Compliance programs fail in a predictable way. The documentation is written for the assessor instead of for the people doing the work, so nobody follows it, and the evidence has to be manufactured at the end. We work in the opposite order.
Decide exactly what is in scope and defend that line. Most cost overruns trace back to a boundary that was never pinned down.
Decide how each control will be enforced before anything is written. Identity model, segmentation, data flows, system of record. A policy written ahead of the design describes a system nobody built.
Policies and procedures that describe what your organization will actually do, clause-numbered and mapped to controls.
Your team implements to the specification and we review what was delivered against it. Then governance minutes, change registers, access reviews and inventories generate their own record as a byproduct of running.
An internal assessment against the actual assessment objectives, findings raised through the real governance channel, gaps closed before anyone external looks.
A control environment that produces its own evidence, documentation your team actually follows, and a program that holds up the week after we stop working on it.
A certification timeline that requires everything to go right is not a timeline. You will get that read on the first call, before either of us has spent anything.
Purchased policy sets fail assessment for the same reason every time. They describe an organization that is not yours.
Not an advisor on the side. On her last program our principal was the only dedicated security resource, reporting to the site President, and raised a control finding on her own program through the formal governance channel. That is the standard.
If a self-assessment and three weeks of your own effort gets you there, that is the better answer and we will say so.
If your question is not here, the contact page is the fastest way to reach us.
It depends almost entirely on two things: how much CUI has spread outside a controllable boundary, and whether your identity and endpoint stack can actually enforce the controls you are claiming. A clean, contained environment moves quickly. A tenant with CUI scattered through it needs discovery and remediation before anything else is worth doing, and that is where timelines slip. If the answer is an enclave, we have built and operated inside GCC High before, so that is not new ground.
Usually yes. HIPAA, SOX ITGC, ISO 27001 and SOC 2 differ in wording and overlap heavily in substance. We crosswalk them into a single register with one owner per control, so one quarterly access review satisfies the auditor, the regulator and the questionnaire at the same time. Running them as separate programs is what makes compliance feel like four jobs instead of one.
Sometimes. The test is whether they describe your organization or a generic one. Purchased policy sets fail assessment for the same reason every time, which is that nobody follows a procedure written for somebody else. We will tell you which ones are worth keeping and rewrite the rest, rather than charging you to start from nothing.
Yes, and usually you should keep them. We have managed MSP relationships from the client side and the division of labour is straightforward. They run the infrastructure, we own the control environment and the evidence. Problems appear when nobody has told the MSP which controls they are responsible for producing evidence for.
Fixed-scope work is quoted after a scoping call, against a written scope and a date. Retained fractional CISO work is a monthly fee tied to an agreed cadence. We do not quote before we understand the boundary, because a number given before that is a guess.
The first call is more useful if you lead with what is broken rather than what is finished.
© 2026 CARMhaus Consulting LLC. All rights reserved. Cybersecurity · Assurance · Risk Management
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.