Services Compliance
Service · 06 of 06

Compliance that's proportional to the actual risk.

Gap assessments, evidence packs, and controls implementation for HIPAA, SOC 2, and cyber-insurance — built on the CIS v8 baseline you're probably already running.

◆ At a glance
CIS v8
The baseline under every compliance engagement
Add-on or standalone Evidence pack included
◆ The approach

We close the gaps. You handle the audit.

Most SMBs fail compliance reviews not because their controls are bad but because nobody documented them. We map your existing controls to the required framework, close the obvious gaps, and produce an evidence pack the auditor can actually use.

  • Gap assessment against HIPAA, SOC 2, or CIS v8
  • Controls implementation — not just a checklist
  • Evidence pack formatted for auditor intake
  • Cyber-insurance questionnaire support
◆ What's included

6 capabilities. One SLA.

INCLUDED

Gap Assessment

We audit your current controls against the target framework and score the gaps.

INCLUDED

HIPAA Alignment

Policies, access controls, and BAAs — mapped and documented.

INCLUDED

SOC 2 Readiness

Control selection, evidence collection, and auditor-ready artifacts.

INCLUDED

Cyber-Insurance Pack

Questionnaire support plus the evidence pack most underwriters request.

INCLUDED

CIS v8 Baseline

The 18 controls mapped to your environment with remediation priority order.

INCLUDED

Ongoing Monitoring

Quarterly reviews to keep controls current and evidence fresh.

CIS v8
Baseline under every engagement
60d
Typical readiness timeline
1 pack
Auditor-ready evidence deliverable
0
Surprise audit findings for prepared clients
◆ Questions we hear

The ones owners ask before signing.

If yours isn't here, ask on the discovery call — we'll give a real answer.

Do we need a dedicated compliance consultant?

Not for most SMB frameworks. We handle the technical controls and evidence; for formal certification you'll want a specialist auditor alongside us.

How long does a SOC 2 readiness engagement take?

About 60 days to get to a defensible posture. The observation period and formal audit come after — that timeline is set by the auditor, not us.

Is this included in managed services?

Gap assessment and evidence pack are available as add-ons. Managed clients get the CIS v8 baseline as part of Standard and Premier tiers.

What if we already have some controls in place?

Good — we start with what you have. The gap assessment scores what's in place, what's partial, and what's missing. Most clients are further along than they think.

◆ Ready when you are

See if Compliance from PHT fits your business.

30 minutes with the founder. We'll look at your environment, your support load, and tell you honestly whether this service is the right fit — even if the answer is "not yet."