Heights Consulting Group

Compliance as a Service

Compliance as a service is the continuous operation of your compliance program between assessments: controls kept running, evidence collected as it is produced, obligations tracked as they change, and the assessment itself supported, so compliance is a standing condition of the business rather than a project that restarts every year.

What you receive

Part of
Knowing which obligations apply, and being able to evidence them when somebody asks.
Engaged as
A defined piece of work, or as part of an ongoing vCISO engagement.
Sits under
Executive ownership of the cybersecurity program.

The service

What this engagement is

Who it is for

  • Organizations that hold a certification or attestation and have to keep it.
  • Defense suppliers maintaining CMMC readiness across the year, not only before assessment.
  • Healthcare and financial organizations with continuous obligations and small compliance teams.
  • Companies whose customers ask for current evidence, not last year's report.

A subscription arrangement in which Heights runs the compliance program continuously: maintaining the control set, collecting evidence on the cadence each control requires, tracking obligations and their changes, and preparing and supporting each assessment as it comes.

It is built on the readiness work that establishes the program in the first place. Readiness gets the organization to its first clean assessment; this service keeps it there.

Alignment

Frameworks this work touches

Establishing which of these apply to you

CMMC
NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
PCI DSS
Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
ISO 27001
An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
HITRUST
A prescriptive framework that maps to several underlying regulations and standards, with a graded certification. Requested by some healthcare payers and partners as a single piece of evidence.

The problem

Why this comes up

Most organizations reach compliance the same way twice: a scramble before the assessment, a period of relief, and a slow decay until the next one. The evidence assembled the first time is stale the second, the controls that were switched on have drifted, and the people who knew where everything was have moved on.

Meanwhile the obligations themselves change. A framework revision, a new customer requirement, a regulation reaching a sector for the first time, each arrives between assessments, when nobody is looking.

Scope

What Heights does

  • Control operation and monitoring

    Each control assigned, run on its cadence, and checked so drift is caught in the month it happens.

  • Continuous evidence collection

    Evidence gathered as controls operate and filed against the requirement it satisfies, so an assessment is a retrieval, not a reconstruction.

  • Obligation tracking

    Framework revisions, new customer requirements and regulatory changes identified, assessed for impact and folded into the program.

  • Policy and procedure upkeep

    Documents reviewed and reissued on schedule, with the approval trail an assessor expects.

  • Assessment support

    Preparation, evidence delivery and handling of findings for each assessment, audit or customer review.

  • Compliance reporting

    A standing view for leadership of what is in place, what is due, and what has changed since the last report.

Timing

When organizations engage this

  • The last assessment was passed with effort nobody wants to repeat.
  • Evidence requests from customers or auditors take weeks to answer.
  • Controls that were in place at the assessment have quietly stopped operating.
  • A framework has been revised and nobody has mapped the change.
  • The person who owned compliance has left or is doing it alongside another job.

What you receive

  • A maintained control set with named owners and operating cadence
  • An evidence library kept current and mapped to each framework requirement
  • A quarterly compliance report for leadership and a running obligations register
  • Assessment preparation and support for each cycle covered by the service

The flagship

Compliance is a consequence of a governed program, not a substitute for one. The vCISO decides what the program must achieve and where compliance obligations fit among the other risks; this service keeps the obligations met continuously, so the decision never has to be made in a hurry.

Read about vCISO leadership

First steps

How an engagement begins

The same three steps whichever service you start with.

  1. A confidential conversation

    What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.

  2. Scope agreed in writing

    What Heights will do, what stays with you, the working rhythm, and how progress will be reported.

  3. Work begins

    Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.

FAQ

Questions we are asked about this

Broader questions about executive security leadership are answered on the vCISO page.

How is this different from regulatory and framework readiness?

Readiness is a project with an end: establishing which obligations apply, closing the gaps and getting through the first assessment. Compliance as a service is what follows, the continuous operation of that program so the second assessment does not start from scratch.

Organizations usually begin with readiness and move to the service once the program exists. Where a program already exists, the service can begin directly.

Can one service cover several frameworks at once?

Yes, and that is the point of running it continuously. Controls are built once and mapped to every framework they satisfy, so evidence collected for SOC 2 serves HIPAA or CMMC where the requirements overlap.

The obligations register records which framework asked for what, so a change in one is assessed against the others rather than handled in isolation.

What happens when an assessor finds a gap?

It is treated as a finding in the program: assigned, planned, remediated and evidenced, with the assessor kept informed. Findings are normal; what an assessor judges is whether the organization can respond to one.

Because evidence is collected continuously, most gaps are found by the service before an assessor does, which is the outcome the service exists to produce.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.

Sign in to the employee portal

For Heights employees. Accounts are created by Heights; if you expected one and it has not arrived, contact us.