Can't Vanta tell us what we're missing?
Vanta is excellent at tracking automated checks — tests that pass or fail. But it doesn't assess the quality of your policies, whether your processes are actually followed, or whether your evidence will hold up under auditor scrutiny. Platform compliance is not the same as program compliance. This assessment covers both.
When should we do a gap assessment?
Before you engage an auditor. The gap assessment identifies what needs to be fixed so you can remediate before the audit starts. Doing this work during the audit costs more and takes longer.
What if we've already started compliance work?
That's fine. We'll assess what you've done so far, identify what's still missing, and give you a clear picture of remaining work. Many clients come to us after getting stuck partway through compliance on their own.
Do you help with remediation too?
Yes. The gap assessment produces the roadmap. If you want help executing that roadmap — writing policies, implementing controls, configuring Vanta, preparing evidence — we can scope a follow-on engagement for that work.
SOC 2 or ISO 27001 — which should we pursue?
That depends on your market. If your customers are primarily U.S.-based, SOC 2 is usually the right starting point. If you sell internationally, ISO 27001 may be required. We'll help you decide during the initial consultation — and if you need both, the gap assessment can cover both frameworks.
What does it cost?
Fixed-fee, scoped to the framework and your company's complexity. We'll give you a clear quote after an initial consultation. This engagement typically costs a fraction of what companies waste by going into an audit unprepared.