Skip to main content
CyberBackstop

02 / The Catch · Compliance & audit backup

We catch what your process misses.

Your team drives the SOC 2, ISO 27001, HIPAA, PCI, or CMMC effort. We’re the review layer behind it — finding the gap while it’s still cheap to fix, and before it counts against you.

The gap

You’re not missing effort. You’re missing a second reader.

Somebody at your company owns the compliance program. They have the spreadsheet, they chase the evidence, they know which controls are shaky. They are usually not a full-time compliance professional, and they are almost never someone who has been through the audit from the other side of the table.

That is the entire difficulty. Compliance work is judgement work. Is this screenshot evidence, or is it a picture of a screen? Does this policy describe what your company actually does, or what a template said it should? Will “we review access quarterly” hold up when the auditor asks for four quarters of proof and you have two?

Nobody inside a small program can reliably answer those questions about their own work. Not because they’re careless — because it’s their work. Every serious process has a reviewer who didn’t do the thing being reviewed. Most compliance programs at this size simply don’t have one, and they find out during fieldwork, when the finding is expensive and the timeline is gone.

That’s the role we take. Not the driver. The second reader.

Who owns what

You keep the pen.

This is a review engagement, and the ownership line is drawn on day one and does not move.

Your team owns: the program, the timeline, the auditor relationship, the control decisions, the remediation, and the final word on every document. Your name is on the policies. Your team’s evidence goes in the file.

We own: the second read. We test your controls against the criteria the way an auditor will, mark what won’t hold and why, draft what you ask us to draft, and rehearse the questions before someone else asks them for the record.

We never speak to your auditor as your representative unless you explicitly ask us to join a call, and we never sign anything on your behalf. We are also not your auditor: we don’t issue opinions, certify, or attest, and we are neither a CPA firm nor a CMMC C3PAO. A firm that offers you both preparation and the opinion is selling you a conflict of interest that a good auditor — and a good customer — will notice.

The routine

What this actually looks like on a Tuesday

  • Weekly

    A working review session

    Sixty minutes against the live control set. We walk what your team closed since last week, what we’ve reviewed, and what we’re sending back. Every item leaves the session with a named owner and a date — one of yours, or one of ours.

  • Continuous

    Evidence review, item by item

    Your team collects the evidence; we read it before the auditor does and mark each item holds / thin / won’t hold, with the reason in one sentence. “Thin” is the useful category: technically responsive, but it will draw a follow-up request you don’t want at week six of fieldwork.

  • Running

    A gap register your team owns

    One list, in your document store, in your format. Gap, control reference, severity, owner, target date, current state. It is the artifact your compliance owner uses to run the program and to answer “where are we?” without building a status deck.

  • As they arrive

    Questionnaire and RFP support

    Customer security questionnaires, vendor risk reviews, and the security section of an RFP — turned around fast, answered accurately, and consistent with what your policies actually say. Answers get reused, so the second one is faster than the first.

  • Before the audit

    A readiness dry-run

    We run the audit interview with your team: the same questions, the same evidence requests, the same follow-ups. Your people practise answering in their own words. The first time someone asks your engineering lead to walk through change management should not be the real thing.

  • After findings

    Remediation, in order

    When gaps land, they get ordered by what actually threatens the report and what actually reduces risk — not by whichever is easiest to close. Your team fixes them. We check the fix and update the register.

The coverage

Frameworks we back you on

Same role in every one: your team drives, we review.

  • SOC 2 (Type I and Type II)

    Trust Services Criteria scoping — including the argument for not pulling in criteria you don’t need — control design review, evidence quality checks across the observation window, and readiness testing before fieldwork. The most common Type II failure we see is not a missing control; it’s a control that ran for nine months of a twelve-month window. We watch for that from the start.

  • ISO 27001 (and ISO 27701)

    Statement of Applicability review, Annex A control mapping, risk assessment methodology that will survive the certification body’s questions, internal audit support, and management review preparation. Also the tedious part nobody schedules time for: making sure the ISMS documents are actually consistent with each other, because inconsistency between them is where Stage 1 stalls.

  • HIPAA

    Security Rule and Privacy Rule control review, risk analysis quality — the requirement is routinely under-documented and it’s the first thing OCR asks for — Business Associate Agreement review in both directions, workforce training and sanction policy, and breach notification procedures your team can actually execute under time pressure.

  • PCI DSS

    Scope reduction first, because scope is the entire cost of PCI. Which SAQ genuinely applies, what your payment flow really touches, segmentation validation, and evidence review against the requirements your QSA or acquirer will assess. Getting the scope question right is worth more than any other hour spent on PCI.

  • CMMC (Levels 1 and 2)

    NIST SP 800-171 control review, System Security Plan quality, POA&M realism, scoping and enclave strategy for the systems that actually touch CUI, and assessment readiness. We prepare you. We are not a C3PAO and cannot assess you — those are separate roles under the program, and any firm blurring them is a problem for your eventual certification.

  • Everything else that lands on your desk

    Customer security addenda, insurance questionnaires, TX-RAMP and StateRAMP prep questions, NIST CSF alignment, and the bespoke control set your largest customer invented. Same review posture.

Good fit

This works well when…

  • Someone internal owns the compliance effort and intends to keep owning it
  • You’re preparing for a first audit and have no internal precedent to work from
  • You’ve been through an audit before and want fewer findings this time
  • Your team is using a compliance automation platform and needs someone to judge whether the green checkmarks mean anything
  • Security questionnaires are arriving faster than your team can answer them
  • A deal is waiting on a certification and you need an honest read on the timeline

And it doesn’t work when…

  • You want someone to run the whole program with no internal owner — that’s a different engagement, and we’ll tell you honestly what it costs
  • You want the certificate without the controls; we don’t write evidence and we don’t help anyone describe a process they don’t operate
  • Your audit is in three weeks and the program hasn’t started (we’ll tell you what’s achievable, and it may be a later audit date)
  • You need the audit opinion itself — that’s your auditor, and it can’t be us

Asked and answered

Questions we get

  • Q. We’re already using a compliance automation platform. Do we still need you?

    Frequently, yes, and for a specific reason. Those platforms are very good at collecting evidence and tracking tasks. They cannot tell you whether your policy describes your actual process, whether your evidence is persuasive, or whether the control you marked complete would hold under a follow-up question. A green dashboard is a claim, not a conclusion. We review the claim. We work with whichever platform you’ve chosen and we don’t sell one.

  • Q. Can you just do it for us?

    Not in this engagement, and the reason is practical rather than principled. Compliance that lives with an outside party stops being true the moment the engagement ends — the control decays, nobody notices, and the next audit finds it. Your team stays the owner so the program survives us. If you need more hands than review, the augmentation engagement adds them, and your team still owns the program.

  • Q. How much of our team’s time does this take?

    Realistically: your compliance owner spends a few hours a week, plus the evidence work they’d be doing anyway. Control owners in engineering, HR, and IT spend a few hours a month. The dry-run is a half day. We are deliberately not the kind of engagement that generates work for your team to feed us — if you’re spending more time managing us than doing the program, we’ve built it wrong.

  • Q. When should we bring you in?

    Earlier is cheaper. The most valuable point is before you finalize scope and before the observation window opens, because scoping mistakes are the expensive kind and they compound daily. The second most valuable point is four to eight weeks before fieldwork, for the dry-run. Mid-fieldwork is possible, but by then the options narrow to triage.

  • Q. Will you be there during the audit?

    We prepare your team to handle it themselves, which is the goal. If your team wants us on the call as backup, we can be — listening, and available when a question lands outside your owner’s area. We do not answer for you, and we don’t represent you to the auditor.

  • Q. What if you find something serious?

    You hear it immediately and plainly, with a recommendation and a sense of what it costs to fix. That’s the job. A review layer that softens findings to keep the relationship pleasant is worse than no review layer, because it produces confidence you haven’t earned. We’d rather have the uncomfortable conversation in week two than let your auditor have it in week twelve.

  • Q. Do you work with our auditor?

    We work around them, deliberately. We’ll help your team prepare responses, organize evidence, and understand what’s being asked. We keep the relationship between your team and the auditor, which is where the independence has to sit.

Next

Get a read before the auditor does.

Tell us which framework you’re facing and where you are in it. Forty-five minutes and an honest answer about your timeline — including if the honest answer is that it’s tight.

Staff & leadership augmentation