative
- A realistic timeline and effort estimate for every workstream
What we need from you
- A review session with leadership to align on priorities
- Confirmation of budget or resourcing constraints we should plan around
Implement
Timeline varies by scope
This is where most consultants hand you a document and step back. We don't. Your vCISO rolls up their sleeves alongside your team — writing policies, configuring controls, running vendor reviews, and managing the audit relationship if one is in motion.
What you get
- Hands-on policy and control implementation
- Direct collaboration with engineering and IT on technical controls
- Vendor and third-party risk assessments handled on your behalf
- Audit liaison and evidence collection support if you're pursuing SOC 2 or ISO 27001
What we need from you
- A designated technical point of contact for implementation questions
- Reasonable access to systems and tooling as controls are configured
Maintain
Ongoing
A security program isn't a project with an end date — it's an operating discipline. We keep your program current through ongoing advisory, ownership of monitoring cadences, and periodic reassessment as your company grows and risk evolves.
What you get
- Ongoing advisory access via Slack, email, or a standing call
- Continuous control monitoring and evidence upkeep
- Policy reviews and updates as your business changes
- Annual or semi-annual reassessment to catch drift before an auditor does
What we need from you
- A light ongoing cadence — typically a weekly or biweekly sync
- A heads-up on major business changes (new products, new data types, new markets)
Realistic pacing, not rushed compliance theater
Some phases can move fast — an assessment might take two weeks. Others, like a SOC 2 Type II observation period, require months by design because that's what it takes for an auditor to trust the evidence. We'll be upfront about which is which from day one.
See what this looks like for your company
Book a free consultation and we'll map the process to your specific timeline, team, and compliance goals.