← All services Security frameworks & control coverage

“Are we covered?” — answered on one page.

The recognized frameworks — NIST CSF 2.0 and CIS Controls — mapped to how your business actually runs, so you can see exactly where you're strong, where you're exposed, and what to fix first. Written to be read by a customer, a board, or an insurer, not just a security team.

Sound familiar?

You're probably here because of one of these.

A customer wants a framework

A bigger client or partner asked which framework you follow, and “we take security seriously” isn't going to cut it.

You can't see the whole picture

You have tools and policies, but nothing that shows how they add up or where the real gaps are.

A board or insurer is asking

Someone above you wants a defensible answer about coverage, and you need it on a page, not in a slideshow.

What you get

Everything included.

  • A mapping of your current controls to NIST CSF 2.0 and CIS Controls, in plain language
  • A one-page control-coverage view — green / partial / gap — that a non-technical reader can understand at a glance
  • The gaps ranked by what actually reduces risk, not by what's easiest to check off
  • A short, prioritized roadmap: what to close now, next quarter, and later
  • A reusable reference you can hand to a customer, an insurer, or an auditor without a research project
  • Optional mapping to an additional framework a specific customer demands (SOC 2 readiness, NIST AI RMF, and similar)
  • A walkthrough with your team and thirty days of follow-up questions at no charge
How it runs

Start to finish.

01 / LOOK

A working session

We walk through your systems, tools, and how the business runs — enough to map reality, not a wish list.

02 / MAP

I build the coverage model

Your controls mapped clause-by-clause to the frameworks, with each gap traced to something real.

03 / REVIEW

You pressure-test it

You confirm what's accurate and flag anything that looks off. It's fixed before it's final.

04 / HANDOFF

Yours to use

The coverage page, the roadmap, and editable files — ready to send the next time someone asks.

Fixed price
from $3,500

Scales with how many systems are in play and how many frameworks you need mapped. A single-framework view for a small services firm sits near the bottom; multi-framework coverage for a larger, multi-system business sits higher. Quoted before we start.

Start here
Questions

Asked often enough to write down.

NIST or CIS — which one do I need?

Usually both, used differently. CIS Controls are ordered by what prevents the most damage first, which makes them a great action list for a business without a security team. NIST CSF 2.0 is the framework most customers and boards recognize by name. I map to both so you get an action plan and a name you can cite.

Is this the same as a SOC 2 audit?

No. An audit is performed by a licensed firm and results in a formal report. This is the readiness work that comes first — knowing where you stand and closing the obvious gaps — so that if you do pursue an audit later, you're not starting from zero.

What if a customer demands a framework I've never heard of?

Tell me which one on the form. Most customer requirements map back to the same underlying controls, so adding a specific framework is usually an extension of this work rather than starting over.

Do you sell the tools you recommend?

No. I don't resell anything and take no commissions, so the roadmap is only ever about what actually closes your gaps.

Next step

Let's see where you actually stand.

Describe your setup on the form. I'll tell you which frameworks apply and what a coverage view would take.

Get in touch