Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Security and compliance guides

Plain-language guides to SOC 2, the HIPAA Security Rule, PCI DSS, ISO/IEC 27001, CMMC, penetration testing and security leadership, each with its primary sources listed.

These guides explain security and compliance topics in plain language: SOC 2 reports, the HIPAA Security Rule, PCI DSS, ISO/IEC 27001, CMMC and NIST SP 800-171, penetration testing, risk assessment, vCISO leadership and incident response planning.

Each guide answers its question first, then goes into detail. It lists the primary sources it relies on, such as AICPA criteria, the Code of Federal Regulations, PCI Security Standards Council documents and NIST publications, and shows the date those sources were checked. The glossary defines the terms the guides use.

Start here

Good first reads if you're preparing for SOC 2, the HIPAA Security Rule, PCI DSS or a penetration test. Each also appears under its subject below.

Guides by subject

Each subject links to the page on this site that covers it. Every guide lists its primary sources and the date they were checked.

Showing all 20 guides in 8 subjects.

CMMC and NIST SP 800-171

CMMC readiness overview

Comparing frameworks and formal outcomes

Compliance frameworks compared

Penetration testing and vulnerability scanning

Penetration testing service overview

Security leadership, risk and incident readiness

All security services

Glossary

Short, precise definitions, including who is authorized to issue each formal outcome. A few terms people often ask about:

Browse all 68 glossary terms

Tools

Help choosing a service, understanding cost, or finding a page.

  • Tool

    Service finder

    Answer a few questions about your situation to see which services fit.

  • Tool

    Pricing estimator

    See how starting prices and scope factors fit together before you ask for a proposal.

  • Tool

    Site search

    Search services, compliance guides, glossary terms, and articles in one place.

How these resources are written

We review dated technical and compliance content at least every six months.

Each article lists the primary sources it relies on, so you can check the original.

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Have a question these resources don't answer?

Every engagement begins with a written scope and proposal.