Single Framework Readiness
14 Days

One framework. Control assessment, gap register rated by audit impact, and a roadmap.
One framework. Control assessment, gap register rated by audit impact, and a roadmap.
A readiness assessment that tells you whether you can pass a SOC 2 Type II or ISO 27001 audit, what will fail if you attempt it now, and the sequence to fix it. Built by an accredited ISO 27001 Lead Auditor who has authored a full 93-control Statement of Applicability and run a 98-subcategory NIST CSF maturity assessment.
The costly mistake is entering an observation window before the controls are operating. A Type II audit measures controls over time, so a control implemented in month four of a six-month window has four months of evidence it cannot produce. Readiness work exists to prevent exactly that.
What you receive:
Control assessment against SOC 2 Trust Services Criteria or ISO 27001 Annex A, or both.
Evidence-readiness review: what you can prove today versus what you merely assert.
A gap register rated by audit impact.
A remediation roadmap sequenced against your target audit date.
A policy and documentation inventory showing what is missing.
How I work. I start from your audit date and work backwards. Every finding carries the question an auditor will ask and the evidence you would need to answer it. Where a control cannot be ready in time, I say so early enough for you to move the date rather than fail the audit.
Who this is for. Companies with an audit booked, companies whose largest customer has just demanded a report, and teams who have been told they are ready and want that tested before it is expensive to be wrong.
14 Days
30 Days
45 Days

21 years directing security programs across 14 countries, from a 238-site, 28-state US footprint to embedded country security roles with Ericsson and the Inter-American Development Bank. I work across the line most organizations draw between physical and cyber. Accredited ISO/IEC 27001 Lead Auditor, five OCEG credentials, and a Technical Committee seat on the Board of Executive Protection Professionals, which authored ANSI/BEP EPS 2026. Assessments, audits, policy, program design.
21 years directing security programs across 14 countries, from a 238-site, 28-state US footprint to embedded country security roles with Ericsson and the Inter-American Development Bank. I work across the line most organizations draw between physical and cyber. Accredited ISO/IEC 27001 Lead Auditor, five OCEG credentials, and a Technical Committee seat on the Board of Executive Protection Professionals, which authored ANSI/BEP EPS 2026. Assessments, audits, policy, program design.








Terms and conditions apply