Conformiti
ProductEditionsPricing ConsultingSelf-hostDocs Security GitHub Book a demo

Consulting · elemosecurity

Let us handle the audit
evidence for you.

Every GRC vendor sells you somewhere to put the evidence, then leaves you to produce it. Producing it is the hard part.

We do that part. A practitioner works inside your organisation, collecting the artefacts, drafting the policies, standing up the procedures and filing every item against the right control. Readiness, implementation and audit preparation as well.

At a glance

Done-for-you audit evidencefrom $9,800 sprint · $5,900/mo
Readiness assessmentfrom $6,500 · 2-3 weeks
Implementation & rolloutfrom $18,000 · 6-10 weeks
Audit preparationfrom $12,000 · 4-6 weeks
ISMS stand-upfrom $24,000 · 8-12 weeks
Policy & procedure authoringfrom $9,500 · 3-5 weeks
Compliance packsfrom $1,200 · installed in a week
Migration from another toolfrom $7,500 · 2-4 weeks
Fractional GRC / vCISOfrom $4,800 / month
Day rate$1,850 · $245/hr

Fixed fee against a written scope, quoted after a free 45-minute scoping call.

The differentiator

Somebody has to
produce the evidence.

Your engineers should not be taking configuration screenshots at midnight, and your ops lead should not be writing a policy they have never had to defend.

We do it instead. Not a template pack and not a checklist. A practitioner, in your instance, doing the work.

We collect the evidence

From inside your organisation, with the access you grant and nothing more. We sit with the people who hold the artefacts, export what needs exporting, and file each item against the control it satisfies, with an owner and a cadence so it does not rot.

We write the staging policies

Policies written for your systems and your team, staged for your review rather than published over your name. You change what is wrong and approve. Nothing goes live that you have not signed off.

We stand the procedures up

A policy nobody follows is a finding waiting to happen. We turn each approved document into the thing it describes: owner named, cadence set, calendar entry created, and the first cycle run with the person who now owns it.

We build the meeting schedule

Steering committee quarterly, risk review semi-annually, access review each quarter, management review annually. Created as real series, dated for the next twelve months, and tracked against what the calendar demands.

We take the snapshots

The configuration screenshots auditors ask for and nobody enjoys producing: MFA, password policy, backups, logging retention, firewall rules, patch status, access lists. Captured, dated, labelled and re-taken on cadence.

You end up audit-ready

Not a folder of documents but a sealed package: a canonical manifest with a detached Ed25519 signature, populations and sampling stated per control, the PBC list answered, and a management response drafted for every likely exception.

Who does the work

The owner does it. Personally.

There is no delivery team, no offshore bench, no junior learning your environment on your budget. The person who wrote Conformiti is the person in your building, in your systems, and on the call with your assessor.

That is also why capacity is finite and engagements book out. It is a deliberate trade: fewer clients, and none of them wondering who actually touched their evidence.

What you do

  • Grant access: named accounts, least privilege, revoked on the last day, every action in your audit log with our name on it
  • Point us at people: a half-hour with each system owner, and we take it from there
  • Review and approve: you read the staged policies and say yes, no or change this
  • Show up to the audit: because the walkthrough answers have to come from your team, and by then they will have them
We do not sign anything as you. Policies are approved by your management, minutes are recorded by the people who attended, and the management assertion on a sealed package is yours. We produce and file; you own and attest. Anything else would be worthless to an auditor and dishonest to sell.

Evidence sprint

from $9,800

One framework, one push. Four to six weeks of collection, drafting, standing-up and snapshotting to get a first audit off the ground. Ends with a sealed package.

Evidence retainer

from $5,900/mo

The ongoing version. We keep the evidence current through the whole observation window: snapshots re-taken on cadence, minutes filed, reviews chased, the package rolled forward each year.

Multi-framework

quoted

SOC 2 and ISO 27001 together, or PCI on top of either. The crosswalk means one artefact often satisfies three controls: priced on the union, not the sum.

Fixed fee, written scope

You get a scope document with deliverables, dates and a number before anything starts. Change requests are priced separately and in writing. No hourly drift.

Everything lands in the tool

Findings become control statuses, risks and evidence in your instance, not a PDF that ages out. The handover is a demo of your own system, run by your own team.

We are not your auditor

We prepare you for an audit; we do not perform one, and we do not sell you an opinion on our own work. Independence matters more than the extra invoice.

Your data stays yours

We work in your instance, under your accounts, with a signed NDA and DPA. Nothing is copied to our systems. Access is revoked on the last day of the engagement, and the audit trail shows it.

Engagements

Eight ways in.

Most teams start with a readiness assessment, or hand the evidence over entirely. None of it requires a licence. Most of this work is done inside a self-hosted, free instance that you keep.

Flagship

Done-for-you audit evidence

from $9,800sprint · or $5,900/mo

The engagement most vendors leave to you. Evidence collected inside your organisation, policies written for your systems, procedures stood up with the people who run them, and the configuration snapshots captured and re-taken on cadence.

  • Evidence collected from your teams and filed against the right control
  • Staging policies and procedures drafted for your review and approval
  • Procedures stood up: owner, cadence, calendar entry, first cycle run
  • Meeting series created with a required cadence and twelve months dated
  • Configuration snapshots captured, labelled and re-taken on cadence
  • Ends with a sealed package: signed manifest, pinned evidence, recorded hashes, and the PBC list answered
The whole management system

ISMS stand-up

from $24,0008-12 weeks

Installing the software is the easy hour. A management system is a scope, a risk method somebody signed off, a policy suite that matches how you work, an internal audit programme, and a management review that actually happened. We build all of it and hand it over running.

You receive

  • A written scope: what is in the management system, what is out, and the justification an auditor will read first
  • A risk method and register: criteria, appetite, scoring, treatment plans with owners and dates, approved by your management
  • A Statement of Applicability covering every Annex A control with the applicability decision and its reason
  • The full policy suite, written to your organisation and mapped to every control it satisfies
  • An internal audit programme with the first audit performed and its findings logged
  • The first management review chaired, minuted and filed as evidence
  • Your team trained on running it after we leave, and the calendar cadence already set
Documents

Policy & procedure authoring

from $9,5003-5 weeks

Policies written for your organisation rather than downloaded and find-replaced. We interview the people who actually do the work, write what they actually do, and close the gap to the standard deliberately instead of pretending it is already closed.

You receive

  • A policy suite covering every control that requires a documented policy, in your voice and your terminology
  • Procedures and standards beneath them, so the policy is not the only document in the set
  • Each document staged as a draft for your approval: we never approve your policies for you
  • Version history, owners, review cadence and the control mappings already in place
  • An acknowledgement campaign ready to send, pinned to the exact version (needs Pro)
Most common first step

Readiness assessment

from $6,5002-3 weeks

A control-by-control gap analysis against the frameworks you intend to certify against, plus an inventory of evidence you already have and did not know counted. Ends with a remediation plan sequenced by what blocks the audit.

You receive

  • Every applicable control set to a real status, with an owner named and agreed
  • Existing policies and artefacts uploaded, versioned and mapped to the controls they satisfy
  • A risk register seeded from the gaps, scored 5×5 with treatment and due dates
  • A written report: scope decisions, control exclusions with justification, and a dated remediation plan
  • A readiness baseline snapshot so the trend line starts on day one
End to end

Implementation & rollout

from $18,0006-10 weeks

From nothing to a programme other people operate. We deploy, configure, populate and then train, and the last two weeks are deliberately spent watching your team do the work while we answer questions, rather than doing it for them.

You receive

  • Deployment on your own infrastructure, with TLS, backups, mail and (where wanted) ClamAV working
  • SSO wired to your identity provider (OIDC or SAML) with step-up MFA and a tested break-glass path
  • Roles, folder grants and the evidence tree shaped to how your organisation actually divides work
  • Control ownership and a RACI matrix agreed with each owner, not assigned in their absence
  • The vendor register loaded, assurance filed with expiry dates, and shared responsibility matrices imported
  • Review cadences, the compliance calendar and the reminder engine tuned so it is useful rather than noise
  • Two training sessions (one for administrators, one for control owners) recorded for new joiners
Before fieldwork

Audit preparation & PBC run

from $12,0004-6 weeks

Takes the scramble out of fieldwork. We assemble the package, define the populations, dry-run the walkthroughs, then sit with your team through the auditor's request list.

You receive

  • A sealed audit package scoped to the engagement, with evidence pinned, every file's SHA-256 recorded, and a detached Ed25519 signature over the manifest your assessor verifies offline with the stdlib-only verifier in the bundle
  • Population definitions and sampling methods stated per control, defensible under questioning
  • A rehearsal of every walkthrough, with the weak answers found and fixed while there is still time
  • The PBC list transcribed, assigned and dated, then run beside your team until it is empty
  • A management-response draft for each likely exception, and the risk-register entries to back it
  • A roll-forward plan so next year's package is a diff, not a rebuild
Ongoing

Fractional GRC / vCISO

from $4,800per month

A named practitioner, two to five days a month, who owns the compliance calendar so your engineering lead does not. For companies whose customers demand a security contact but whose headcount does not yet justify a full-time one.

Typically covers

  • Running the review calendar and chasing owners before things go overdue, not after
  • Vendor assurance: collecting reports, chasing bridge letters, reading matrices and filing the gaps
  • Quarterly access reviews, meeting cadences and the minutes that prove they happened
  • Fronting customer security questionnaires and prospect due-diligence calls
  • Being the named contact for the assessor between engagements
  • A monthly readiness and risk report to your board or leadership team
Move

Migration from another GRC tool

from $7,5002-4 weeks

Leaving a per-seat SaaS platform whose renewal has stopped making sense. We extract what you have, map it onto Conformiti's model, and make sure the history that matters (review dates, ownership, past evidence) survives the move.

You receive

  • Controls, statuses, owners and evidence links migrated with their mapping intact
  • Documents re-filed into the generated tree, with cadences and next-review dates preserved
  • Risk register imported from CSV or XLSX, the vendor list re-entered with assurance and expiry dates, and past access reviews filed as evidence. A completed review from your old tool is kept, not recreated.
  • A written record of what could not be extracted from the old system, and why, for your auditor
  • Parallel running for one review cycle before the old subscription is cancelled

Compliance packs

Any framework, modelled properly
and installed like a native one.

Everything beyond the three free libraries we build as a pack: categories, controls, objectives, a folder spine and a crosswalk to what you already hold, so mapped evidence counts immediately.

The full catalogue and what is already built is on the editions page. All twenty-two are $8,900 together, perpetually.

Catalogue

Built before

$4,500

Anything in the catalogue below. Installed and crosswalked in about a week, because the modelling work is already done.

Commissioned

New framework

from $9,500

A published standard we have not modelled yet. Three to five weeks, and it joins the catalogue at the lower price for everyone after you.

Bespoke

Your own control set

from $6,500

An internal control set, a regulator's schedule, or a customer's security addendum you have to evidence line by line.

Upkeep

Maintenance

$1,800/ year

First year included. After that: revisions tracked when the source standard changes, with a migration that preserves your statuses and evidence links.

Catalogue of compliance packs available to commission
FrameworkTypically forStatus
Shipped in the box: free, MIT
SOC 2: Trust Services CriteriaSaaS selling to enterpriseIncluded
ISO/IEC 27001:2022: Annex AInternational certificationIncluded
PCI DSS v4.0.1Card data environmentsIncluded
Attestation and assurance
SOC 2 Type II: operating-effectiveness overlayObservation-window evidence, sampling and population design on top of the shipped criteriaCatalogue
SOC 1: ICFR (SSAE 18)Payroll, billing and anything touching a client's financial statementsCommission
SOC 3A public-facing report derived from the SOC 2 scopeCommission
CSA STAR Level 2: CCM v4Cloud providers answering CAIQ, and the customers auditing themCommission
HITRUST CSF: e1 / i1 baselinesHealthcare vendors whose customers demand HITRUST specificallyCommission
ISO management systems
ISO/IEC 42001:2023: AI management systemsAnyone shipping AI features and being asked how they govern themCatalogue
ISO/IEC 27017:2015: cloud security controlsCloud service providers and the customers relying on themCatalogue
ISO/IEC 27018:2019: PII in public cloudsProcessors handling personal data on behalf of controllersCatalogue
ISO/IEC 27701:2019: privacy information managementExtending an ISO 27001 ISMS to cover privacyCatalogue
ISO 22301:2019: business continuityContinuity and resilience obligations in enterprise contractsCatalogue
ISO/IEC 27002:2022: implementation guidanceTeams that want the guidance modelled alongside Annex ACommission
ISO 9001:2015: quality managementManufacturing and services, usually alongside 27001Commission
Healthcare and privacy
HIPAA: Security and Breach Notification RulesUS covered entities and their business associatesCatalogue
FIPPA: Ontario provincialOntario public bodies and their service providersCatalogue
MFIPPA: Ontario municipalMunicipalities, police services boards, school boardsCatalogue
PHIPA: Ontario personal health informationHealth information custodians and their agentsCatalogue
PIPEDA: Canadian federal private sectorCommercial activity across provincial bordersCatalogue
Quebec Law 25Anyone holding personal information of Quebec residentsCatalogue
GDPR: Articles 5, 24-32 and records of processingEU/UK data subjects, wherever you are hostedCatalogue
CCPA / CPRACalifornia consumer data at threshold volumesCatalogue
Government, defence and public sector
NIST CSF 2.0A common language for boards and for supplier questionnairesCatalogue
NIST SP 800-53 Rev. 5: Low / Moderate / HighUS federal systems and anything modelled on themCatalogue
NIST SP 800-171 Rev. 2: CUIDefence supply chain holding controlled unclassified informationCatalogue
CMMC Level 2DoD contractors, assessed against 800-171Catalogue
CCCS ITSG-33 Annex 3A: PBMM profileCanadian federal departments and their suppliersCatalogue
Protected B: Canadian government handlingSuppliers processing Protected B informationCommission
FedRAMP Moderate (Rev. 5 overlay)Selling cloud services to US federal agenciesCatalogue
StateRAMP · TX-RAMPSelling cloud services to state or Texas agenciesCommission
Sector and financial
CIS Controls v8.1: IG1 / IG2 / IG3A practical hardening baseline that maps cleanly to everything elseCatalogue
SOX ITGCIT general controls for public-company financial reportingCatalogue
OSFI B-13: technology and cyber riskCanadian federally regulated financial institutionsCatalogue
NY DFS Part 500Financial services licensed in New YorkCommission
GLBA Safeguards Rule · FFIEC CATUS financial institutions and non-bank lendersCommission
NERC CIPBulk electric system operatorsCommission
TISAX / VDA ISAAutomotive supply chainCommission
Your own control set or a customer's security addendumAnything you have to evidence line by line and cannot buy off a shelfBespoke
What a compliance pack is, and is not. It is a modelled control library that installs like the built-in ones, survives upgrades, and carries a crosswalk so existing evidence counts. It is not a certification, an attestation, or legal advice about whether a statute applies to you. Buying the HIPAA pack does not make you HIPAA compliant; it gives you the register against which you can become so, and the evidence model to prove it.
On the text of the standards. Control identifiers and short titles are functional references. Objectives are brief original paraphrases written for the pack, not the normative text of the source document. Where a standard is licensed rather than public (ISO, in particular), you need your own copy, and we will say so before you buy rather than after.

What a deliverable looks like

Not a report. A running system.

The output is your own dashboard, populated. A readiness figure measured from implemented controls over applicable ones, never typed in, with an ownership-coverage figure beside it and a trend line starting the day we finish.

grc.yourcompany.com/analytics

Ownership coverage, honestly

The percentage of controls, documents and risks with a named owner is on the dashboard from day one. It is usually the most uncomfortable number in the report, and the one that most predicts whether the audit goes well.

A review load you can staff

Six months of upcoming reviews, laid out by month, so you can see the quarter where forty documents come due at once and re-cadence before it happens rather than after.

A written scope you can defend

Every control marked not applicable is set that way before fieldwork, with the reason in the scope document, filed against the control and dated in the audit trail. When the assessor asks why PCI 9.x is out of scope, the answer is one click away.

How an engagement runs

Six steps,
no surprises.

Timelines below are for a readiness assessment; longer engagements repeat steps 3 to 5.

Start with a scoping call

Scoping call: free, 45 minutes

What you sell, to whom, what they are asking for, and which framework actually gets you the contract. We will tell you if you do not need us, and we have done so.

Written scope and fixed fee

Deliverables, dates, who does what on your side, and the number. Signed before any access is granted. NDA and DPA go with it.

Access and instance setup

Named accounts in your instance with the least privilege the work needs. If you have not deployed yet, we deploy first. That is included, not billed.

Fieldwork, in the open

Interviews with control owners, evidence collection, and configuration: done in your instance where you can watch it happen. A short written update every week, no exceptions.

Readout and remediation plan

A session with the people who have to act on it, not just the sponsor. Findings are already in the tool as risks with owners and dates by the time the meeting ends.

Handover and access revocation

Your team demonstrates the system back to us. Then our accounts are deactivated, the revocation is in your audit log, and thirty days of email follow-up is included at no charge.

Rates

Published, so you can budget.

Fixed-fee engagements are quoted from a written scope. Where work genuinely cannot be scoped in advance, these are the rates it is billed at.

Consulting rates and engagement pricing
EngagementTypical durationFeeNotes
Scoping call45 minutesFreeNo obligation, no recording, no follow-up sequence.
Done-for-you evidence: sprint4-6 weeksfrom $9,800One framework. Collection, staged policies, procedures, meeting schedule, snapshots, sealed package.
Done-for-you evidence: retainerRolling, 3-month minimumfrom $5,900/moKeeps evidence current through the observation window and rolls the package forward yearly.
Readiness assessment2-3 weeksfrom $6,500One framework. Add $2,500 per additional framework in the same pass.
Implementation & rollout6-10 weeksfrom $18,000Includes deployment, SSO, training and two review cycles of support.
Audit preparation & PBC run4-6 weeksfrom $12,000Covers the package, sampling, walkthrough rehearsal and the request list.
Compliance pack: catalogue framework~1 week$4,500HIPAA, FIPPA, GDPR, ISO 42001, ISO 27017 and more. Crosswalk and year one of maintenance included.
Compliance pack: newly commissioned3-5 weeksfrom $9,500A published standard we have not modelled yet. Joins the catalogue afterwards.
Compliance pack: bespoke control set2-4 weeksfrom $6,500An internal set or a customer's security addendum. $1,800/yr maintenance after year one.
Migration from another tool2-4 weeksfrom $7,500Priced on control count and evidence volume after a free extraction review.
Fractional GRC / vCISORolling, 3-month minimumfrom $4,800/mo2 days/month. 5 days/month from $11,000. 30 days' notice either way.
Day ratePer day$1,850For advisory, workshops and work outside a fixed scope.
HourlyPer hour, 1-hour minimum$245Blocks of 20 hours at $4,400, valid 12 months.
Emergency / out of hoursAs needed1.5×Weekends, public holidays, and anything inside 48 hours' notice.

USD, excluding travel and sales tax. Remote by default. On-site available across Canada and the United States: travel billed at cost, agreed in advance.

Boundaries

What we will not sell you.

A short list, published on purpose. Every item on it is something the industry routinely sells and we think it damages the client, the audit, or both.

If any of these is what you need, we will name someone who does it properly rather than stretch to fit.

  • An audit or attestation. We prepare you; an independent assessor tests you. Doing both is a conflict that a good auditor will spot and a bad one will accept, which is worse.
  • Penetration testing or red teaming. Adjacent, genuinely different discipline. We will help you scope one and read the report with you.
  • Machine-generated policies with your logo on them. If you cannot explain a control in your own words in a walkthrough, the document is a liability, not evidence.
  • “Certification in 30 days.” A Type II observation window has a minimum length set by the standard, not by our sales target.
  • Perpetual advisory that never hands over. Every engagement has a handover step and a date. The fractional retainer is cancellable at 30 days for exactly this reason.
  • Reselling your data or your logo. We do not publish client names without written permission, and we do not ask for it as a condition of anything.

Questions

Working with us.

Do I have to buy a licence to hire you?

No. Most consulting clients self-host, and several run with no outbound access at all. The engagement does not depend on a licence.

What access do you need?

The minimum the work requires. A readiness assessment usually needs two to three weeks; an ISMS stand-up eight to twelve. We quote a fixed fee against a written scope after a free scoping call, and we will argue for less if you offer more.

Can you talk to our auditor directly?

Yes, with your permission and you on the call. We will not represent that we are your staff, or answer a control question on your behalf. The assessor needs to hear it from the owner. We help with the preparation, and with translating a request your team has not understood.

What if the assessment says we are further behind than we thought?

Then it says so in writing, before you have booked fieldwork and paid a deposit. The most common finding is not that controls are missing but that the evidence proving them was never retained, which is faster to fix than people fear.

How small is too small?

Six people chasing a first enterprise contract that requires SOC 2 is a normal client. Below that, a day of advisory and the free product is usually better value than a full assessment, and we will say so.

Do you work with regulated or public-sector clients?

Yes, including air-gapped deployments, where we work on-site or through your own remote-access path. Nothing about the engagement needs the instance to reach us.

Who actually does the work?

The named practitioner on your scope document, and nobody you have not met. There is no bench of juniors behind the pitch. That is also why the calendar is finite: engagements are typically booked three to six weeks out.

Next step

Forty-five minutes, no obligation.

Tell us what your customers are asking for and when. We will tell you what it takes, what it costs, and whether you need us at all.