Cybersecurity compliance assessments, across every framework.
Compliance is the foundation of a credible security program, and the gate on a lot of revenue. SubRosa assesses your controls against the frameworks and regulations you answer to (SOC 2, ISO 27001, PCI DSS, HIPAA, NIST), with a clear gap analysis and a prioritized remediation roadmap, so you know exactly where you stand and what to fix first.
SOC 2 · ISO 27001 · PCI DSS · HIPAA · NIST · Gap analysis
What is a cybersecurity compliance assessment?
A cybersecurity compliance assessment evaluates how well your security controls meet the regulations and frameworks your organization is subject to, SOC 2, ISO 27001, PCI DSS, HIPAA, NIST, and others. It compares your current posture against each framework's requirements, identifies the gaps, and produces a prioritized remediation roadmap so you can close them in the right order. Run across multiple frameworks at once, it reveals where your obligations overlap, so the work you do for one standard counts toward the rest.
From gap analysis to remediation roadmap.
We evaluate every critical part of your compliance program, end to end.
Compliance gap analysis
A thorough evaluation of your current posture against each framework's requirements, with every gap documented and prioritized by risk.
Multi-framework assessment
Readiness and control assessments across SOC 2, ISO 27001, PCI DSS, HIPAA, and NIST, cross-mapped so overlapping controls are assessed once.
Policies & procedures
Review and development of the policies and procedures auditors expect, mapped to the controls they support.
Remediation roadmap & support
A prioritized remediation roadmap based on your risk profile, plus ongoing support to keep you compliant as regulations evolve.
Gap to audit-ready.
A compliance assessment establishes the distance between where you are and what a framework requires, then closes it. This is the shape of that work.
- 01
Scoping and framework mapping
We confirm which frameworks apply and map them against each other first. SOC 2, ISO 27001 and CMMC overlap heavily, and organisations pursuing more than one routinely do the same work several times because nobody mapped the controls once.
- 02
Control-by-control gap analysis
Every control is assessed as met, partially met or not met, with the reason recorded. Partially met is the category that matters — it is where most organisations sit and where a generic checklist tells you nothing useful.
- 03
Evidence review
Auditors do not accept assertions. We review what evidence exists for each control, whether it would satisfy an assessor, and what has to be produced or retained differently going forward.
- 04
Policy and procedure work
Where policies are missing or describe a process nobody follows, we write or revise them against how your organisation actually operates. A policy that does not match reality fails at audit and is worse than none.
- 05
Remediation roadmap
Gaps are sequenced by dependency and effort, not listed alphabetically. Some controls take a week; some require a quarter of operational change. Knowing which is which is what makes a certification date realistic.
- 06
Readiness check
Before you engage an auditor, we re-check the closed gaps so the audit is a confirmation rather than a discovery. SubRosa does not audit its own clients for certification — that independence is the point — so we prepare you and hand off to your auditor.
Regulatory depth, business focus.
Multi-framework expertise
Deep, hands-on knowledge across the frameworks and regulations that matter to your industry, so assessments reflect what auditors actually look for.
Risk-based prioritization
We prioritize remediation by the risk it reduces and the revenue it unblocks, so budget goes where it counts first.
Strategic, not box-ticking
We give you a roadmap to a stronger program, not just a checklist, strategic guidance to achieve and maintain compliance as standards evolve.
Cross-mapped controls, assessed once.
Sable maps your controls across SOC 2, ISO 27001, PCI DSS, HIPAA, and NIST, so a single assessment covers every framework that shares a control, and your evidence and gaps live in one workspace instead of a stack of spreadsheets.
- 4 gaps92%SOC 2 Type II
- 9 gaps85%ISO 27001
- 12 gaps78%PCI DSS
- 2 gaps96%HIPAA
Common questions
- What is a cybersecurity compliance assessment?
- A cybersecurity compliance assessment evaluates how well your security controls meet the regulations and frameworks your organization is subject to: SOC 2, ISO 27001, PCI DSS, HIPAA, NIST, and others. It compares your current posture against each framework's requirements, identifies the gaps, and produces a prioritized remediation roadmap so you can close them in the right order.
- Which compliance frameworks does SubRosa assess?
- SubRosa assesses SOC 2, ISO 27001, PCI DSS, HIPAA and HITRUST, NIST 800-53 and NIST CSF, the FTC Safeguards Rule, and more. Because controls overlap across frameworks, we cross-map them so a single assessment covers every framework that shares a control.
- What is a compliance gap analysis?
- A compliance gap analysis compares your current security controls against the requirements of a framework or regulation, documenting where you fall short. The output is a list of gaps prioritized by risk, plus a remediation roadmap that sequences the work so you close the most important gaps first.
- We need SOC 2 and ISO 27001. Is that two engagements?
- It should not be. The two overlap substantially, and organisations pursuing both routinely do the same work twice because nobody mapped the controls against each other first. We map the frameworks up front so a single piece of evidence satisfies every control it legitimately satisfies.
- Can SubRosa audit us and certify us?
- No, and that is deliberate. We prepare you and hand off to your chosen auditor. A firm that both remediates your gaps and certifies that they are closed has an obvious conflict, and a serious auditor will not accept it. We will happily recommend auditors we have worked alongside.
- What does 'partially met' mean and why does it matter?
- It is where most organisations actually sit, and it is the category a generic checklist handles worst. A control can be documented but not followed, followed but not evidenced, or evidenced in a form an auditor will reject. Each needs different work, and knowing which you have is the difference between a realistic certification date and an optimistic one.
- How long before we are audit-ready?
- It depends far more on operational change than on documentation. Writing a policy takes days; running a process consistently for the observation period an auditor requires takes months. We sequence gaps by dependency and effort so the date you commit to is one you can meet.
Know exactly where you stand.
Let's assess your compliance posture across the frameworks that matter and map the fastest path to close the gaps.