Compliance is an opinion you can defend.
Regulated products need more than a feature that behaves correctly. They need evidence, and evidence has to be produced deliberately.
The problem
If you operate in health services or payments, a working product is the easy half. The other half is being able to show a regulator, an auditor, or an enterprise security reviewer why your handling of their data is defensible.
That work is different in kind from feature delivery, which is why it is priced differently. Governance, risk and compliance work is never story-point priced. A point measures functional scope. A policy set, a risk register or a Statement of Applicability has none, so a point-based price for advisory work has no unit behind it.
One boundary matters more than any capability claim. Koombea does not issue certificates and neither does any development partner. An ISO/IEC 27001 certificate comes from an accredited certification body. A SOC 2 report comes from a licensed CPA firm. A PCI DSS Report on Compliance comes from a Qualified Security Assessor. You engage that party. We do the gap analysis, build the controls, produce the evidence, and get you ready for the room.
On completion of a build we provide a written attestation covering the agreed security checks and any known critical or high-severity findings identified within that scope. That is a statement we are willing to put in writing, which is the only kind worth having.
- Security leadership on demand, without a full-time hire
- A management system built against ISO/IEC 27001:2022, not a folder of documents
- A prioritized risk treatment plan, not a maturity score
- Vendor risk caught before it becomes yours
- Penetration testing you authorize in writing first
- Gap analysis, audit readiness, and accompaniment through certification
Nine services, three pillars
Governance sets the direction. Risk management finds what can hurt you. Compliance and audit readiness gets you into the audit prepared. These are the service names, and each one is a defined engagement with a defined deliverable.
Virtual CISO (vCISO)
A named security lead for risk decisions, executive reporting, and the control program, without a full-time hire.
Policies and Procedures Development
We write your security documentation and keep it current. It fits how your organization actually works.
ISMS Design and Implementation
We build and deploy an information security management system against ISO/IEC 27001:2022.
Risk Assessment and Treatment
We analyze your posture, name the risks, and order the treatment plan by what matters most.
Third-Party Risk Management
We evaluate and monitor your vendors. You do not inherit their vulnerabilities.
Offensive Security Services
Network penetration testing and vulnerability management. Findings you can act on, not a scanner dump.
Gap Analysis
We measure your environment against the requirement, control by control, and map the path to compliance.
Audit Readiness
Technical and documentary preparation. The audit is not the first time you answer the question.
Certification Support
We prepare the evidence, answer technical findings, and stay with your team through the assessor's review.
Which framework, precisely
A framework claim is the sentence your legal team reads literally. So here is what each one is, where it stands today, and which part of it is ours.
| Dimension | What it is | Where it stands | What we do |
|---|---|---|---|
| ISO/IEC 27001:2022 | An auditable information security management system. An accredited body certifies it after a Stage 1 and a Stage 2 audit. | The 2022 edition restructured Annex A to 93 controls in four themes. The transition period closed on 31 October 2025, so 2013 certificates no longer hold. | ISMS design and implementation, gap analysis, evidence, and accompaniment through both audit stages. |
| SOC 2 | An AICPA framework against the Trust Services Criteria. A licensed CPA firm issues the report. | Type I covers control design at a point in time. Type II covers operating effectiveness over a period. SOC 2 with no type stated is not a scope. | Readiness for the type you are targeting, then support through the Type II observation period. |
| PCI DSS v4.0.1 | The card brands' security standard. A Report on Compliance needs a Qualified Security Assessor. A Self-Assessment Questionnaire you complete and attest yourself. | The January 2025 SAQ A revision dropped three requirements and replaced them with a site-wide script susceptibility criterion, effective 31 March 2025. A full redirect avoids it. An iframe does not. | Scope reduction first, SAQ eligibility determined honestly, then the controls the remaining scope actually requires. |
| HIPAA | A US federal regulation covering the Privacy Rule, the Security Rule and the Breach Notification Rule. The HHS Office for Civil Rights enforces it. | No certification scheme exists. Anyone selling you HIPAA certification is selling something that is not real. Business associates and their subcontractors sit directly in scope. | Security Rule gap analysis, readiness assessment, business associate obligations, and the evidence behind them. |
How a framework gets satisfied
Step 01
Scope reduction
The first move is always making the regulated footprint smaller. The cheapest compliance work is the work you engineer your way out of needing, and it is the step most partners skip because it shrinks the engagement.
Step 02
Gap analysis
Measure the current state against the specific framework, control by control, and produce a list a person can act on rather than a maturity score. Start here. Leading with certification support is buying the end of the process first.
Step 03
Control implementation
The engineering work: access control, encryption, logging, audit trails, retention and data residency. This part is a build and is priced in points like any other build.
Step 04
Evidence production
Documentation produced while the work happens, not reconstructed afterwards. Reconstructed evidence is how audits go badly.
Step 05
Audit readiness
A dry run against the questions your assessor will ask, so the first time you answer them is not in front of the assessor.
Step 06
The audit itself
Run by the independent third party you appoint. We support it and respond to findings. We do not issue the certificate and neither does any development partner.
How this is priced
Governance work is never story-point priced, because the deliverable is an assessment and an evidence trail rather than a shipped feature. It prices on four bases instead, and the engagement decides which one applies.
The control implementation that comes out of an assessment is a build. An AI Pod delivers that part, pointed like any other build.
When a compliance engagement and a build run together, they are two lines on two bases. We state them separately. Folding advisory work into a build total would quietly convert an opinion into a fixed-bid commitment.
- A monthly retainer for vCISO, ongoing third-party monitoring, and ISMS maintenance
- A fixed fee for a defined assessment: gap analysis, risk assessment, an initial vendor evaluation
- A scoped engagement for penetration testing, priced by target count, scope, test depth, and whether retesting is included
- A phase or milestone price for ISMS implementation, audit readiness and certification support, tied to audit stages rather than to a delivery calendar
What drives the number
What moves the number is how much regulated data you touch and how much of it you could stop touching. Almost everything else follows from that.
- How much regulated data is genuinely in scope after reduction, which is often far less than at the start
- Which framework, and which flavour of it, since SOC 2 Type I and Type II are different engagements on different timelines
- Your current state: nothing in place, policies but no management system, previously certified and lapsed, or mid-audit
- Whether evidence exists already, or starts from nothing
- Number of systems and third parties inside the compliance boundary, each of which needs its own diligence
- Whether you have appointed an assessor already, and what they have told you
- Whether the deadline is yours, or a customer contract, procurement gate, regulator or investor set it
If we are already building it
Every regulated build triggers a compliance conversation.
The build creates the trigger and this capability answers it, without anyone having to learn your architecture a second time. Sequencing that works: gap analysis first, because it is small, fixed fee, and produces a roadmap you can defend.
- A health platform handling protected health information: Security Rule gap analysis, business associate scoping, policies and procedures
- Payments, or anything touching cardholder data: PCI DSS scope reduction, SAQ eligibility, penetration testing
- B2B software selling into US enterprise procurement: SOC 2 Type II readiness, then support through the observation period
- An international or public sector sales motion: an ISMS against ISO/IEC 27001:2022, then certification support
- Any platform with a real vendor footprint: a third-party risk program, designed and then monitored
- After launch, any of the above: a vCISO retainer instead of the full-time hire you were about to make
Accessibility is a separate line
WCAG verification sits outside the compliance frameworks above, and we keep it separate on purpose. We deliver it as compliance QA against a stated conformance level, and you get findings you can act on.
A general accessibility claim is worth nothing to the buyer who asks for it. A verified level, with the exceptions named, is worth something.
Governing the AI in the delivery
Every engagement now runs on AI-First delivery, and that raises questions procurement asks before a contract is signed. These are our answers, and they are written down rather than improvised per deal.
Not every client wants AI used on their project, and that is a legitimate position. When a client has not agreed to it, the agreement governs, and the configuration that would make an agent useful stays out of the repository you can see.
- An AI usage policy that states which client data may enter a prompt and which may not
- Disclosure and consent recorded per engagement, not assumed from a master agreement
- Data classification that names what counts as personal, confidential, or restricted before anyone has to judge it live
- Tool vetting per vendor, including model training opt-out status and data retention terms
- A distinct identity per agent, scoped to the systems it needs, with no shared credentials across agents or clients
- An audit trail of agent actions, plus the named boundaries where an agent stops and a person decides
Questions worth asking
Does our data get used to train a model?
We have not agreed to AI being used on our project. What changes?
Which agent did what?
Can you make us HIPAA compliant?
Do you issue the certificate?
Is Koombea itself certified?
What does a vCISO actually do?
Which SOC report do we need?
Which frameworks can you actually evidence?
Where does our data live, and will you sign a BAA?
Why is this not priced in story points?
Is penetration testing included in our build?
When should we start?
Compliance work in production systems
Fashioned Health was built on HIPAA-ready infrastructure with PCI-compliant payment handling through Stripe. Koombea's development unit is appraised at CMMI-DEV/3.
Our compliance work has been delivered in finance, where the scope is transactions and cardholder data, in healthcare, where it is the privacy and security of patient information, and in technology, where it is infrastructure, intellectual property and operations. Those engagements sit under confidentiality, so we will walk you through them in the Priority Sync rather than name them on a page.
Bring us the backlog.
In 30 minutes, we will show you what a Pod would ship first and how we would price it.