BrickellTechnologies

Service

Compliance Readiness & Scanning

Gap assessment first, then the scanning and testing evidence your assessor asks for. We get you ready for the audit. We do not pretend the audit is the goal.

Frameworks we work in

FrameworkWho it applies toWhat we do
SOC 2 SaaS and service providers whose enterprise customers ask for it Readiness assessment, control design review, the penetration test and scanning evidence, auditor handoff
HIPAA Covered entities and their business associates Security Rule risk analysis, technical safeguard review, remediation plan
PCI DSS 4.0 Anyone storing, processing or transmitting cardholder data Scope reduction, segmentation testing, quarterly scanning, the required penetration test
CMMC / NIST 800-171 Defense contractors and their supply chain Gap assessment against all 110 controls, SSP and POA&M support, evidence
ISO/IEC 27001 Organisations selling internationally, often into Europe Annex A gap assessment, technical control testing, pre-certification review

Gap assessment

We go control by control and record three things: what the framework requires, what you are actually doing, and how far apart those are. The output is a spreadsheet your team can work through and a written plan that puts the items in order of effort against audit risk, because some gaps take an afternoon and some take a quarter.

We will also tell you where you are over-engineering. Companies routinely build elaborate processes for a control the assessor will satisfy with a policy document and a screenshot, while leaving a genuinely weak control untouched because it was harder.

Scope reduction, before anything else

The cheapest compliance work is the work you delete. Under PCI DSS especially, segmenting cardholder data into a smaller environment removes entire systems from assessment, and the engineering cost of doing that is often less than the ongoing cost of assessing them every year. Same logic applies to CMMC and controlled unclassified information. We look at this first, before writing a single policy.

The evidence, produced by people who do the testing

Nearly every framework eventually asks for scanning and for a penetration test. Buying those from a compliance consultancy that subcontracts them is how you end up with a report that satisfies the auditor and tells you nothing. Ours come from the same people doing the penetration testing and vulnerability assessment work, written to stand up in both conversations: scope, dates, methodology and tester credentials for the assessor, and real findings for your engineers.

An honest note about certificates

A SOC 2 report says an auditor checked that you did what you said you would. It is not a statement that you are secure, and companies with clean reports get breached regularly through something the report never covered. Treat the audit as a floor and a sales requirement. The security work is a separate, longer project that happens to produce most of the evidence along the way.

Questions we get asked

Can you be our auditor as well?

No, and nobody honest can. A SOC 2 opinion comes from a licensed CPA firm, and whoever does your readiness work is disqualified from auditing it. We get you ready and hand you to an assessor; keeping those roles separate is the whole reason the report means anything.

How long does SOC 2 readiness take?

The gap assessment is a couple of weeks. Closing the gaps is the real timeline and it depends entirely on what we find, though three to six months before a Type II observation window starts is a fair planning assumption for a company doing this the first time. Type I is faster because it is a point in time.

Does the penetration test have to be from a third party?

For PCI DSS the tester must be organisationally independent of the systems being tested, which for most companies means external. SOC 2 does not name a requirement at all; the auditor evaluates whatever the organisation committed to in its own control descriptions, and independent testing is simply the easiest way to satisfy one. Customer security questionnaires are frequently stricter than the framework.

We use a compliance automation platform already. Do we still need you?

Those platforms are good at evidence collection and terrible at judgment. They will tell you a control is not satisfied; they will not tell you that the way you implemented it is technically compliant and practically useless. And every one of them still leaves you to source an actual penetration test, because a dashboard cannot perform one.

Which framework applies to us?

Usually whichever one a customer put in a contract. Handle cardholder data and PCI DSS is not optional; handle protected health information and HIPAA applies; sell to enterprise software buyers and SOC 2 gets asked for; sell to the Department of Defense and CMMC with NIST SP 800-171 underneath it is the conversation. If several apply, the controls overlap heavily and there is no sense running the programmes separately.

What happens after we pass?

The scanning and the annual test keep running, because the certificate is a snapshot and the estate is not. Most clients move onto a recurring cycle after the first audit: quarterly scans, an annual penetration test, and a short review before each surveillance visit.

Know what an attacker would reach first.

Tell us what you run and what worries you. We will come back with a scope, a fixed price and the earliest week we can start.