Step 1

Onboarding

What happens

We get access to the systems in scope and align on what "in scope" actually means for your product.

What we need from you

Admin access to the tools that touch customer data, and an hour with whoever can answer questions about how the product actually works.

What comes out of it

A written scope, agreed before any control work starts.

Step 2

Discovery

What happens

We map what you're promising customers against what your systems actually do. We check log retention against the observation period in the first week, because retention shorter than the period means the evidence is already gone by the time an auditor asks for it.

What we need from you

Access to logging, infrastructure, and identity systems, and time from whoever owns each one.

What comes out of it

A gap list, ranked by what actually blocks the audit and what can wait.

Step 3

Assessment

What happens

We run coverage in both directions. Every Trust Services criterion gets a control, and every control answers a named risk with a named owner. Nothing gets added because a template has it.

What we need from you

Sign-off on who owns each risk. Someone has to be answerable for it.

What comes out of it

A control set mapped to risk and owner, not copied from a boilerplate list.

Step 4

Build

What happens

We write the policies and stand up the workflows behind each control. We decide how a control will be evidenced when we design it, not after, so evidence collection isn't a scramble at the end.

What we need from you

Review and sign-off on policies, and engineering time where a control needs a workflow change.

What comes out of it

Policies your team will actually follow, and controls that produce evidence as a byproduct of the work, not a special project.

Step 5

Report & Support

What happens

We hand over the readiness report, the evidence collection guide, and a 90-day roadmap. Then we stay through the audit and after it, as the program needs adjustment.

What we need from you

Nothing new. Just the ongoing rhythm of the work already built.

What comes out of it

Audit-ready evidence, and someone who still knows the program six months from now.

See where you stand before we talk method.

The free Enterprise-Readiness Snapshot tells you what an enterprise buyer’s security reviewer would find today.