Compliance and policy assessment
A gap analysis of your policies and controls against HIPAA, PCI DSS, SOC 2, ISO 27001, GDPR or CMMC, with a plan to close what is missing.
What changes for you
You know exactly where you fall short
A written gap list against the standard you need, control by control, instead of a general feeling that you are probably fine.
A plan, not just a list
Each gap comes with a recommended action and an order to do them in, so the report becomes a project rather than a worry.
Proof for customers and regulators
Documented policies and assessed controls are what a customer security questionnaire, an auditor or a DoD prime contractor wants to see.
What's included
- Review of your current policies, procedures and documentation
- Assessment of controls against your chosen standard: HIPAA, GDPR, PCI DSS, SOC 2, ISO 27001 or CMMC
- Gap analysis identifying where you do not meet the requirement
- Written action plan with recommendations in priority order
- Implementation guidance while your team or TSR closes the gaps
- For defence contractors: CMMC readiness at any level, including how Controlled Unclassified Information is handled
How it works
From the first call to steady state.
- 1
Review
We collect and read your current policies, procedures and evidence, and interview the people who run the controls.
- 2
Analyse
We compare what you have against every requirement of the standard and record each gap.
- 3
Recommend
You receive an action plan: what to fix, in what order, and what it takes.
- 4
Support
We stay on to guide implementation, and can run the technical changes under a package or as project work.
Why TSR
- 1991
- Serving Wisconsin businesses since
- 24×7
- Detection and response in Guardian and Sentinel
- One rate
- Per user, per month. No add-on invoices inside a package
Built on
- MicrosoftMicrosoft 365, Entra ID, Intune and Defender for Business
- Blackpoint Cyber24×7 managed detection and response
- NinjaOneEndpoint monitoring, patching and remote support
- AutoElevatePrivilege management
- HuduDocumentation and credential vaulting
- Phin SecuritySecurity awareness training and phishing simulation
Questions we get asked
Which standards do you assess against?
HIPAA, GDPR, PCI DSS, SOC 2, ISO 27001 and CMMC. If you have a different requirement, tell us and we will confirm whether we can cover it.
We are a DoD subcontractor. Can you help with CMMC?
Yes. CMMC is required for DoD contractors and subcontractors that handle sensitive defence information. We assess your readiness at the level you need, focus on how CUI is protected, and lay out the practices you still have to put in place.
Is this an audit or a certification?
Neither. It is a readiness assessment. It tells you what an auditor or certifying body would find, so you can fix it first. Certification itself comes from the relevant body.
Do you write the policies too?
The assessment identifies which policies are missing or out of date. Writing and maintaining them is part of the vCISO service, or can be scoped as a project.
Is this included in a package?
The compliance assessment and management platform is included in Sentinel and available as an add-on with Foundation, Guardian and Co-Managed Guardian.
Request a compliance assessment quote
Tell us a little about your environment and an engineer will reply within one business day with next steps, not a brochure.
Prefer to talk? Call 262-292-2000 or email sales@tsrsolutions.com.
Or open the full quote form: Get a quote for Compliance assessment
The form is not available right now.
Email sales@tsrsolutions.com or call 262-292-2000 and an engineer replies within one business day.
More in Security
Managed SOC
A staffed security operations center that watches your endpoints, network and cloud around the clock and acts when something is wrong.
Learn morePentest
A scoped, human-led attack on your network, web applications and APIs so you find the gaps before someone else does.
Learn moreWeb app pentest
An OWASP-based, manual test of your web application or API, with a report your developers can act on within days.
Learn more