We establish whether the controls you believe are in place are actually operating, and give you the evidence to prove it to a customer, an insurer or your board. We also publish editable documentation for organizations that would rather deploy it themselves.
RootGuard Security assesses, documents, trains and verifies. We do not configure systems, we do not resell vendor products and we take no commission, which means there is no finding we benefit from making and none we benefit from softening. We report to the business rather than to the party that implemented the controls.
Security documentation is the written evidence that defines how an organization governs, implements and demonstrates its obligations. Without it, compliance cannot be shown. With it but unverified, you are relying on what people believe rather than on what is true. We close that second gap.
How it works
Getting started is simple. Every engagement has a fixed scope, a fixed fee and a fixed end date, agreed in writing before any work begins.

Step 1
Take the free readiness assessment. Eighty questions, about ninety minutes, and a scored result you keep whether or not you ever engage us.

Step 2
We confirm what is covered, what is excluded, what evidence we need and from whom. Signed before anything starts, so nothing later is a surprise.

Step 3
Controls assessed against evidence rather than assertion, and a documentation set deployed and tailored to your environment. Editable files, yours to keep.

Step 4
Each agreed action checked against a stated criterion. A message saying the work is done is not sufficient, and this is the step most engagements leave out.
Why RootGuard
There are no fill-in-the-blank sections in our documentation and no generic templates with a logo dropped on top. Everything is written by practitioners who run security operations and sit real audits, and tailored to the technologies and obligations you actually have.

We report to the business rather than to the party that implemented the controls. We do not configure systems, resell products or take vendor commission, so there is no finding we benefit from making and none we benefit from softening.

We ask for the export, the report, the record. Where the scale allows we inspect complete populations rather than samples. A control that cannot be demonstrated is recorded as unproven and reported as a finding.

Documentation is delivered as editable Word and Excel files with updates included. No platform to log into, no subscription required to keep your own policies, and no lock-in of any kind.
Our products
Editable, audit-focused documentation mapped to the frameworks your customers, insurers and regulators actually ask about. Every pack carries a free sample and the full document list.
Policies, standards and procedures to stand up a documented program from nothing, mapped to NIST CSF 2.0, ISO 27001 and CIS Controls.
Learn more →Playbooks, evidence-collection procedures, severity criteria, and the templates to brief executives, regulators and insurers when there is no time to draft.
Learn more →Privacy notices, data inventories, retention schedules, subject request workflows and the processing records a regulator will ask to see.
Learn more →Policies, procedures and evidence structure mapped to the Trust Services Criteria, so a readiness review finds a program rather than a gap list.
Learn more →Reach a defensible Level 1 self-assessment for Federal Contract Information, with the policies, evidence and scoring to affirm in SPRS.
Learn more →Prepare for a Level 2 assessment: a System Security Plan, POA&M and policies across all 110 NIST SP 800-171 requirements.
Learn more →Our services
Documentation proves a program exists. An assessment establishes whether the controls behind it operate. Buy one service, or run them in sequence.
Assess, document, implement, train, verify. You end with a documented program operating in your business, staffed by trained people, backed by evidence the controls work.
Learn more →Readiness assessed against evidence, a complete response set deployed, a facilitated exercise with your own people, and confirmation the gaps are closed.
Learn more →Monthly. Documentation kept current as frameworks move, and independent verification that agreed actions have genuinely closed rather than been reported as closed.
Learn more →Free tools and guides
Self-scoring workbooks and complete production-ready documents, built to the same standard we deliver to paying clients. No account, no card, no email required, and the four below are only the start.
Eighty questions in plain language across all six framework functions. Every control is asked twice: do you do this, and could you prove it today.
Download →A working register with an auto-scoring matrix, likelihood and impact before and after treatment, and a worked example.
Download →Eight pages. Severity definitions, a role table, contact list, the six response phases, an incident log and an after-action record.
Download →Fifteen sections, written to be cut down to your organization rather than adopted whole. A complete foundation policy, not a sample.
Download →Complete the readiness assessment, send us the result, and we will spend forty-five minutes going through it with you at no charge. If our honest view is that you do not need a paid engagement yet, we will say so. These tools are self-reported and unverified, and we say so on the front of them: they record what you believe about your controls. Establishing what is true is the paid work.
Documentation lifecycle
Contacts change, systems change, the person who knew the runbook leaves, and frameworks are revised. If your documentation is old enough to attend school, it needs a thorough review rather than a tidy-up.
The most static layer. High-level statements of management intent, generally good for three to five years without material change, but they must still be approved and dated.
Generally stable, but influenced by new obligations and by changes to your technology. Annual review, with a three to five year lifecycle before a rewrite.
The most dynamic layer. Shaped by people, providers and technology, and liable to change several times a year. This is the layer that decays first and fastest.
Our Program Support service exists for exactly this. Each month we verify a defined number of roadmap actions against their criteria, keep the register and the documentation current, and report to you rather than to whoever did the work.
Product categories
Each category includes professionally written, editable documentation and, where you want it verified, the assessment that establishes whether the controls behind it operate.
| Category | Key products | Frameworks |
|---|---|---|
| Policies & standards | Security Program Pack | NIST CSF 2.0, ISO 27001 / 27002, CIS Controls v8 |
| Incident response | Incident Response Pack, free incident response plan | NIST CSF, ISO 27035 |
| Risk management | Risk register, control assessment, risk register template | All major frameworks |
| Privacy | Data Privacy Pack | Privacy frameworks, Jamaica DPA, GDPR |
| Customer assurance | SOC 2 Readiness Pack | AICPA Trust Services Criteria |
| US defense supply chain | CMMC Level 1 and Level 2 Packs | CMMC, NIST SP 800-171, FAR 52.204-21 |
| Assurance services | Security Program Deployment, Program Support | NIST CSF 2.0 spine, crosswalked per standard |
Industries served
A standard is a standard for a reason, and that applies regardless of company size. Our documentation is written to industry-recognized practices and right-sized to the organization in front of us.
Credit unions, lenders, brokers, accountants
Law firms, consultancies, agencies
Contact centres, shared services, back office
Software, MSPs, hosting, integrators
Clinics, diagnostics, care providers
Multi-site retail, hotels, restaurants
Shipping, distribution, energy, water
Agencies, statutory bodies, charities
Talk to us
Tell us what prompted you to look and which framework matters. We will point you at the right pack or the right service with the reasoning rather than a recommendation, and if a paid engagement is not the right answer this quarter, that is a perfectly good outcome.