Gap analysis against your framework
A written gap analysis against the framework you answer to: HIPAA, PCI-DSS (the Payment Card Industry Data Security Standard), SOC 2 (System and Organization Controls), CMMC (Cybersecurity Maturity Model Certification) readiness, or the security requirements your largest client wrote into the contract. Findings are ranked by what an assessor asks for first.