Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Independent Security Assurance, Done Right

We establish whether the controls you believe are in place are actually operating, and give you the evidence to prove it to a customer, an insurer or your board. We also publish editable documentation for organizations that would rather deploy it themselves.

RootGuard Security assesses, documents, trains and verifies. We do not configure systems, we do not resell vendor products and we take no commission, which means there is no finding we benefit from making and none we benefit from softening. We report to the business rather than to the party that implemented the controls.

Security documentation is the written evidence that defines how an organization governs, implements and demonstrates its obligations. Without it, compliance cannot be shown. With it but unverified, you are relying on what people believe rather than on what is true. We close that second gap.

242Controls assessed against evidence
123In the core baseline set
5Frameworks mapped and crosswalked
9Professional certifications held

How it works

From unproven to proven, in four steps

Getting started is simple. Every engagement has a fixed scope, a fixed fee and a fixed end date, agreed in writing before any work begins.

Score where you stand with the free readiness assessment

Step 1

Score where you stand

Take the free readiness assessment. Eighty questions, about ninety minutes, and a scored result you keep whether or not you ever engage us.

Agree the scope in writing before work begins

Step 2

Agree the scope

We confirm what is covered, what is excluded, what evidence we need and from whom. Signed before anything starts, so nothing later is a surprise.

Controls assessed against evidence, documentation deployed

Step 3

We assess and document

Controls assessed against evidence rather than assertion, and a documentation set deployed and tailored to your environment. Editable files, yours to keep.

Each agreed action verified closed against its criterion

Step 4

We verify it closed

Each agreed action checked against a stated criterion. A message saying the work is done is not sufficient, and this is the step most engagements leave out.

Why RootGuard

Three things that do not change

There are no fill-in-the-blank sections in our documentation and no generic templates with a logo dropped on top. Everything is written by practitioners who run security operations and sit real audits, and tailored to the technologies and obligations you actually have.

Independent of the party that implemented the controls

Independence

We report to the business rather than to the party that implemented the controls. We do not configure systems, resell products or take vendor commission, so there is no finding we benefit from making and none we benefit from softening.

Controls assessed against evidence rather than assertion

Evidence

We ask for the export, the report, the record. Where the scale allows we inspect complete populations rather than samples. A control that cannot be demonstrated is recorded as unproven and reported as a finding.

Editable documentation you own outright

Ownership

Documentation is delivered as editable Word and Excel files with updates included. No platform to log into, no subscription required to keep your own policies, and no lock-in of any kind.

Our products

Editable documentation for every situation

Editable, audit-focused documentation mapped to the frameworks your customers, insurers and regulators actually ask about. Every pack carries a free sample and the full document list.

Security Program Pack

Policies, standards and procedures to stand up a documented program from nothing, mapped to NIST CSF 2.0, ISO 27001 and CIS Controls.

Learn more →

Incident Response Pack

Playbooks, evidence-collection procedures, severity criteria, and the templates to brief executives, regulators and insurers when there is no time to draft.

Learn more →

Data Privacy Pack

Privacy notices, data inventories, retention schedules, subject request workflows and the processing records a regulator will ask to see.

Learn more →

SOC 2 Readiness Pack

Policies, procedures and evidence structure mapped to the Trust Services Criteria, so a readiness review finds a program rather than a gap list.

Learn more →

CMMC Level 1 Pack

Reach a defensible Level 1 self-assessment for Federal Contract Information, with the policies, evidence and scoring to affirm in SPRS.

Learn more →

CMMC Level 2 Pack

Prepare for a Level 2 assessment: a System Security Plan, POA&M and policies across all 110 NIST SP 800-171 requirements.

Learn more →

Our services

Three engagements, each with a defined end

Documentation proves a program exists. An assessment establishes whether the controls behind it operate. Buy one service, or run them in sequence.

Security Program Deployment

Assess, document, implement, train, verify. You end with a documented program operating in your business, staffed by trained people, backed by evidence the controls work.

Learn more →

Incident Readiness Deployment

Readiness assessed against evidence, a complete response set deployed, a facilitated exercise with your own people, and confirmation the gaps are closed.

Learn more →

Program Support

Monthly. Documentation kept current as frameworks move, and independent verification that agreed actions have genuinely closed rather than been reported as closed.

Learn more →

Free tools and guides

Fourteen free resources, and none of them need an account

Self-scoring workbooks and complete production-ready documents, built to the same standard we deliver to paying clients. No account, no card, no email required, and the four below are only the start.

Security Readiness Assessment

Eighty questions in plain language across all six framework functions. Every control is asked twice: do you do this, and could you prove it today.

Download →

Risk Register

A working register with an auto-scoring matrix, likelihood and impact before and after treatment, and a worked example.

Download →

Incident Response Plan

Eight pages. Severity definitions, a role table, contact list, the six response phases, an incident log and an after-action record.

Download →

Information Security Policy

Fifteen sections, written to be cut down to your organization rather than adopted whole. A complete foundation policy, not a sample.

Download →

Complete the readiness assessment, send us the result, and we will spend forty-five minutes going through it with you at no charge. If our honest view is that you do not need a paid engagement yet, we will say so. These tools are self-reported and unverified, and we say so on the front of them: they record what you believe about your controls. Establishing what is true is the paid work.

Documentation lifecycle

Security documentation has a shelf life

Contacts change, systems change, the person who knew the runbook leaves, and frameworks are revised. If your documentation is old enough to attend school, it needs a thorough review rather than a tidy-up.

Policies

The most static layer. High-level statements of management intent, generally good for three to five years without material change, but they must still be approved and dated.

Standards

Generally stable, but influenced by new obligations and by changes to your technology. Annual review, with a three to five year lifecycle before a rewrite.

Procedures

The most dynamic layer. Shaped by people, providers and technology, and liable to change several times a year. This is the layer that decays first and fastest.

Our Program Support service exists for exactly this. Each month we verify a defined number of roadmap actions against their criteria, keep the register and the documentation current, and report to you rather than to whoever did the work.

Product categories

What maps to which framework

Each category includes professionally written, editable documentation and, where you want it verified, the assessment that establishes whether the controls behind it operate.

CategoryKey productsFrameworks
Policies & standardsSecurity Program PackNIST CSF 2.0, ISO 27001 / 27002, CIS Controls v8
Incident responseIncident Response Pack, free incident response planNIST CSF, ISO 27035
Risk managementRisk register, control assessment, risk register templateAll major frameworks
PrivacyData Privacy PackPrivacy frameworks, Jamaica DPA, GDPR
Customer assuranceSOC 2 Readiness PackAICPA Trust Services Criteria
US defense supply chainCMMC Level 1 and Level 2 PacksCMMC, NIST SP 800-171, FAR 52.204-21
Assurance servicesSecurity Program Deployment, Program SupportNIST CSF 2.0 spine, crosswalked per standard

Industries served

Built to scale, from a single office upward

A standard is a standard for a reason, and that applies regardless of company size. Our documentation is written to industry-recognized practices and right-sized to the organization in front of us.

Financial services

Credit unions, lenders, brokers, accountants

Professional services

Law firms, consultancies, agencies

Business process outsourcing

Contact centres, shared services, back office

Technology

Software, MSPs, hosting, integrators

Healthcare

Clinics, diagnostics, care providers

Retail and hospitality

Multi-site retail, hotels, restaurants

Logistics and utilities

Shipping, distribution, energy, water

Public and non-profit

Agencies, statutory bodies, charities

Talk to us

If we think you do not need us yet, we will say so.

Tell us what prompted you to look and which framework matters. We will point you at the right pack or the right service with the reasoning rather than a recommendation, and if a paid engagement is not the right answer this quarter, that is a perfectly good outcome.