TSR Solutions Managed IT & security

Compliance and policy assessment

A gap analysis of your policies and controls against HIPAA, PCI DSS, SOC 2, ISO 27001, GDPR or CMMC, with a plan to close what is missing.

What changes for you

You know exactly where you fall short

A written gap list against the standard you need, control by control, instead of a general feeling that you are probably fine.

A plan, not just a list

Each gap comes with a recommended action and an order to do them in, so the report becomes a project rather than a worry.

Proof for customers and regulators

Documented policies and assessed controls are what a customer security questionnaire, an auditor or a DoD prime contractor wants to see.

What's included

  • Review of your current policies, procedures and documentation
  • Assessment of controls against your chosen standard: HIPAA, GDPR, PCI DSS, SOC 2, ISO 27001 or CMMC
  • Gap analysis identifying where you do not meet the requirement
  • Written action plan with recommendations in priority order
  • Implementation guidance while your team or TSR closes the gaps
  • For defence contractors: CMMC readiness at any level, including how Controlled Unclassified Information is handled

How it works

From the first call to steady state.

  1. 1

    Review

    We collect and read your current policies, procedures and evidence, and interview the people who run the controls.

  2. 2

    Analyse

    We compare what you have against every requirement of the standard and record each gap.

  3. 3

    Recommend

    You receive an action plan: what to fix, in what order, and what it takes.

  4. 4

    Support

    We stay on to guide implementation, and can run the technical changes under a package or as project work.

Why TSR

1991
Serving Wisconsin businesses since
24×7
Detection and response in Guardian and Sentinel
One rate
Per user, per month. No add-on invoices inside a package

Built on

  • MicrosoftMicrosoft 365, Entra ID, Intune and Defender for Business
  • Blackpoint Cyber24×7 managed detection and response
  • NinjaOneEndpoint monitoring, patching and remote support
  • AutoElevatePrivilege management
  • HuduDocumentation and credential vaulting
  • Phin SecuritySecurity awareness training and phishing simulation

Questions we get asked

Which standards do you assess against?

HIPAA, GDPR, PCI DSS, SOC 2, ISO 27001 and CMMC. If you have a different requirement, tell us and we will confirm whether we can cover it.

We are a DoD subcontractor. Can you help with CMMC?

Yes. CMMC is required for DoD contractors and subcontractors that handle sensitive defence information. We assess your readiness at the level you need, focus on how CUI is protected, and lay out the practices you still have to put in place.

Is this an audit or a certification?

Neither. It is a readiness assessment. It tells you what an auditor or certifying body would find, so you can fix it first. Certification itself comes from the relevant body.

Do you write the policies too?

The assessment identifies which policies are missing or out of date. Writing and maintaining them is part of the vCISO service, or can be scoped as a project.

Is this included in a package?

The compliance assessment and management platform is included in Sentinel and available as an add-on with Foundation, Guardian and Co-Managed Guardian.

Request a compliance assessment quote

Tell us a little about your environment and an engineer will reply within one business day with next steps, not a brochure.

Prefer to talk? Call 262-292-2000 or email sales@tsrsolutions.com.

Or open the full quote form: Get a quote for Compliance assessment