Half-day review

Security Readiness Review

A half-day review of your cloud security posture against the control set you are actually being measured on, and a remediation plan ordered by what an assessor will find first.

Who this is for

Teams with SOC 2, HIPAA, PCI or a customer security questionnaire ahead of them, who would rather find the gaps first.

  • Half-day review
  • Prioritised remediation plan
  • Fixed scope, agreed before it starts

What we look at

We review the estate against the framework you are being held to, not a generic checklist. The difference matters: an auditor asks for evidence, not intent, and most failures are a control that exists but cannot be demonstrated.

  • Identity, access review and privileged account handling
  • Encryption at rest and in transit, and where the keys actually live
  • Logging, retention and whether the evidence an auditor wants is being kept
  • Network boundaries, and what is exposed that nobody intended to expose
  • Change management, and whether the pipeline can prove who approved what
  • Backup, restore and the last time a restore was genuinely tested

What you get afterwards

A remediation plan ordered by audit risk, separating what must be fixed before the assessor arrives from what can be scheduled afterwards. Each item names the control it maps to, so your compliance lead can work from the same document.

  • Gaps mapped to the specific control they fail
  • A must-fix list, dated against your audit window
  • Evidence gaps: controls you satisfy but cannot currently prove
  • What is already sufficient, so you stop paying attention to it

Finding it first is the entire point

A finding you bring to an assessor is a remediation plan. The same finding raised by the assessor is a qualification on your report, and often a customer conversation you did not want to have. The review exists to move findings from the second category into the first, while there is still time.

Common questions

Is this a penetration test?

No. It is a configuration and control review of the estate. If you need a penetration test we will say so and tell you what to look for in a firm that does them.

Do you issue the certification?

No, and be careful of anyone who says they do both. Auditors certify. We get you ready for them, which is a different job and a different firm.

How close to the audit can we book this?

The later it is, the shorter the must-fix list has to be to stay realistic. Six to eight weeks out is comfortable. Two weeks out we will tell you honestly what can and cannot be closed in time.

What does it cost?

A fixed price, confirmed by a consultant on the call once the framework and estate size are clear.

Contact

Tell us what
you are building.

A few lines is enough. We will come back with an honest view of whether we are the right people for it.

Prefer to talk? Call (888) 652-9469 or email contact@edcogroup.io, or book a call.