CMMC 1.0 vs 2.0: What Changed and How It Affects You
The consolidation from five levels to three did more than simplify the model: it moved real assessment burden onto contractors.
Read articleAccredited audit, assessment and advisory
NexaVault maps SOC 2, ISO 27001, PCI DSS, HIPAA and fourteen more frameworks onto a single set of controls, so you gather evidence once and certify everywhere. Licensed CPA firm, PCI Qualified Security Assessor and authorised HITRUST assessor, all under one roof.
Why we exist
Every enterprise deal now arrives with a security questionnaire attached. Miss the certificate and the deal stalls, so compliance quietly becomes a revenue problem rather than a paperwork one.
The usual answer is to run each framework as its own project, with its own auditor and its own evidence trail. You pay for the same work several times and your engineers get pulled off the roadmap every quarter.
We built NexaVault to end that. One mapped control set, one senior team, and the accreditations to both close your gaps and issue the report at the end of it.
How we workOur services
Whether a customer contract forced the deadline or you decided to get ahead of it, the work breaks down the same way. No part of it gets handed off to someone else.
We scope, assess and issue. Because we hold the CPA licence, the QSA accreditation and the HITRUST authorisation ourselves, the report at the end comes from the same team that walked you in.
We do not hand over a spreadsheet of findings and invoice you. Our consultants sit with your engineers to write the policy, configure the control and collect the proof.
We shape your environment so that evidence collects itself: logging that answers the question an assessor will ask, access reviews that run on a schedule, infrastructure that starts compliant.
Certificates expire and scope drifts. We monitor controls through the year so your next surveillance audit is a formality rather than a fire drill.
Discover our solution
Compliance programmes fail on duplicated effort, not on missing controls. Here is how we collapse four audits into one operating model.
We treat every framework as a set of controls your business already needs. Instead of writing policy to satisfy an auditor, we implement controls that hold up when something actually goes wrong, and the certificate follows.
Scanners produce thousands of results. Our assessors filter the noise, manually validate exploitability against your environment, and hand your engineers a queue that is short enough to clear before the audit window closes.
Monitor real attacker activity targeting your environment, with no generic feeds. Only insights tied to your users, systems and domains, mapped straight back to the control that would have stopped it.
No procurement friction. No discovery marathon. A scoping call, a fixed-fee proposal, and a start date you can plan around.
Book a scoping callFrameworks multiply faster than budgets. SOC 2, ISO 27001, HIPAA and PCI DSS all want evidence of the same underlying controls, collected in four different formats.
Most teams answer this by running four separate projects, four separate auditors and four separate evidence trails, and paying for the same work four times over.
We start with a single control set mapped across every framework in your scope, so one piece of evidence satisfies every requirement that asks for it.
Gaps get remediated once. Documentation gets written once. Your engineers get interrupted once, not once per quarter per framework.
Because we are a licensed CPA firm, a QSA company and an authorized HITRUST assessor, the team that closed the gaps can also issue the report.
The result: fewer audit cycles, a shorter path to the certificate your buyer is asking for, and a security programme that keeps working after the report is signed.
Testimonials
Frameworks we cover
Pick the certificate your buyers keep asking for. Every one below draws on the same mapped control set, so the second is far cheaper than the first.

The report North American buyers ask for by name. We run readiness, close the gaps and issue the Type 1 or Type 2 opinion ourselves as a licensed CPA firm.
Learn more
An ISMS your team can actually operate, scoped to your real risk rather than a template, and defensible in front of any certification body.
Learn more
A Qualified Security Assessor Company that shrinks your cardholder data environment first, so you are assessed on what genuinely matters.
Learn more
The Security Rule risk analysis OCR expects, the safeguards to back it, and an independent attestation your healthcare partners will accept.
Learn more
An Authorized External Assessor Organization taking you through e1, i1 or r2, from MyCSF scoping to quality assurance and certification.
Learn more
A Registered Practitioner Organization preparing defense contractors for Level 1 self assessment or a Level 2 C3PAO assessment that holds up.
Learn more
All 110 controls assessed honestly against Revision 3, with the SSP, POA&M and SPRS score a DIBCAC assessor will actually accept.
Learn more
Current and target profiles across all six functions of CSF 2.0, scored and costed into a roadmap your board can approve and fund.
Learn more
The authorization path chosen for your size, the full SSP package built once, and continuous monitoring that does not become a second job.
Learn moreScope determination, Article 21 gap closure and a 24 hour incident notification workflow rehearsed before you ever need it.
Learn more
Quality management implemented alongside ISO 27001 as one integrated system, so you run a single set of audits instead of two.
Learn more
Records of processing that stand up to scrutiny, DPIAs where they genuinely apply, and a DSAR process that meets the one month clock.
Learn more
Notices, opt outs and vendor contracts brought to a state that survives a CPPA inquiry, including Global Privacy Control handling.
Learn moreScroll the row or use the arrows. Hovering pauses it. Every framework links through to how we run that engagement.
Our approach
Four stages, fixed fee, dates you can plan a quarter around. You will know at every point what we need from you and what we are doing next.
We work out what is genuinely in scope, then map every framework you need onto one control set so nothing gets assessed twice.
Our consultants write the policies, configure the controls and collect the evidence with your team rather than handing you a findings list.
Controls have to operate over time. We monitor them through the observation window and fix drift before it becomes a finding.
We perform the audit and issue the report, then keep you ready so the next cycle costs a fraction of the first.
Technical services
Most frameworks require evidence that someone competent actually tried to break in, or that you could recover if they succeeded. These are the engagements that produce it.
Manually validated findings with a reproduction path your engineers can follow, not a scanner export with a logo on the cover.
Learn moreRisk quantified by what a control failure would actually cost you, so budget goes to the largest exposure rather than the loudest one.
Learn moreScanning is easy and triage is the work. We tune out the noise and hand back a queue short enough for your team to clear.
Learn moreImpact analysis, defensible recovery targets, and a plan rehearsed until it survives contact with a real outage.
Learn moreAWS, Azure and GCP reviewed against CIS benchmarks, with the identity model that caused the drift fixed rather than just flagged.
Learn moreTell us who is asking and why, and we will tell you what you actually need. If the answer is nothing yet, we will say so.
Talk to an expertWhy us
Compliance firms mostly sell the same scope. The differences show up in who does the work, who signs the report, and what happens when a finding appears late.
Your controls are mapped across every standard in scope from day one, so a single piece of evidence answers SOC 2, ISO 27001 and HIPAA at once.
CPA licence, PCI QSA accreditation and HITRUST authorisation in house. Most firms have to hand you to a third party to finish the job.
Closing gaps is part of the engagement, not a change order. We configure, document and test alongside your engineers.
You know who is leading your engagement before you sign, and they stay on it. No handover to a junior team after kickoff.
A scoping call and a proposal you can plan a quarter around. We staff ahead so a start date means a start date.
We wire your tooling so proof accumulates automatically through the year, which is what makes the second audit cheap.
“NexaVault exists because compliance had become something done to companies rather than for them. We built a practice that closes the gaps and signs the report, so our clients get a security programme that still works the day after the certificate arrives.”
About us
A focused in-house team of certified consultants rather than a subcontractor network. Headquartered in California, working with clients across the US, Canada, Europe and APAC.
Read moreframeworks and standards covered by one mapped control set
accreditations held in house, so we assess and issue
minutes from scoping call to a fixed fee proposal
senior consultant named on your engagement, start to finish
Expertise
Start with whatever is blocking revenue. If deals stall on a security questionnaire from a North American buyer, that is usually SOC 2. European and APAC procurement more often asks for ISO 27001. We will tell you on the scoping call, and we will say so if you do not need one yet.
For SOC 2 Type 1 or ISO 27001, most teams are audit ready in eight to twelve weeks, then a Type 2 needs an observation window on top. The variable is not us, it is how much control work you already have in place.
No, and that is the point. We hold the CPA licence, the PCI QSA accreditation and the HITRUST authorisation, so the team that closed your gaps can also issue the report.
Far less than the first one. Because your controls are already mapped across frameworks, most of the evidence is reusable and the second certification is largely a scoping and gap exercise.
Every audit is preceded by a gap assessment and hands on remediation, so a surprise failure is rare. If a finding does appear, closing it is part of the engagement rather than a new invoice.
To a point. We offer virtual CISO and team augmentation for programme ownership, but we will be straight with you when what you actually need is a full time hire.
Probably not. Seed stage companies certify all the time, usually because one large customer asked. The work scales with your footprint, so a small environment means a smaller engagement.
Insight
The consolidation from five levels to three did more than simplify the model: it moved real assessment burden onto contractors.
Read articleA practical breakdown of the control count at Level 1, 2 and 3, and which ones consistently trip up first-time assessments.
Read articleThey share 110 controls, but the assessment mechanics, evidence bar and consequences of failure are not the same thing.
Read articleThirty minutes to work out what is in scope, what it will cost and when it can start. No obligation and no pressure.
Talk to an expert