Frameworks we work with

  • NIST CSF 2.0 / NIST SP 800-53 Independent assessment, Current and Target Profiles, control selection, and gap analysis
  • SOC 2 (Type I & II) Readiness assessment, control design, evidence collection, and mock audit ahead of your CPA firm's examination
  • ISO/IEC 27001 ISMS design, Statement of Applicability, internal audit, and certification readiness
  • HIPAA Security Rule risk analysis, Privacy and Breach Notification Rule assessment, and policy development
  • PCI DSS Scoping, gap assessment, and remediation planning ahead of your SAQ or QSA validation
  • GDPR Privacy program assessment, records of processing, DPIA review, and Article 32 security measures
  • CCPA / CPRA Consumer-rights, notice, and cybersecurity-audit readiness under the California regulations

How engagements work

We start with a gap assessment against the specific framework you need to meet — often driven by a customer contract, cyber insurance renewal, or a regulator. The output is a prioritized remediation roadmap, not just a scorecard: what's missing, what it takes to close each gap, and in what order. From there we can help implement controls directly, or support your team and auditor through the certification or attestation process itself.

One control set, several frameworks

Most requirements overlap. A single well-documented control such as multi-factor authentication for privileged access satisfies SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CCPA, and NIST CSF requirements at once. We assess against a unified control set mapped to every framework you care about, so one round of evidence collection supports several assessments instead of seven separate checklists.

Good fit if you...

  • Have a customer, partner, or RFP requiring a specific compliance framework
  • Are pursuing SOC 2, ISO 27001, or PCI DSS validation for the first time
  • Handle protected health information and need a HIPAA risk analysis
  • Need an independent gap assessment before your formal audit begins
Plain Language

What we can sign, and what we can't.

We perform assessments and issue a signed Attestation of Assessment letter and report for every one of them. Some frameworks also have an official certification or attestation that only a specific kind of body can issue, and some have none at all. Here is where each one stands, so you know exactly what a PlainScore report means before you engage us.

SOC 2

We performReadiness assessment, gap analysis, Trust Services Criteria control mapping, evidence collection, remediation, and mock audits.

We issueAn Attestation of Assessment letter and report documenting readiness for your SOC 2 examination. It is not a SOC 2 report; those are issued only by a licensed, independent CPA firm, which PlainScore is not.

Recognized sign-offYour CPA firm's SOC 2 examination report. We prepare you for it and can help you engage the firm.

Full disclaimer →

ISO/IEC 27001

We performGap assessments, ISMS implementation, Statement of Applicability, internal and supplier audits, and certification readiness.

We issueAn Attestation of Assessment letter and report covering the gap assessment or internal audit performed, usable as internal-audit evidence for your certification body. It is not an ISO certificate; those come only from a body accredited under ISO/IEC 17021.

Recognized sign-offAn accredited certification body's certificate following its own audit.

Full disclaimer →

HIPAA

We performPrivacy, Security, and Breach Notification Rule assessments, including the Security Rule risk analysis.

We issueAn Attestation of Assessment letter and report stating whether your controls conform to the applicable rules within scope. Since no official HIPAA certification exists and HHS endorses none, this is the strongest independent evidence available. We never call anyone "HIPAA certified."

Recognized sign-offNone exists. The covered entity or business associate documents its own ongoing compliance.

Full disclaimer →

PCI DSS

We performScoping, readiness and gap assessments, and remediation planning ahead of formal validation.

We issueAn Attestation of Assessment letter and report that supports your SAQ or your QSA's Report on Compliance. It is not an AOC, ROC, or SAQ, and we do not act as a QSA, ISA, or ASV unless a signed engagement letter says so.

Recognized sign-offAn eligible SAQ with Attestation of Compliance, or a QSA's Report on Compliance, as your merchant level, acquirer, and payment brands require.

Full disclaimer →

GDPR

We performPrivacy program assessments: records of processing, DPIAs, DPO program, data-subject rights, processor arrangements, breach management, Article 32 measures, transfers, and notices.

We issueAn Attestation of Assessment letter and report documenting the accountability measures and controls examined, for your records, supervisory authority, and counterparties. It is not a legal opinion or a "GDPR certification"; none universal exists, and questions of law belong with privacy counsel.

Recognized sign-offNone in general. Compliance is the controller's or processor's legal accountability; Article 42 schemes apply only where an approved scheme exists.

Full disclaimer →

CCPA / CPRA

We performConsumer-rights, notice, and contract assessments, plus readiness for the cybersecurity audit, risk assessment, and automated decision-making regulations.

We issueAn Attestation of Assessment letter and report your business can rely on when making its own certification to the Agency. No CCPA compliance certificate exists, and unless confirmed in writing our work is readiness for the regulatory cybersecurity audit, not the audit itself.

Recognized sign-offThe business's own. For covered businesses, an executive certifies completion of a qualifying cybersecurity audit under penalty of perjury.

Full disclaimer →

NIST CSF 2.0 / SP 800-53

We performIndependent assessments across Govern, Identify, Protect, Detect, Respond, and Recover; Current and Target Profiles; SP 800-53 baseline gap analysis; evidence and remediation plans.

We issueAn Attestation of Assessment letter and report giving the profile, methodology, and results by function and subcategory. NIST certifies nothing and has said it will not create a conformity program, so this attestation is what customers and insurers typically ask for. We never call anyone "NIST certified."

Recognized sign-offNone exists. NIST does not certify implementations.

Full disclaimer →
How our Attestation of Assessment letters and reports are worded. A PlainScore conclusion reads: “Based upon the procedures performed and the evidence examined, the assessment determined that the organization's implemented controls conform to the applicable requirements identified within the scope of this assessment, subject to the findings, limitations, and exclusions contained in this report.” We never write that an organization is “fully compliant” or “certified” under a scheme we are not qualified to certify. Read the Legal Notices & Service Disclaimers for the full terms.

Find out which framework fits your business

Contact Us