Compliance as a Service
Compliance as a service is the continuous operation of your compliance program between assessments: controls kept running, evidence collected as it is produced, obligations tracked as they change, and the assessment itself supported, so compliance is a standing condition of the business rather than a project that restarts every year.
- Part of
- Knowing which obligations apply, and being able to evidence them when somebody asks.
- Engaged as
- A defined piece of work, or as part of an ongoing vCISO engagement.
- Sits under
- Executive ownership of the cybersecurity program.
The service
What this engagement is
Who it is for
- Organizations that hold a certification or attestation and have to keep it.
- Defense suppliers maintaining CMMC readiness across the year, not only before assessment.
- Healthcare and financial organizations with continuous obligations and small compliance teams.
- Companies whose customers ask for current evidence, not last year's report.
A subscription arrangement in which Heights runs the compliance program continuously: maintaining the control set, collecting evidence on the cadence each control requires, tracking obligations and their changes, and preparing and supporting each assessment as it comes.
It is built on the readiness work that establishes the program in the first place. Readiness gets the organization to its first clean assessment; this service keeps it there.
- CMMC
- NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.
- HIPAA
- The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
- SOC 2
- An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
- PCI DSS
- Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
- ISO 27001
- An international standard for an information security management system: the governance, risk treatment and continual improvement processes around security, rather than a fixed control list.
- HITRUST
- A prescriptive framework that maps to several underlying regulations and standards, with a graded certification. Requested by some healthcare payers and partners as a single piece of evidence.
The problem
Why this comes up
Most organizations reach compliance the same way twice: a scramble before the assessment, a period of relief, and a slow decay until the next one. The evidence assembled the first time is stale the second, the controls that were switched on have drifted, and the people who knew where everything was have moved on.
Meanwhile the obligations themselves change. A framework revision, a new customer requirement, a regulation reaching a sector for the first time, each arrives between assessments, when nobody is looking.
Scope
What Heights does
-
Control operation and monitoring
Each control assigned, run on its cadence, and checked so drift is caught in the month it happens.
-
Continuous evidence collection
Evidence gathered as controls operate and filed against the requirement it satisfies, so an assessment is a retrieval, not a reconstruction.
-
Obligation tracking
Framework revisions, new customer requirements and regulatory changes identified, assessed for impact and folded into the program.
-
Policy and procedure upkeep
Documents reviewed and reissued on schedule, with the approval trail an assessor expects.
-
Assessment support
Preparation, evidence delivery and handling of findings for each assessment, audit or customer review.
-
Compliance reporting
A standing view for leadership of what is in place, what is due, and what has changed since the last report.
Timing
When organizations engage this
- The last assessment was passed with effort nobody wants to repeat.
- Evidence requests from customers or auditors take weeks to answer.
- Controls that were in place at the assessment have quietly stopped operating.
- A framework has been revised and nobody has mapped the change.
- The person who owned compliance has left or is doing it alongside another job.
What you receive
- A maintained control set with named owners and operating cadence
- An evidence library kept current and mapped to each framework requirement
- A quarterly compliance report for leadership and a running obligations register
- Assessment preparation and support for each cycle covered by the service
The flagship
How this fits under vCISO leadership
Compliance is a consequence of a governed program, not a substitute for one. The vCISO decides what the program must achieve and where compliance obligations fit among the other risks; this service keeps the obligations met continuously, so the decision never has to be made in a hurry.
Sectors
Where this comes up most
- Government and Defense Contractors Contractual security requirements that determine eligibility to bid, and assessment regimes that verify them before an award rather than after an incident.
- Healthcare Statutory obligations for protected health information, clinical availability requirements that constrain how controls can be applied, and growing security scrutiny from payers and partners.
- Financial Services Several supervisory regimes at once, and several of them expecting a named individual to be accountable for the information security program.
- Technology and SaaS Companies assessed by their own customers, where security maturity shows up in the sales cycle long before it shows up in an audit.
- Insurance Organizations Licensed entities holding concentrated nonpublic personal data, state insurance data security laws with annual certification duties, and carriers auditing the agencies and administrators they appoint.
First steps
How an engagement begins
The same three steps whichever service you start with.
-
A confidential conversation
What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.
-
Scope agreed in writing
What Heights will do, what stays with you, the working rhythm, and how progress will be reported.
-
Work begins
Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.
FAQ
Questions we are asked about this
Broader questions about executive security leadership are answered on the vCISO page.
How is this different from regulatory and framework readiness?
Readiness is a project with an end: establishing which obligations apply, closing the gaps and getting through the first assessment. Compliance as a service is what follows, the continuous operation of that program so the second assessment does not start from scratch.
Organizations usually begin with readiness and move to the service once the program exists. Where a program already exists, the service can begin directly.
Can one service cover several frameworks at once?
Yes, and that is the point of running it continuously. Controls are built once and mapped to every framework they satisfy, so evidence collected for SOC 2 serves HIPAA or CMMC where the requirements overlap.
The obligations register records which framework asked for what, so a change in one is assessed against the others rather than handled in isolation.
What happens when an assessor finds a gap?
It is treated as a finding in the program: assigned, planned, remediated and evidenced, with the assessor kept informed. Findings are normal; what an assessor judges is whether the organization can respond to one.
Because evidence is collected continuously, most gaps are found by the service before an assessor does, which is the outcome the service exists to produce.
Portfolio
Related services
- Regulatory and Framework Readiness Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.
- Security Program Assessment A documented picture of what your security program actually covers, measured against a recognized framework, with the gaps ranked by business consequence.
- Managed Security Services (MSSP) Continuous monitoring, detection and response, and vulnerability management, run against priorities the security strategy has already set.