Common questions
Answered the way we would answer them on a call. If what you need is not here, ask, and we will add it.
Choosing
It depends on what prompted the question. If nobody has asked you to prove anything, a documentation pack is probably enough. If a customer, an insurer or your board is asking for evidence rather than policy, that is an assessment. The ladder on the products page sets out what each one can actually prove.
No. Every document is complete and written, with bracketed fields where a figure or a name has to be yours. You are replacing values, not writing sections. Download one and see before you decide.
NIST CSF 2.0, ISO 27001, CIS Controls, SOC 2 Trust Services Criteria, CMMC Levels 1 and 2, and data privacy obligations. If the standard you are held to is not among them, you can commission a pack for it.
The engagement
A report of every control assessed against the evidence behind it, a roadmap of what to fix in what order with named owners and verification criteria, and a briefing that goes through both. Not a score and not a certificate.
No, and that is deliberate. We do not configure systems, deploy software or make changes, because a supplier who both implements and assesses is marking their own work. We specify what needs doing precisely enough for your team or your provider to do it, then verify it closed. Why that matters.
We record it. A control that cannot be demonstrated is reported as unproven, not softened. And if our honest view at the outset is that you do not need a paid engagement yet, we say so before you spend anything.
Yes, and it is usually the right arrangement. They know your environment better than we will. The difference is who the report goes to: we report to you rather than to whoever implemented the controls.
Afterwards
Yes. Editable files, yours to keep, with updates included. There is no platform to stay subscribed to and nothing stops working if you stop working with us.
No. Engagements are confidential and we will not list a client to win the next one. If a published reference list is what decides it for you, that is a fair reason to choose someone else.
No. We do not publish client names and we do not pass client details on privately either. Confidentiality that only holds until the next sales call is not confidentiality. Judge the work instead: the free documents are the same standard we deliver to paying clients, and you can read every one of them before you talk to us.
Confidentiality
Yes. Send us yours and we will sign it, or we will provide one. It is signed before we see anything of yours.
It is handled under whichever NDA is in force and deleted at the end of the engagement. We do not keep your evidence as a reference set, we do not reuse it on another engagement, and we do not need to hold it to stand behind the report.
Commercial
Because a service fee depends on scope that has not been agreed yet, and a number with an asterisk on it is worth less than a straight answer. Scope, fee and end date are fixed in writing before any work starts, and none of them moves without your agreement. The packs are different: those are products and they carry a price.
No. Every engagement has a fixed fee against an agreed scope. If the scope changes, we agree that in writing first, including what it costs.
Not once it has been delivered, because the whole product is the content and you have it. That is why every pack has a free sample and the full document list is published before you buy. Read the sample first: if the writing is not what you expected, do not buy the pack.
Still not answered
If you had to come to this page to find something out, the page it should have been on was not clear enough. Tell us what you were looking for and we will answer you and fix that page.