Applied IAM

Compliance readiness that holds up in the audit

Security gap analysis and framework readiness for SOC 2, HIPAA, PCI-DSS and NIST. Every gap mapped to the specific criterion it fails, remediation our delivery teams implement with you rather than hand you a list of, and the evidence pack your auditor will ask for. The certificate comes from your assessor, never from us.

SOC 2HIPAAPCI-DSSNIST CSF and 800-171ISO 27001
Evidence pack — readinessApplied IAM
FrameworksFive in scopeCertified byYour assessor
  • Privileged access review — HIPAA §164.308Ready
  • Audit log retention — SOC 2 CC7.2Ready
  • Least privilege — PCI-DSS 7.2Gap
  • MFA on admin access — NIST 800-171Gap
  • Vendor access control — HIPAA §164.308Open

We close the gaps and hand you the pack. The certificate comes from your assessor, not from us — anyone who says otherwise is selling something.

Who does what

We get you ready, someone else certifies it

This is the single most misunderstood thing about compliance, and it is worth being blunt: the firm that builds your controls cannot be the firm that audits them. Here is exactly where our work ends.

UsApplied IAM delivers readinessGap assessment against the framework you are held to, remediation we implement with you, and the evidence pack your auditor will ask for
the evidence pack
ThemAn independent licensed CPA firmPerforms the attestation and issues your report. We work alongside the auditor you choose and never sign off on our own work.
the attestation
YouYour reportHold the report, issued by the CPA firm

Any provider offering to both build and certify your controls is the first thing to walk away from. Two signatures, from two firms.

How it runs

How a readiness engagement runs

01

Scope the framework

Which standard you are actually being held to, and what falls inside its boundary. More engagements go wrong here than anywhere else, because the boundary decides everything downstream — and a boundary drawn generously in month one is a boundary you are auditing against for years.

02

Gap assessment

Every gap mapped to the specific criterion it fails, prioritized by risk rather than by the order they appear in the standard.

03

Remediate

We implement. Our delivery teams close the gaps rather than hand you a list of them, which is the difference between a consultancy and a report. Where a gap is an identity problem, and most are, the same engineers who do our IGA implementation work close it.

04

Evidence

The artifacts your auditor will request, collected across the observation window rather than assembled the week before.

By framework

Readiness by framework

SOC 2

SOC 2 readiness assessment

Type I and Type II preparation: criteria scoping, gap assessment, control implementation, and the evidence pack your auditor asks for. Type I proves the controls existed on a date. Type II proves they operated across a window, usually three to twelve months, which is why the timing of remediation matters as much as the remediation itself. Fix a control halfway through the window and you have evidence for half of it. A SOC 2 penetration test is expected inside that window too, and it needs scheduling early enough that remediation and retest both land before it closes.

HIPAA

HIPAA readiness

HIPAA requires a risk analysis, and most of what fails an OCR review is access control: who can reach ePHI, whether it is least privilege, whether it is logged, and whether you can prove any of it. We run the risk assessment, remediate the access control findings and validate encryption, with HIPAA penetration testing where the systems warrant it. See identity security for healthcare.

PCI-DSS

PCI-DSS readiness

Gap analysis and control implementation for anyone storing, processing or transmitting card data, including the segmentation and penetration testing the standard requires. Requirements 7 and 8 — access control and authentication — are where most identity work lands, and where findings recur year after year if the underlying access model never actually changed. Common across identity security for retail.

NIST

NIST alignment

Security programs mapped to NIST CSF and 800-171: the baseline for government-adjacent work, and increasingly the structure cyber insurance questionnaires are built from, whether or not anyone says so.

ISO 27001

ISO 27001 readiness

Gap analysis against Annex A controls and the management system requirements around them, for organizations whose customers have started asking.

The common core

What every framework is actually asking

Underneath the vocabulary, every framework asks the same four questions. That is why identity sits at the middle of every assessment we run, and why an identity firm is the right one to run it.

The questionWhat it means in practice
Who can access what?Across every system, not just the ones you remembered to scope
Is it controlled?Least privilege, MFA, approval before access rather than after
Is it logged?Retained, tamper-evident, and searchable by someone who is not you
Can you prove it?On the day someone asks, not a month later

Which is why the assessment covers access controls and MFA, access reviews, the joiner and leaver process, logging and monitoring, vendor risk, and the policy set. Where the answer to the fourth question is no, that is usually an IGA implementation rather than a documentation problem, and no amount of policy writing fixes it.

Frameworks
HIPAASOC 2PCI-DSSNIST
All asking
Who can access what?Across every system, not just the in-scope ones
Is it controlled?Least privilege, MFA, approval before access
Is it logged?Retained, tamper-evident, searchable
Can you prove it?On the day someone asks, not a month later

Different vocabulary, same four questions. Which is why identity sits at the middle of every assessment we run.

Deliverables

What you walk away with

Gap assessment report

Every gap mapped to the criterion it fails, prioritized by risk, so you fix what matters first rather than what appears first in the standard.

Remediation roadmap

A sequenced plan with owners against each item. This is the document that turns an audit scare into a project with a budget.

Policy library

The 15 to 25 policies frameworks expect — access control, incident response, change management — drafted for your environment rather than photocopied from a template pack. An auditor can tell.

Evidence pack

The artifacts your auditor will request, collected as the work happens rather than reconstructed afterwards.

The assessment aloneAssessment

You take the report and act on it yourself.

  • Gap assessment against the framework you're held to
  • Every gap mapped to the specific criterion it fails, prioritized by risk
  • The evidence pack structure your auditor will request
The whole journeyAssessment through audit day

Our delivery teams close the biggest gaps directly.

  • Access reviews and identity governance
  • Privileged access management and MFA enforcement
  • Monitoring and logging that generates your audit evidence continuously
  • Audit-day support
Proof

Compliance work in practice

Insurance, 20,000+ employees. Facing a SOX deadline with an outdated onboarding process and growing certification risk, our engineers deployed a unified onboarding framework and integrated 470 databases across six complex database types in six weeks, against a six-month baseline. The certification pipeline was streamlined alongside it, and the result was full compliance with SOX and audit requirements before the deadline.

FAQs

Common questions about compliance readiness

No, and nobody who builds your controls can. An independent licensed CPA firm performs the attestation and issues the report. We get you ready and work alongside the auditor you choose. Any provider offering to do both is your first red flag.

A structured comparison between what the framework requires and what you actually have, with every gap tied to the specific criterion it fails. It is not an audit and it carries no opinion. Its job is to make sure the real audit holds no surprises.

The gap assessment is usually weeks. What follows depends entirely on what it finds, and on whether you are going for Type I or Type II. Type II requires the controls to operate across an observation window, commonly three to twelve months, so the calendar is set by the window rather than by us.

We fix it. Our delivery teams implement the remediation, which is the difference between a readiness engagement and a report. Where a gap is an identity problem — and most are — the same engineers who do our PAM implementation work close it.

Usually the one a customer or regulator has asked for. SOC 2 comes from enterprise customers. HIPAA from handling health data. PCI-DSS from handling cards. NIST from government-adjacent work or an insurer. If more than one applies, the overlap is large and most of the work is shared.

Yes, and it is a common starting point. A failed audit comes with a finding list, which makes scoping faster than starting cold. The question we ask first is why the control failed, not how to make the finding go away — because a finding that gets papered over comes back next year with interest.

Find out what the auditor will find

A free consultation covers which framework you are being held to, what falls inside its boundary and where the obvious gaps are. You get the findings in writing.