Saying you're compliant is easy. Proving it is the job.

Auditors, carriers and customers don't want a policy document. They want evidence that the control actually operated, collected over time. We build the controls, map them to the frameworks that apply to you, and capture the proof on an ongoing cadence, so the answer already exists when someone asks for it.

Thirty minutes, no cost, and you leave knowing which frameworks apply to you and what closing the gap involves.

Evidence ledger · live -
08:41Access review completed: Finance systems✓ logged
09:15Control tested: change management✓ logged
11:02Evidence captured: incident log✓ logged
13:37Vendor risk review updated✓ logged
15:20Backup restore test verified✓ logged
AUDIT READY
Evidence is captured, access reviews, controls tested!
What compliance services actually are

What compliance services actually are

A compliance framework such as ISO/IEC 27001, SOC 2, NIST CSF 2.0, NIST SP 800, PCI DSS or CMMC is a published set of requirements describing what an organization must have in place and be able to demonstrate before a regulator, auditor, insurer or customer will treat it as trustworthy. Meeting one is rarely a matter of buying a product. It is a matter of having the right controls, proving they operated over time, and keeping someone accountable for them.

Cyberwall does four things against that:

→Tell you where you stand. A structured gap assessment based on interviews, document review and technical validation, not a self-assessment questionnaire.
→Tell you what to fix first. Findings ranked by risk, business impact, dependency and effort, so a small team knows what to do this month versus this year.
→Help you fix it. Policy and governance design, control implementation, risk treatment and evidence preparation. Hands-on, not a report handed over at the door.
→Keep it standing. Recurring control reviews, evidence collection, internal audit and executive reporting between assessments.

Why this lands on your desk now

Most organizations do not go looking for a compliance program. A compliance program finds them. A customer writes SOC 2 Type II or ISO 27001 into a renewal and revenue is gated on an artifact you do not have. A regulator applies: payment card data, health information, or controlled unclassified information. An underwriter prices your premium on whether you can evidence MFA coverage, backup testing and incident response. AI tools are already in use and someone asks who approved them. Or the board asks how exposed you are and nobody can answer with evidence.

The underlying problem is the same every time: you are being asked to demonstrate something, and demonstration requires evidence collected over time.

How we work

Every engagement runs on the same four phases.

Scaled to your size and the assurance outcome you need.

01

Assess

Interviews with the people who operate the controls, review of policies and evidence, control testing, and technical validation of the environment where the control is supposed to live. A factual baseline, not an opinion.

02

Prioritize

Gaps rated for risk and business impact, mapped for dependency and sized for effort, producing a sequenced roadmap rather than a flat list of 300 findings.

03

Implement

Governance and policy design, control implementation, documented risk treatment and evidence preparation, alongside your IT team, your MSP or our managed security practice.

04

Sustain

Recurring control reviews, evidence management, internal audit and executive reporting. The phase most providers skip, and the one that decides whether next year is calm.

Every engagement produces the same deliverable set: an executive summary written for the board rather than the security team, a requirement-by-requirement control assessment and findings register with defensible severity ratings and remediation guidance, a risk-rated roadmap with owners and target dates, an evidence index showing which artifact proves which requirement, and a walkthrough session for leadership or the audit committee.

Our compliance services

Our compliance services.

Assessment and readiness

Gap and readiness assessment

The starting point for most engagements. We assess your control environment against a target framework and produce a requirement-by-requirement view of what is in place, partially in place and missing, with a findings register, severity ratings, evidence of what we tested and a realistic timeline to readiness. Available for ISO 27001, SOC 2, NIST CSF 2.0, NIST SP 800, CIS Controls v8.1, PCI DSS v4.0, CMMC 2.0, HIPAA and others.

Security and privacy maturity assessment

A broader read than a single framework check, benchmarking capability across cybersecurity, privacy and AI governance, third-party risk, security operations, business continuity, incident response and regulatory compliance. The right choice when the board wants a baseline and a trajectory rather than a certificate.

Risk assessment and risk treatment (ISO 31000 aligned)

A defensible risk methodology, a populated risk register, documented treatment decisions and residual risk ratings an auditor or board can follow. Most certification frameworks require a repeatable risk process, and it is the piece most often missing.

Implementation and remediation

Implementation support

Closing the gaps the assessment found: designing the control, documenting it, standing it up and testing that it works. At whatever depth you need, from advisory guidance to your team through to Cyberwall engineers operating the control as a managed service.

Policy and governance development

Policy framework, review cycles, roles and responsibilities, oversight structures, and the compliance documentation the framework requires. Written to be usable by your organization rather than downloaded from a template library and search replaced.

Evidence preparation and management

Access reviews, change logs, incident records, backup restore tests, training completion and control testing captured on a defined schedule as they happen, so the artifact a SOC 2 auditor samples against already exists instead of being rebuilt from memory. The difference between an audit that takes two weeks and one that takes four months. For access-control evidence, an identity risk assessment of your Microsoft 365 or Google Workspace tenant captures administrator inventory, multi-factor coverage and third-party app permissions in one document. For training evidence, see our security awareness training requirements, clause by clause.

Internal audit

Independent, risk-based review of your management system and controls, with documented findings, corrective action tracking and follow-up. ISO 27001 requires an internal audit programme and a management review. We run both, and in a way that produces useful findings rather than a rubber stamp.

Certification and audit readiness support

Pre-audit readiness review, evidence package assembly, auditor liaison, coordination with the certification body or CPA firm, and support responding to requests and findings during fieldwork. When the auditor request lands, someone answers it with you.

Ongoing and managed

Compliance-as-a-Service

Compliance run as an operating program rather than a project, priced monthly and scaled to your framework load. Includes quarterly compliance reviews, continuous evidence collection, risk register management, corrective action tracking, internal audit, audit coordination, and executive and board reporting, keeping the program audit-ready throughout the year.

vCISO advisory

Security leadership without a full-time executive hire: strategy, governance, risk reporting, policy oversight, budget and roadmap input, and board guidance from a senior practitioner who knows your environment. Frequently the piece that makes a compliance program stick, because someone senior owns it.

Third-party and vendor risk management

Your compliance posture depends on the vendors in your environment, and every major framework now says so. Vendor due diligence, support for the security questionnaires you receive and send, vendor risk review, remediation tracking and ongoing oversight of the third-party population.

Who does the work

Engagements are staffed by senior practitioners, not a template and a junior analyst. Certifications held across the Cyberwall team include CISA, CRISC and CDPSE (ISACA), ISO/IEC 27001 Lead Auditor, ISO/IEC 27701 Lead Auditor (PIMS), ISO/IEC 20000 Lead Auditor, ISO/IEC 27032, EC-Council Certified Security Analyst (ECSA) and Certified Cyber Threat Analyst (CCTA).

AI governance and responsible AI

AI governance and responsible AI

AI moved into business processes faster than governance did. AI-enabled tools are already handling customer data and sitting inside products, and in most organizations nobody has documented who approved them, what data they touch or who is accountable when they get it wrong. Auditors, enterprise customers and regulators have all started asking. Where personal information is involved, we run this jointly with our privacy practice.

ISO/IEC 42001, Artificial Intelligence Management System

The first certifiable management system standard for AI, structured like ISO/IEC 27001 and designed to sit alongside it. AIMS gap assessment, governance and policy design, AI risk and impact assessment processes, control implementation, internal audit and certification readiness. If you already hold or are pursuing ISO 27001, most of the management system scaffolding is reused rather than rebuilt.

NIST AI Risk Management Framework (AI RMF)

A voluntary, risk-based framework organized around Govern, Map, Measure and Manage. We assess your current state across all four, identify where AI risk is being created and by whom, prioritize against business impact and build an implementation roadmap. The practical choice for a defensible AI risk posture without committing to certification, and the usual step before an ISO 42001 program.

AI security review

Governance without technical validation is an assumption. We threat-model AI and LLM applications against the risks that actually apply: prompt injection, insecure output handling, training and inference data exposure, supply chain risk in models and plugins, and over-permissioned integrations. Aligned to OWASP guidance for LLM and generative AI, with MITRE ATLAS mapping adversarial techniques to your safeguards.

What the engagement establishes

→AI governance model: accountability, decision rights, policies and the oversight structure that approves AI use.
→AI system inventory: scope, use cases, owners, data classes and dependencies, including the tools nobody registered.
→AI risk register: risks, controls, treatment actions and residual risk, in the same form as your enterprise risk register.
→Responsible AI roadmap: prioritized actions tied to business objectives, with technical findings and remediation guidance.
Standards and frameworks we cover

Standards and frameworks we cover.

Which of these govern you comes down to three questions: what industry you are in, where your customers live, and what your own clients ask for in their vendor security questionnaires. Each framework is described once below, and the sector index at the end of this section shows which ones typically apply to you.

SOC 2, NIST and CIS

FrameworkWhat it covers and how Cyberwall helps
SOC 2 (Type I and Type II)Trust Services Criteria assurance for service organizations. Readiness and gap assessment, control design, Type I and Type II preparation, internal control testing, evidence collection support and audit coordination with your CPA firm.
NIST CSF 2.0Risk-based program structure across Govern, Identify, Protect, Detect, Respond and Recover. Current and target state profiles, maturity assessment, gap analysis, improvement roadmap and vCISO alignment. Usually run with NIST SP 800, which supplies the control detail behind the CSF outcomes.
NIST SP 800The NIST control publications underneath most US federal and enterprise programs, covering security and privacy controls for information systems and the protection of controlled unclassified information. Control assessment, tailoring and baseline selection, CUI scoping, supplier security assessment, POA&M development, government program readiness and security authorization support.
NIST AI RMFTrustworthy and responsible AI across Govern, Map, Measure and Manage. AI governance assessment, responsible AI evaluation and AI risk program development.
CIS ControlsPrioritized safeguards organized into Implementation Groups. IG-based baseline assessment, safeguard review, maturity evaluation and a pragmatic implementation roadmap. Often the most practical starting point for an organization not yet chasing a certificate.

ISO/IEC standards

StandardWhat it covers and how Cyberwall helps
ISO/IEC 27001:2022Information Security Management System. Gap and readiness assessment, ISMS implementation, risk assessment and treatment, Statement of Applicability, Annex A control design, internal audit, management review support and certification preparation.
ISO/IEC 27017Cloud security controls. Cloud control assessment with implementation guidance.
ISO/IEC 42001Artificial Intelligence Management System. Gap assessment, governance design, internal audit and certification readiness.
ISO 22301Business Continuity Management System. BCMS assessment, business impact analysis, BCP and DR design, and exercise support.
ISO 31000Enterprise risk management. Risk framework design and risk assessment facilitation.

ISO/IEC 27018 and ISO/IEC 27701, which cover privacy in the cloud and privacy management systems specifically, are on our Privacy Consulting page.

Which frameworks apply to your sector

Healthcare: ISO 27001, SOC 2, plus HIPAA, HITRUST CSF and PHIPA on our Privacy Consulting page. Financial services: PCI DSS, ISO 27001, SOC 2, NIST CSF 2.0, and OSFI guidance for Canadian credit unions and federally regulated institutions. Government and public sector: CMMC 2.0, NIST SP 800, FedRAMP, CJIS. Technology and SaaS: SOC 2, ISO 27001, plus customer security questionnaires. Education, manufacturing, professional services and MSPs: CIS Controls, NIST CSF 2.0, ISO 27001, SOC 2. AI-enabled organizations in any sector: ISO 42001, NIST AI RMF, OWASP LLM guidance, MITRE ATLAS.

Common questions

Common questions.

Which frameworks actually apply to us?

It depends on your industry, where your customers are, and what your clients require in their vendor questionnaires. This is usually the first thing we sort out together. A healthcare provider holding patient records has a different control set to demonstrate than a US professional services firm answering to state breach notification law.

Does Cyberwall hold ISO 27001 or other certifications?

Cyberwall holds SOC 2 Type II. The other frameworks named here are ones we help clients meet, not certifications Cyberwall itself holds, and we are precise about that distinction on every questionnaire we help answer.

You implement controls and you run internal audit. Is that a conflict?

It would be if the same people did both. ISO 27001 requires internal audits to be objective and impartial, and auditors not to audit their own work. Where Cyberwall has implemented or operates a control, the internal audit of that control is staffed separately from the delivery team, and the separation is set out in the engagement letter. If you would rather the internal audit sit entirely outside Cyberwall, we will tell you that too and work with whoever you appoint.

How long until we are audit ready?

It varies with how much control documentation already exists, and a gap assessment in the first few weeks gives you a real timeline rather than a guess. As a rough shape, an organization with reasonable IT hygiene and no formal program typically spends three to six months reaching SOC 2 Type I readiness, with a Type II observation window on top. ISO 27001 usually runs longer, because the management system sits on top of the controls.

Is "compliant" the same as "secure"?

No. A framework tells you what has to be documented and demonstrated. Good security practice is what keeps you out of the incident. Plenty of breached organizations were compliant on the day. We treat the framework as the floor and build toward both at once.

Do we need AI governance if we only use off-the-shelf AI tools?

Usually yes, and that is the case most organizations are in. A commercial AI tool still sends information out of your environment, still creates a new purpose for data collected for something else, and still produces outputs people act on. ISO/IEC 42001 and NIST AI RMF apply to organizations that deploy AI, not only to those that build it.

From the blog

Cyberwall Successfully Passes SOC 2 Type II Audit →

What Credit Unions Should Ask a Managed Security Provider →

Works with

Pairs naturally with these.

Can you prove it today?

Book a compliance readiness call. Thirty minutes, no cost, and you leave knowing which frameworks govern you and where the gaps are.