Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Services

Security and compliance advisory services

Each service page explains who it’s for, what’s included and excluded, what you receive, and how the work runs, so you can judge the fit before you talk to us.

The services on this site fall into three groups. Readiness work prepares you for a formal outcome, such as a SOC 2 report, an ISO/IEC 27001 certificate, a PCI DSS validation or a CMMC assessment, which an independent, authorized party then issues. Testing, such as penetration testing and cloud and application reviews, shows how your systems hold up against real attack techniques.

Advisory work covers risk assessments, vCISO leadership, vendor risk, policies and evidence, and incident readiness. If you're unsure where to begin, the service finder asks a few questions about your situation and suggests a first step.

Choose a service

Start with the problem in front of you. Every page lists what’s out of scope as clearly as what’s in it.

  • PCI DSS readiness

    PCI DSS readiness — scoping support, gap assessment, and remediation planning before a QSA assessment or self-assessment.

  • Risk assessments

    Security posture and risk assessments mapped to NIST CSF 2.0 and CIS Controls.

  • Virtual CISO

    Virtual CISO advisory: roadmap, governance, policy, metrics, and executive reporting.

  • Compliance readiness

    Compliance readiness for SOC 2, ISO/IEC 27001, the HIPAA Security Rule, PCI DSS, and CMMC.

  • Penetration testing

    Authorized penetration testing for web applications, APIs, and external or internal networks.

  • Cloud & application security

    Cloud and application security reviews covering architecture, configuration, identity, logging, and secure design.

  • Vendor risk

    Third-party and vendor-risk reviews with prioritized remediation guidance.

  • Incident readiness

    Incident-readiness services: response-plan development and tabletop exercises.

Not sure where to start? Use the service finder to match your situation to a service, or compare published starting prices.

How every engagement works

  • Remote-first, senior-led delivery. Every engagement is led by an experienced practitioner.
  • Every engagement begins with a written scope and proposal.
  • We work with U.S.-based organizations in all 50 states and Washington, D.C. We don't accept international engagements.

What we don't do

Security Inspect is not a law firm, a CPA firm, or an ISO/IEC 27001 certification body. We don't give legal opinions, issue SOC 2 reports or ISO/IEC 27001 certificates, or guarantee that a client will pass an assessment.

Read how readiness work differs from certification

Talk to a practitioner about your priorities

Tell us what you’re trying to achieve. We’ll help you work out which service fits, if any.

What happens next

  1. Tell us what's prompting the work.
  2. Discuss goals, constraints, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.