NextGen Global IT ParkNextGen Global IT Park
← All services

Fixed price · Fixed scope

SOC 2 Remediation Sprint

Compliance tools are good at telling you what is wrong and no help at all in fixing it. We take your open infrastructure findings and close them — properly, with evidence attached — so your audit stops waiting on engineering.

Starts
Within a week
Scope
Fixed, in writing
Rollback plan
On every change

We closed every Drata compliance finding for a US healthcare platform as part of its SOC 2 certification, on a live system serving clinical staff.

This is for you if

  • Drata, Vanta or Secureframe is showing a wall of red and your team has no spare time
  • An auditor has given you a remediation window and a deadline
  • A deal is blocked on a SOC 2 report you have not finished
  • You passed Type I and need the controls to actually hold for Type II

What we do

What the $4,000 covers

IAM least privilege

Wildcard policies replaced with scoped ones, unused users and keys removed, MFA enforced, role assumption paths documented.

Access without SSH

Bastion hosts and open SSH ports replaced with AWS Systems Manager session access — logged, auditable, and no inbound ports at all.

Network hardening

Security groups and ACLs narrowed to what each service actually needs. Databases moved off public subnets where they are still exposed.

Encryption and key management

Encryption at rest and in transit verified across RDS, S3 and EBS; KMS keys rotated and scoped; SSL renewal automated so no certificate expires by surprise.

Logging, alarms and evidence

CloudTrail, CloudWatch alarms and log retention configured to the control's wording, with Lambda alerts where a human needs to know. Each control gets a screenshot or export the auditor can accept.

What you get

  • Findings closed in your compliance tool, each marked with what changed
  • Evidence pack: one folder per control, with screenshots, exports and config
  • Change log of every production change we made, with its rollback step
  • Runbook for the controls that need a recurring human action
  • Handover call with your team and, if you want, with your auditor

Not included

  • Policy writing, HR controls, vendor reviews and security training (your compliance tool and your auditor cover these)
  • The audit itself — we are not an audit firm and never sign off on our own work
  • Application-layer findings that need product changes, quoted separately

Anything outside this list is quoted before we start it, never invoiced afterwards.

Timeline

How it runs, start to finish

  1. Week 1, days 1–2 — triage

    We go through every open finding with you and split them: ours to fix, yours to fix, and not applicable with a written reason the auditor will accept.

  2. Week 1, days 3–5 — the safe half

    Everything that cannot affect production traffic goes first: policies, logging, alarms, retention, key rotation.

  3. Week 2, days 1–3 — the careful half

    Network and access changes, each with a written rollback plan, applied in a window you approve. Nothing touches production without that plan existing first.

  4. Week 2, days 4–5 — evidence and handover

    Evidence collected per control, the dashboard re-run, and a call to walk your team through what changed and why.

Questions we always get

What if we have more than 25 findings?

Most of what looks like 60 findings is 20 real problems repeated across resources, and the fixed price still holds. If it genuinely is more work, we tell you after triage on day 2 and quote the rest before continuing — never after.

Will this break production?

Every production change has a written rollback plan before it is applied, and the risky ones run in a window you approve. That is how we work on a healthcare platform where downtime affects patient care.

Do you work with Vanta as well as Drata?

Yes, and Secureframe. The controls underneath are the same; only the dashboard differs.

Start your SOC 2 Sprint

Book a 20-minute call. Bring your AWS account, your compliance dashboard or your database version, and we will tell you what we would do and what it costs — on the call, not in a proposal two weeks later.

See the case studies behind this work →