Contact Us
Home/Blog

Blog

Field notes on getting certified

Notes from live engagements: how frameworks compare in practice, where assessments actually go wrong, and what a defensible answer looks like.

CMMC

CMMC 1.0 vs 2.0: What Changed and How It Affects You

The consolidation from five levels to three did more than simplify the model: it moved real assessment burden onto contractors.

Read article
CMMC

CMMC Controls List: How Many Controls by Level?

A practical breakdown of the control count at Level 1, 2 and 3, and which ones consistently trip up first-time assessments.

Read article
SOC 2

CMMC vs NIST 800-171: What’s the Difference

They share 110 controls, but the assessment mechanics, evidence bar and consequences of failure are not the same thing.

Read article
ISO 27001

SOC 2 vs ISO 27001: Which One Does Your Buyer Actually Want?

North American buyers ask for SOC 2. European and APAC buyers ask for ISO 27001. Here is how to decide when both are on the table.

Read article
PCI DSS

PCI DSS v4.0.1 and the Targeted Risk Analysis

The customised approach is the biggest change in v4, and the most commonly misunderstood. What a defensible TRA looks like.

Read article
HIPAA

Five Common HIPAA Security Rule Deficiencies

From missing risk analyses to unencrypted backups, the findings OCR keeps citing, and what an adequate control looks like.

Read article

Start with a scoping call

Thirty minutes to work out what is in scope, what it will cost and when it can start. No obligation and no pressure.

Talk to an expert