UpCISO Book a call
Compliance readiness & audit preparation

Answer once. Prove it to everyone who asks.

A customer, a contract, an insurer and a prime are asking substantially the same questions in four dialects. Almost all of it resolves to a self-assessment you have to sign. We get you ready for that one — and for an outside audit when a contract calls for one.

No customer logos on this page. Here is what we show instead →

Gap analysis · CMMC Level 2 NIST SP 800-171A
AC.L2-3.1.1
Limit system access to authorised users, processes acting on behalf of authorised users, and devices.
[a] Authorised users are identified. Met
[b] Processes acting on behalf of authorised users are identified. Met
[c] Devices authorised to connect are identified. Not met
[d] System access is limited to authorised users. Met
[e] System access is limited to authorised processes and devices. Met
Requirement: not met. One unmet objective decides it. −5 points
Illustrative. Objective text and scoring weights come from the published methodology, not from our interpretation of it.
438
Questions in the bank, grouped into focus areas
1,342
Links from an answer to the requirements it satisfies
320
SP 800-171A assessment objectives, judged one at a time
1,196
SP 800-53 Rev 5 controls imported as the crosswalk spine
How it works

Two days of your time. Then you stop starting over.

Spread over as many sittings as you like.

Scope it

Which frameworks you actually owe, and why — a contract clause, a customer, an insurer, a board. Then the systems, people and providers that touch the data in question.

Outcome: a defensible boundary

Answer once

Questions arrive in focus areas — access, devices, network, data, logging, vendors — not as one endless form. Upload your policies and the relevant paragraph comes up beside each question with an Accept button.

Outcome: one answer set, reused

Get the outputs

A gap report ordered by what buys most for least effort, the policies you are missing, the plan of action, and a report you can hand to whoever asked.

Outcome: something you can sign
Answer once

The part that compounds

One answer about how you handle privileged accounts is evidence against every framework that asks about privileged accounts.

The bank is answered once and the links do the rest. Each additional framework costs you the difference, not the whole thing again — which is the only reason a second or third obligation is affordable at all.

One answer Privileged accounts are separate from day-to-day accounts, approved by the owner, reviewed quarterly, and require phishing-resistant MFA.
AC.L2-3.1.5 least privilege AC.L2-3.1.6 non-privileged accounts AC.L2-3.1.7 privileged functions IA.L2-3.5.3 MFA AC-2(7) SP 800-53 §164.308(a)(4) HIPAA KSI-IAM FedRAMP 20x
Depth

Judged at the objective level, scored from the source

CMMC is where we have taken this furthest, because it is the framework with a published scoring method you can be held to. The same discipline applies everywhere else.

Objectives, not a yes/no per control

110 requirements decided on 320 individual assessment objectives. One unmet objective makes the whole requirement unmet, so the roll-up is a rule rather than a judgement call.

Scoring taken from the methodology

Point values, partial credit and the roll-up come from the DoD Assessment Methodology itself. The engine that applies them is tested against the regulation rather than against its own output.

A plan of action that qualifies

Where a framework restricts what may be deferred, we enforce it. Conditional status needs a score of at least 88, with specific requirements ineligible for deferral and a 180-day closeout clock. A plan that breaks those is a rejection waiting to happen.

Evidence in final form

Working papers, drafts and unapproved policies are not acceptable evidence to an assessor, so they are not acceptable here. A draft is flagged as one, every time.

What we work from

We cannot show you a customer list. We can show you exactly which published documents the analysis is built on, so you can check our work against them.

NIST SP 800-171 Rev 2110 requirements NIST SP 800-171A320 assessment objectives DoD Assessment Methodologyscoring & partial credit 32 CFR Part 170CMMC programme rule FAR 52.204-21CMMC Level 1 DFARS 252.204-7012safeguarding & SPRS 45 CFR Part 164, Subpart CHIPAA Security Rule FedRAMP 20x KSIs10 themes, 46 indicators NIST SP 800-53 Rev 5crosswalk spine
If you are a defence contractor: the CMMC Phase 2 transition was suspended on 13 July 2026 and a class deviation on 3 September made that binding — but DFARS 252.204-7012, NIST SP 800-171 Rev 2, SPRS scoring and the annual affirmation are all still in force, and Phase 1 self-assessments are still required before award. The reform changed who checks your work, not whether you owe it.
Frameworks

What we support, stated plainly

Compliance marketing lists a hundred logos and means something different by each one. There are exactly two tiers here, and the difference between them matters.

Built end to end today

Gap analysis & audit prep 5 frameworks
CMMC Level 2
NIST SP 800-171 Rev 2
All 110 requirements, worked through each of the 320 assessment objectives, with the SSP, POA&M, scoping and evidence register an assessor asks for. Scored the way the methodology defines it.
CMMC Level 1
FAR 52.204-21
The 15 basic safeguarding requirements, for the annual self-assessment and affirmation you sign. No score and no plan of action — Level 1 is met in its entirety or not at all.
NIST SP 800-171
Rev 2 · DFARS Basic Assessment
The same 110 and the same 320 objectives, getting you ready for the assessment you perform yourself and post to SPRS outside the CMMC programme.
HIPAA Security Rule
45 CFR Part 164, Subpart C
22 standards and 41 implementation specifications — 19 Required, 22 Addressable — with Addressable handled as the rule actually defines it, not treated as optional.
FedRAMP 20x
Key Security Indicators
10 KSI themes and 46 indicators, prepared as validation evidence rather than as a narrative document set.

Coverage mapping only

Not an assessment 12 frameworks

We hold the requirement identifiers and NIST's published crosswalks for these — not their own text and not their assessment methods. So we can tell you which of their controls your answers speak to, and which they do not touch. A crosswalk shows coverage, never compliance. You will never get a percentage against a framework in this tier.

ISO/IEC 27001:2022 PCI DSS 4.0.1 CIS Controls HITRUST CSF CSA CCM CRI Profile NERC CIP NIST CSF 2.0 NIST SP 800-53 NIST SP 800-82r3 NIST SP 800-171 Rev 3 DOE C2M2
Why the list is short: a framework is not a list of controls. It is controls plus an assessment method, a scoring rule, a document set and an evidence standard, and those differ completely. Shipping two hundred control lists without that machinery produces an app that tells you that you are “80% compliant” with something — a number nobody can defend and a client might repeat to an auditor. We add a framework properly when a client needs it, and say coverage until then.
Where you are right now

Three ways this usually starts

Something just landed

A contract clause, a customer questionnaire or a renewal form has named a framework and you are not sure what you actually owe or how big it is.

Start with scoping and a coverage map

You are part-way in

Policies exist, some controls are real, and nobody can say where you stand against the requirement set without a week of archaeology.

Start with the objective-level gap analysis

You already signed something

A score is posted, an affirmation is on file, or an attestation went to an insurer — and you would like it to be true before anyone checks.

Start with verification and a plan of action
No charge

Start with a coverage map

Hand us your existing policy set. We map every section to the requirements it speaks to and tell you what your documentation already covers.

Typical output: “Your documentation speaks to 61 of the 110 requirements you owe. These 19 are partial — here is the sentence that falls short. These 30 are absent, and two of them are the ones nobody is allowed to defer.”
  • Policy documents only. Nothing regulated, nothing customer-owned. Where a framework restricts what may leave your environment — CUI and FCI under CMMC, for instance — a check runs in your browser and blocks marked material before anything is transmitted.
  • Documentation coverage is not implementation. A policy saying a thing does not make it true, so nothing read out of a document is ever recorded as met without you confirming it.
  • We do not keep your file. Text is extracted and the original is discarded.
  • It is not an assessment. It is a reading of your documents against a requirement set, and it is free because the analysis is automated, not because it is a lead magnet with a pitch attached.
The line

We get you ready. We do not certify you.

This is the most important sentence on the page, and the one the industry is loosest about. Readiness work and assessment are different jobs, and the same firm should not claim both.

Ready to self-assess Most people

Most obligations are met by your own assessment and your own signature — a SPRS self-assessment and affirmation, a questionnaire returned to a customer, an attestation to an insurer. Our job is to make sure the thing you sign is true.

Ready for someone external to look

When a contract calls for an independent opinion, somebody else examines you: an authorised C3PAO for CMMC, a licensed CPA firm for SOC 2, an accredited certification body for ISO 27001, a QSA for PCI DSS. We make sure what they find matches what you told us before they open anything.

And some frameworks have no certification at all. HHS does not endorse or recognise private HIPAA certifications, so anyone selling you one is the problem. Where that is the case we will tell you plainly and prepare you for what actually happens instead.
Straight answers

What we are not going to pretend

Every other site in this category opens with a customer count and a wall of logos. We do not have those, and inventing them would be an odd way to start a relationship built on telling you the truth about your own compliance.

No customers to name Yet

So there are no logos, testimonials, review badges or case studies on this page, and there will not be any until they are real and the client has agreed to be named.

What you can judge us on instead is directly above: the published documents the analysis is built on, the depth it is worked at, and the exact line between what we do and what an assessor does.

The platform is in development In development

UpCISO is the platform we are building to deliver this work. The question bank, objective-level analysis, scoring engine, policy and SSP generation, plan-of-action tracking, coverage mapping and reporting are being built now.

The engagements we run today are delivered by us, not by you logging into software. When a module is live for self-service, this page will say so.

We sell to companies, not to MSPs

This is not a white-label product you resell. We work directly with the company that owes the obligation, which is also why there is no portfolio dashboard anywhere in the product.

The early clients get the founder

You are early, and the honest trade is that you get direct access to the person who read the regulation, in exchange for being the client whose edge cases shape the product.

Get started

Talk to someone who has read the regulation

Bring whatever prompted this — a contract clause, a customer questionnaire, a renewal form, a score you posted years ago — and whatever documentation exists. A first call is scoping, not a pitch.