Assess

Readiness and gap assessments

Know exactly how far you are from a SOC 2 report, ISO 27001 certificate or CPCSC level, which gaps an auditor would care about, and a realistic date.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP, more than twenty years in enterprise security. Leads every engagement.

Connect on LinkedIn

Frameworks we assess against

One method, applied to the framework you are being measured on. Per-framework detail pages are being added.

icon-6

SOC 2 Type I and Type II

Trust Services Criteria in scope, system boundary, observation period options, and what a first report should include.

icon-5

ISO 27001

Clauses 4 to 10 and the Annex A controls, statement of applicability, and internal audit readiness.

icon-7

ISO 42001

AI management system scope, AI risk and impact assessment, and how it extends an existing ISO 27001 management system.

icon-2

CPCSC and CMMC

Defence contract requirements at the level your contract names, and the evidence a certification body expects.

icon-9

HIPAA and HITRUST

Safeguards against the rule and the HITRUST control set at the e1, i1 or r2 level.

icon-4

Multi-framework

Where a second framework is on the roadmap, the gap analysis maps the overlap so the second one is mostly mapping.

Assess, Build, Operate, applied to one framework

Scope is set before the engagement starts. A documented methodology, led by a senior architect with more than ten years of enterprise security experience and a CISSP.

01

Assess

Which framework, which systems, which people. The boundary as the framework defines it rather than the one the platform suggested.

02

Build

Policies, controls and evidence reviewed as an auditor would sample them. Platform status compared against what is really in place.

03

Operate

Gaps rated by audit consequence, a sequenced plan with owners and effort, and a recommendation on auditor, timing and observation period.

What you hold at the end

A plan you can hand to your team, to Truvo, or to any third party, and a realistic date.

  • Scope and system boundary statement

  • Gap analysis against the framework

  • Evidence review against what an auditor samples

  • Gaps rated by audit consequence

  • Sequenced plan with owners and effort

  • Auditor, timing and observation period recommendation

What the assessment settles

The four questions behind every readiness conversation.

When a readiness assessment is the right call, and when it is not

If you already know the gaps and need them closed, skip the assessment and talk to us about managed compliance.

Frequently asked questions

In practice they are the same engagement. A gap assessment measures the distance between what you have and what the framework requires. A readiness assessment adds the judgement about whether you can pass an audit on a given date, and what has to be true first. Truvo delivers both in one report.

The platform tests what it can connect to and reports on the controls it knows about. It does not know whether a policy is followed, whether an evidence screenshot shows the right thing, or whether the boundary you drew is the one an auditor will accept. In our experience the platform score and the audit outcome can differ substantially in either direction, and the assessment tells you which.

SOC 2 Type I and Type II, ISO 27001, ISO 42001, ISO 27701, CMMC, CPCSC, HIPAA, HITRUST, PIPEDA, Quebec Law 25 and GDPR. Where you are pursuing two, the assessment maps the overlap so the second is mostly mapping rather than new work.

No. Truvo prepares your environment, manages the auditor relationship through fieldwork and remediates findings. The audit report is issued by an independent auditor, because the independence boundary matters.

It follows the size of the estate and how much documentation exists, and the timeline is set before the engagement starts. The report includes a recommendation on audit timing and, for SOC 2 Type II, on the observation period.

The plan is written so it can be handed to your internal team, to Truvo, or to a third party. Companies that want the gaps closed and the program operated typically continue into managed compliance or a fractional security team engagement.

Talk to the architect who would do the work

A 30-minute call. We look at your environment and say plainly whether we can help and what it would take.

From the blog: readiness and audits

SOC 2 CC7.5: Recovering From Identified Security Incidents

SOC 2 CC7.5 requires a company to identify, develop, and implement the activities that recover the environment after a security incident, and to ...

SOC 2 CC7.4: Responding to Security Incidents

SOC 2 CC7.4 requires a company to respond to security incidents through a defined incident-response program that understands, contains, remediates, ...

SOC 2 CC7.3: Evaluating Security Events to Identify Incidents

SOC 2 CC7.3 requires a company to evaluate detected security events, decide which of them are incidents, and act on the ones that are. It sits in the ...