First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Compliance Evidence and Audit Readiness Retainer
Managed ServicesCompliance

Compliance Evidence and Audit Readiness Retainer

Compliance Evidence and Audit Readiness Retainer is monthly compliance operations for one agreed framework — the HIPAA Security Rule, CMMC and NIST SP 800-171, SOC 2, CIS Controls v8.1, or your cyber-insurance carrier's control requirements — run on the Microsoft 365 and Azure controls you already own. Every month IT Partner refreshes the evidence behind each control from Entra ID, Purview, Defender, Intune, and Azure; checks the tenant for drift against the baseline your readiness assessment left; works the policy review calendar; drafts answers to security questionnaires within a defined monthly allowance; and keeps an audit binder in your own SharePoint that is ready on any day, not just audit week. It costs a flat $950 per month per tenant with no long-term contract; additional frameworks are quoted. We are Microsoft 365 engineers, not auditors: this retainer produces the evidence, and the auditor, assessor, or carrier reaches their own conclusion.

Timeline 30 daysService owner Dan ApplebyMicrosoft 365Microsoft PurviewMicrosoft Entra ID

What this engagement is

The dangerous part of compliance is not the assessment; it is the eleven months after it. A readiness assessment closes with a gap report, a roadmap, and a tenant that — for one week — matches the documentation. Then a Conditional Access policy gets switched to report-only during a rollout and never switched back. The access-control policy passes its annual review date unread. Entra ID sign-in logs, kept for 30 days on P1 and P2 licensing, quietly age out of the evidence window nobody exported. A customer's security questionnaire arrives the week before renewal, and the person who answered it last year has left. By the time the auditor, the C3PAO, the carrier, or the customer asks for proof, the organization is reconstructing evidence rather than producing it. That scramble is the cost this retainer removes — and, increasingly, it is the shape auditors reject: a SOC 2 Type II report samples evidence across an observation period that commonly runs six to twelve months, CMMC Level 2 requires the score and affirmation to be kept current, HIPAA expects its documentation to be maintained and retained for years, and a cyber-insurance application is an attestation your organization signs. This retainer is the monthly operating layer for one agreed framework. Evidence refresh: on a fixed schedule we pull the artifacts that prove each control from where they actually live — Conditional Access and MFA registration state, role and privileged-access assignments, Purview audit-log searches, DLP and retention policy state, Compliance Manager improvement-action status, Secure Score, Defender Vulnerability Management exposure, Defender for Office 365 policies, Intune device compliance and encryption, Azure Policy and Defender for Cloud regulatory-compliance results, backup and restore-test records — and file each one, dated, against the control it evidences. Drift check: the live tenant is compared with the baseline your assessment left; every difference is raised for a decision, reverted or approved into the baseline, and recorded either way. Policy calendar: every policy has an owner and a review date, we send the review pack showing what changed technically since the last signature, and we file the approval. Questionnaire support: when a customer, carrier, or auditor sends a questionnaire or an evidence-request list, we draft the technical answers from the binder within the monthly allowance recorded in your service order, and you review and sign. Audit binder: all of it lives in a SharePoint site in your tenant, organized by control identifier, with an index an auditor can navigate unassisted — and it is yours to keep if the retainer ends. The boundaries are drawn plainly. IT Partner is not an auditor, a CPA firm, a C3PAO, or a certification body; nothing here is an attestation, and no page of ours will ever promise a compliance outcome — that decision belongs to the third party making it, and the binder is honest about what is not done as well as what is. Security-program leadership — the risk register, policy governance, strategy, executive reporting — is the Virtual CISO service, and this retainer is deliberately the operational layer below it: the vCISO decides what the program requires, and this retainer produces the evidence that it is happening. Legal questions about applicability, contracts, and breach obligations belong to counsel. Remediation of gaps is quoted as fixed-price project work you can take anywhere. What you get from us is the Microsoft side done properly, by a practice that holds Microsoft's Solutions Partner designation for Security, has been a Microsoft partner since 2006, and fills in the same cyber-insurance questionnaires itself every year — our own insured status is verifiable on our insurer's live page.

Success criteria

01Every control in the agreed framework's Microsoft 365 and Azure scope has a current evidence artifact in the binder, dated within the cycle in which it was due, or a documented reason it does not.
02Every month closes with a delivered compliance report: evidence refreshed, drift found and decided, policies reviewed or overdue, questionnaires handled, allowance used, and open roadmap items.
03Tenant drift from the baseline is detected within one monthly cycle and either reverted or approved into the baseline with a recorded decision — never discovered by an auditor first.
04No policy passes its review date without a review pack sent, a decision recorded, and the signed version filed.
05Questionnaires and evidence-request lists are answered from the binder inside the allowance, with technical answers you can sign truthfully because the evidence behind each one is attached.
06When the audit, assessment, or renewal window opens, the binder is exported in the requested format on request — no reconstruction week, no re-screenshotting a year of settings.
07You can stop any month and keep everything: the binder, the control-to-evidence map, the policy calendar, and every report.

What you receive

Onboarding baseline (first monthly cycle): import of your readiness assessment's outputs — gap report, remediation roadmap, plan of action and milestones, truthful-attestation checklist — as the retainer's baseline; a control-to-evidence map for the agreed framework listing, for each control in Microsoft scope, the artifact that proves it, where it comes from, and how often it is refreshed; a documented snapshot of the tenant's control state; the audit binder created in a SharePoint site you own; and the policy calendar, questionnaire allowance, scope boundary, and report recipients recorded in your service order.
Monthly evidence refresh: scheduled collection of the artifacts in the control-to-evidence map from Entra ID (sign-in and audit log exports, MFA registration, Conditional Access policies, role and PIM assignments), Microsoft Purview (audit-log searches, DLP and retention policy state, sensitivity-label deployment, Compliance Manager improvement-action status where licensed), Microsoft Defender (Secure Score, Defender Vulnerability Management exposure, Defender for Office 365 policy state), Microsoft Intune (device compliance, configuration baselines, encryption status), and Azure where in scope (Azure Policy compliance, Defender for Cloud regulatory-compliance results, backup job and restore-test records) — each filed, dated, and attributed against its control.
Monthly control-drift check: the live tenant compared with the baseline across Conditional Access, MFA coverage, administrative roles, sharing and guest settings, DLP, retention, Defender, and Intune compliance policy; each difference raised for your decision, with reversions of changed baseline settings executed with your approval as part of the cycle and larger changes documented as an agreed baseline update or quoted as project work.
Policy review calendar: an owner and review date for every policy in the framework's document set; a review pack ahead of each date showing what changed technically since the last signature; the approval recorded and the signed version filed in the binder; overdue reviews escalated in the monthly report.
Framework watch: changes to the agreed framework, its regulator's rulemaking, or your carrier's questionnaire that affect the Microsoft 365 or Azure portion — surfaced in the monthly report with a recommended action, never forwarded wholesale.
Security-questionnaire support within the monthly allowance recorded in your service order: technical answers drafted from the binder for customer due-diligence questionnaires (SIG, CAIQ, and bespoke), cyber-insurance applications and renewals, and auditor or assessor evidence-request lists, with the supporting artifact attached to each answer — you review, you sign.
The audit binder, maintained continuously in your SharePoint: one entry per control with the control statement, an implementation narrative for the Microsoft portion, the evidence artifacts with dates, the owner, the last-verified date, and status; an index; a change log; and read-only auditor access when you ask for it.
A monthly compliance report and review call (up to 45 minutes): evidence refreshed, drift found and decided, policy reviews completed and due, questionnaires handled and allowance used, open roadmap and plan-of-action items with owners, framework changes, and next month's calendar.
Audit or renewal window support: a binder export in the auditor's, assessor's, or carrier's requested format, and responses to their evidence-request list drawn from the binder within the allowance; attendance at auditor walkthroughs by agreement.

How the work unfolds

1. Onboard and baseline (first monthly cycle)

We take the outputs of your readiness assessment as the starting point, build the control-to-evidence map for the agreed framework, record the tenant's control state as the baseline, create the audit binder in a SharePoint site in your tenant, verify what your licensing surfaces — audit-log retention, Entra log retention, Compliance Manager templates — and record the scope boundary, policy calendar, questionnaire allowance, and report recipients in the service order. If the assessment is older than the tenant's last major change, the first cycle re-verifies the baseline before anything is filed against it.

2. Monthly cycle — evidence refresh

On the schedule in the control-to-evidence map, we collect the artifacts from Entra ID, Purview, Defender, Intune, and Azure and file each one, dated and attributed, against its control. Artifacts with short retention windows — Entra sign-in logs, audit-log searches — are exported every cycle so the evidence exists when the observation period is examined.

3. Monthly cycle — drift check and policy calendar

The live tenant is compared with the baseline; every difference is raised with a recommendation, reverted or approved into the baseline with your decision, and recorded. Policies reaching their review date receive a review pack showing what changed since the last signature; approvals are recorded and signed versions filed.

4. Monthly cycle — questionnaires, report, and review call

Questionnaires and evidence-request lists received through the intake are drafted from the binder within the allowance and returned for your review and signature. The month closes with the compliance report and the review call, where drift decisions are confirmed, open roadmap items are assigned, and the next cycle's calendar is set.

5. Audit, assessment, or renewal window

When the window opens, the binder is exported in the requested format, the evidence-request list is answered from it, and — by agreement — an IT Partner engineer attends the walkthroughs that concern the Microsoft 365 or Azure controls. The retainer continues through the window; findings that need remediation are scoped as fixed-price work.

Prerequisites

A completed readiness assessment for the agreed framework — IT Partner's HIPAA, CIS Controls v8.1, CMMC and NIST 800-171, SOC pre-audit, or Cyber Insurance Readiness engagement, or equivalent work done elsewhere — with a gap report or roadmap the retainer can adopt as its baseline. A tenant with no assessment and no documented control state is an assessment first; the onboarding cycle will say so rather than file evidence against a baseline that does not exist.
A Microsoft 365 tenant, and Azure subscriptions where the framework's scope includes them. Licensing determines evidence depth, and we verify it at onboarding: Purview Audit (Standard) retains audit records for 180 days by default, while Audit (Premium) — in Microsoft 365 E5 and the E5 Compliance and eDiscovery and Audit add-ons — retains one year by default and supports longer retention policies; Entra ID sign-in logs are kept for 30 days on P1 and P2 licensing; Compliance Manager's Data Protection Baseline is included with Microsoft 365 subscriptions, while regulatory templates such as HIPAA, NIST SP 800-171, CIS, and SOC 2 are premium templates Microsoft licenses separately, with a limited number included in E5-family suites at the time of writing. Any Microsoft purchase is quoted at Microsoft's published list price, never marked up into this fee.
A GDAP admin relationship approved by you, granting IT Partner least-privilege, time-bound access consistent with our published access policy — evidence collection is largely read-only, and drift reversions are executed only with your approval.
A SharePoint site or library in your tenant for the audit binder — we create and structure it; you own it.
A named compliance owner on your side, authorized to decide on drift, approve policy reviews, review and sign questionnaire answers and attestations, and attend the monthly review call.
An existing policy document set for the framework, from the readiness assessment, your vCISO engagement, or your own program. Where policies are missing, authoring them is scoped separately before the calendar can run.
A service order recording the agreed framework, the scope boundary (tenant, subscriptions, in-scope Microsoft services), the questionnaire allowance, the policy calendar, and report recipients.

Who does what

IT Partner

  • Build and maintain the control-to-evidence map and the audit binder for the agreed framework's Microsoft 365 and Azure scope.
  • Run the monthly evidence refresh, file every artifact dated and attributed, and export short-retention logs every cycle.
  • Run the monthly drift check, raise every difference with a recommendation, execute approved reversions, and record every decision.
  • Operate the policy review calendar: review packs ahead of each date, approvals recorded, signed versions filed, overdue reviews escalated.
  • Draft questionnaire and evidence-request answers from the binder within the allowance, with the supporting artifact attached to each answer, and say before starting when a request will exceed the allowance.
  • Watch the agreed framework, its regulator, and your carrier's requirements for changes that affect the Microsoft portion, and surface them with a recommended action.
  • Deliver the monthly compliance report, hold the review call, and support the audit or renewal window with binder exports and evidence-request responses.

Your team

  • Own the compliance decisions — drift approvals, policy sign-offs, risk acceptances, and attestations are yours; we recommend, execute with approval, and record.
  • Review and sign questionnaire answers and attestations; IT Partner drafts and evidences, but never signs or submits on your behalf.
  • Route changes to in-scope controls through the agreed intake so they are approved into the baseline rather than discovered as drift.
  • Keep the named compliance owner current, attend the monthly review call, and act on escalations — overdue policy reviews, roadmap items, findings that need remediation.
  • Maintain the Microsoft licensing the evidence depth depends on, and supply evidence for the non-Microsoft systems in the framework's scope for filing in the binder.
  • Engage your auditor, assessor, carrier, or counsel directly; we support their evidence requests, they remain your relationship.

What's not included

The audit, assessment, attestation, or certification itself. IT Partner is not a CPA firm, a C3PAO, a certification body, or an assessor of any kind; the SOC 2 report, the CMMC certificate, the ISO certificate, and the carrier's underwriting decision are issued by third parties on their own judgment. This retainer prepares the evidence they examine — nothing here is, or will ever be described as, an attestation.
Any promise of a compliance outcome — passing an audit, achieving certification, satisfying a regulator, or being insured or renewed. Auditor, assessor, regulator, and carrier decisions are theirs, and the binder documents what is true, including what is not yet done.
Security-program leadership — the risk register, strategy, policy governance, incident-readiness planning, security metrics, and executive and board reporting are the Virtual CISO (vCISO) — Security Program as a Service. The vCISO decides what the program requires; this retainer is the operational evidence layer beneath it, and the two are designed to run together without overlap.
Legal advice of any kind — whether a framework applies to you, which records or systems are in scope, Business Associate Agreement or contract negotiation, breach-notification obligations, regulator or examiner correspondence, or enforcement defence. Those questions belong to your counsel; we file what counsel decides.
The initial readiness assessment. The retainer starts from an assessment's closing state — the HIPAA Compliance Assessment, the CIS Controls v8.1 Gap Assessment, the CMMC and NIST 800-171 Readiness Assessment, the SOC 1, SOC 2, ISAE 3402 Pre-Audit Readiness Assessment, or the Cyber Insurance Readiness Assessment — and does not substitute for one.
Remediation of gaps and findings. Reverting a changed baseline setting is part of the cycle; implementing a control that does not yet exist is not. Roadmap and finding remediation is quoted as fixed-price project work — typically Secure Score and security baseline remediation, DLP policy configuration, or a managed program such as Managed Vulnerability Remediation, Managed Entra ID Identity Hygiene and Access Reviews, or Managed Security Awareness Training — priced in writing before it starts and paid after you approve delivery, and always yours to take elsewhere.
Additional frameworks. The fee covers one agreed framework per tenant; a second — ISO 27001, NIST CSF, FINRA and SEC 17a-4 books-and-records, ISO/IEC 42001 for AI management, or another from the list above — is quoted after we review how much of its evidence the existing map already produces, because overlap is real and should lower the price rather than be ignored.
Evidence collection from non-Microsoft systems — electronic health record platforms, ERP, line-of-business SaaS, on-premises network equipment, physical-security controls, HR processes. We file the evidence you supply for those controls in the binder so the framework view is complete, but we do not operate or extract from systems outside Microsoft 365 and Azure.
Policy authoring and rewrites. The calendar reviews and evidences existing policies; drafting a new policy set or restructuring one is vCISO work or a separately scoped engagement.
Questionnaire work beyond the monthly allowance, and due-diligence packages at RFP scale. Requests that will exceed the allowance are flagged before we start and quoted at our published cloud engineer hourly rate or as a fixed-price package — never silently absorbed and never silently billed.
Threat detection, incident response, breach investigation, and 24/7 monitoring — Multi-Platform Managed Detection and Response covers detection and response; this retainer evidences that controls exist and operate, and escalates anything that looks like compromise rather than investigating it.
Purview implementation projects — Data Lifecycle Management, Insider Risk Management, eDiscovery Premium, or a FINRA books-and-records configuration — each a separately quoted engagement whose operating evidence this retainer then collects.
Microsoft licensing — Audit (Premium), Compliance Manager premium templates, Entra ID P2, Microsoft 365 E5 or its add-ons — billed by Microsoft or your CSP at Microsoft's published list price, never marked up into this fee.
Signing or submitting anything on your behalf: attestations, questionnaires, SPRS scores, carrier applications, or auditor correspondence. We draft and evidence; a named officer of your organization signs and submits.

Limitations & technical notes

!No compliance outcome is promised, ever. The auditor, C3PAO, certification body, regulator, or carrier reaches their own conclusion; this retainer makes the evidence complete, current, and honest — including controls that are not implemented and decisions not to act — because a binder that overstates is worse than no binder at all.
!Evidence visibility equals tenant visibility, and logs have windows. Entra ID sign-in logs are retained for 30 days on P1 and P2 licensing; Purview Audit (Standard) retains 180 days by default and Audit (Premium) one year by default, with longer retention available through Microsoft's retention policies and add-ons. We export short-retention evidence every cycle from the day the retainer starts; evidence from before that day exists only where Microsoft still holds it, and the retainer cannot reconstruct a period it did not cover.
!One framework per retainer, scoped to the Microsoft 365 and Azure controls. Most frameworks also reach systems and processes outside Microsoft — the organization-wide HIPAA risk analysis, a CMMC boundary that includes on-premises assets, SOC 2 criteria that cover HR and vendor management — and the binder holds the evidence you supply for those, but we collect only from Microsoft.
!Drift is measured against the baseline recorded at onboarding and updated only by agreed changes. A change made outside the intake appears as drift until you approve it into the baseline or we revert it; that is the mechanism working, not a defect.
!The questionnaire allowance is recorded in the service order at onboarding and sized to your customer and carrier load; unused allowance does not accumulate, and work beyond it in a month is flagged before it starts and quoted. Questionnaire answers are drafts for your review — the accuracy of what you sign is yours, and we attach the evidence so you can check it.
!Microsoft's licensing, features, and Compliance Manager template coverage change without notice; what your tenant surfaces is verified at onboarding and re-verified when Microsoft changes it, and Microsoft's published terms are always the authority. The retainer does not include the Microsoft licenses that deepen evidence.
!Regulatory timelines are the regulators'. At the time of writing, the HIPAA Security Rule amendments proposed in January 2025 remain unfinalized, with HHS's agenda pointing to 2027, and the Department of Defense has paused the later CMMC phases pending a program review while Phase 1 self-assessments remain in contracts. The framework watch reports what has been published and what we recommend; your counsel, contracting officer, or carrier is the authority on what applies to you.
!Support requests go through IT Partner's intake with first response within our published SLA of 1 business hour, with monthly support statistics published openly since December 2023, including the months we missed; scheduled evidence and drift work runs on the monthly cycle, not on the SLA clock.
!Billing is a flat $950 per month per tenant for one framework, invoiced monthly, with no minimum term — stop any month, and all we ask is payment of previously approved invoices. The binder, the control-to-evidence map, the policy calendar, and every report stay in your tenant.

Frequently asked questions

What does the Compliance Evidence and Audit Readiness Retainer include each month?

A complete cycle for one agreed framework on your Microsoft 365 and Azure controls: a scheduled evidence refresh filed against each control, a drift check of the live tenant against your baseline with every difference decided and recorded, the policy review calendar worked with review packs and filed approvals, security-questionnaire support within the allowance in your service order, a framework watch, a continuously maintained audit binder in your own SharePoint, and a monthly compliance report with a review call. The price is a flat $950 per month with no long-term commitment.

Is this 'compliance as a service'?

It is the honest version of it. The market uses that phrase for anything from a dashboard subscription to a fractional compliance officer. This retainer is specifically the recurring labor between assessments: collecting evidence, catching drift, running the policy calendar, answering questionnaires, and keeping the binder current — continuous evidence instead of an annual scramble. What it is not is an auditor, a certification, or a promise about the outcome, and we say that on every page rather than in the small print.

Which frameworks can the retainer cover?

One agreed framework per retainer, chosen from the HIPAA Security Rule, CMMC and NIST SP 800-171, SOC 2, CIS Controls v8.1, or the control requirements in your cyber-insurance carrier's application. Each has its own control-to-evidence map — the artifacts an OCR investigator, a C3PAO, a SOC 2 auditor, a CIS self-assessment, and an underwriter each expect are related but not identical. Other frameworks we assess, such as ISO 27001, NIST CSF, FINRA and SEC 17a-4, and ISO/IEC 42001, can be quoted after we review how much of their evidence your existing map already produces.

We need two frameworks — HIPAA and SOC 2, say. How does that work?

The fee covers one framework; the second is quoted, not doubled. Overlap between frameworks is real — MFA enforcement, audit logging, access reviews, encryption at rest, and vulnerability management evidence the same way for most of them — so we review the existing control-to-evidence map, identify the controls the second framework adds, and quote the increment. The binder then carries both mappings against one set of artifacts.

Where is the line between this retainer and the vCISO?

The vCISO owns the security program: strategy, the risk register, policy governance, incident-readiness planning, security metrics, and executive reporting — the decisions about what the program requires. This retainer is the operational layer below it: the evidence that the Microsoft controls the program calls for exist and keep operating, month after month. Run together, the vCISO sets the policy calendar's content and this retainer runs it; the vCISO decides a drift finding's risk treatment and this retainer records it. If you have no security leadership at all, the vCISO is the first conversation, and this retainer is the second.

Are you auditors? Will you certify us?

No, and no — and any Microsoft partner who answers differently should be asked which accreditation they hold. IT Partner is not a CPA firm, a C3PAO, an ISO certification body, or an assessor. SOC 2 reports come from licensed CPA firms, CMMC certification from an authorized C3PAO, ISO certificates from accredited bodies, and there is no such thing as HIPAA or CIS certification at all. What we do is make sure that when those parties examine your Microsoft 365 and Azure controls, the evidence is complete, current, and honest, and that the people answering their questions have it in front of them.

Do we need a readiness assessment before starting the retainer?

Yes — the retainer starts from a baseline, and the assessment is what produces one: the gap report, the roadmap or plan of action, and a documented control state to check drift against. IT Partner's HIPAA, CIS Controls v8.1, CMMC and NIST 800-171, SOC pre-audit, and Cyber Insurance Readiness assessments each end in exactly that; an equivalent assessment done elsewhere works too. Starting a retainer without one would mean filing evidence against controls nobody has defined, which is how binders end up telling comforting stories rather than true ones.

Do we need Microsoft 365 E5 or Purview Compliance Manager?

No. The retainer runs on Business Premium and E3 tenants; licensing changes evidence depth, not whether the program works. Compliance Manager's Data Protection Baseline is included with Microsoft 365, and we use Compliance Manager's automatically tested improvement actions as an input where they help; the regulatory templates for HIPAA, NIST SP 800-171, CIS, and SOC 2 are premium templates Microsoft licenses separately, with a limited number included in E5-family suites at the time of writing. Audit (Premium) extends audit-log retention from 180 days to one year by default. We verify what your tenant surfaces at onboarding, tell you plainly what a license would add, and quote any Microsoft purchase at Microsoft's published list price — never inside this fee.

Why does the binder live in our SharePoint rather than in Compliance Manager or your portal?

Three reasons. Auditors and assessors want exportable artifacts organized by their control identifiers, not a vendor dashboard they cannot navigate. A binder in your tenant is covered by your retention and access controls, which is itself evidence. And because it is yours: if you stop the retainer, every artifact, narrative, and report stays exactly where it is. Compliance Manager remains a useful input — we record improvement-action status and use its automated tests where licensed — but the system of record is the one you own.

What counts as questionnaire support, and what is the allowance?

Questionnaire support is drafting the technical answers, with the supporting artifact attached, for documents addressed to your organization: customer due-diligence questionnaires such as SIG and CAIQ or bespoke ones, cyber-insurance applications and renewals, and evidence-request lists from auditors and assessors. The allowance is recorded in your service order at onboarding, sized to your customer and carrier load, and reported against every month. A request that will exceed it is flagged before we begin and quoted at our published cloud engineer hourly rate or as a fixed package — no silent absorption, no surprise invoice. You review and sign every answer; we never submit on your behalf.

What happens when the drift check finds a change?

It is raised with a recommendation, not silently fixed. If someone switched a Conditional Access policy to report-only, shortened a retention policy, or added a global administrator, you decide: revert to the baseline, or approve the change into it. Reverting a baseline setting is executed with your approval as part of the cycle; designing a new control or a larger change is scoped as project work. Either way the decision is recorded in the binder, which is what an auditor asking 'how do you manage change?' actually wants to see.

Do you write our policies?

No — we review and evidence the ones you have. The calendar gives every policy an owner and a review date; ahead of each date we prepare a pack showing what changed technically since the last signature, and after the review we file the approval and the signed version. Writing a new policy set, or restructuring one, is the vCISO's work or a separately scoped engagement, because a policy is a management commitment and should be authored by the people who own it.

What about our EHR, ERP, or systems outside Microsoft?

Every framework reaches beyond Microsoft 365 — HIPAA's risk analysis is organization-wide, a CMMC boundary may include on-premises assets, SOC 2 covers HR and vendor management. The binder is structured for the whole framework so the auditor sees one coherent picture, and we file the evidence you supply for non-Microsoft controls in their place. What we collect ourselves is the Microsoft 365 and Azure evidence; we do not operate or extract from other platforms, and we say so instead of implying coverage we do not have.

Will the binder satisfy our auditor, assessor, or insurer?

It is built for exactly that audience — organized by their control identifiers, dated, attributed, and exportable — and clients use it to answer evidence-request lists without a reconstruction week. What we will not do is promise their verdict. An auditor may want a sample we did not anticipate, a C3PAO applies the assessment guide as they read it, a carrier's underwriting is their business. The retainer makes the evidence complete and honest; the conclusion is theirs, and we will never tell you otherwise to close a sale.

How do SOC 2 observation periods, CMMC affirmations, and insurance renewals change the rhythm?

They are why the rhythm is monthly. A SOC 2 Type II report tests controls across an observation period that commonly runs six to twelve months, so the auditor samples evidence from throughout it — an artifact that exists only in audit week fails the sample. CMMC Level 2 keeps a score and an affirmation current in SPRS, and the plan of action has deadlines. A cyber-insurance renewal is an annual attestation whose questions rarely get easier. The monthly cycle means that whichever window opens, the last twelve months of evidence already exist.

What happens in the first month?

Onboarding: we import your readiness assessment's outputs as the baseline, build the control-to-evidence map for the agreed framework, record the tenant's control state, verify what your licensing surfaces, create the binder in your SharePoint, and record the scope, policy calendar, questionnaire allowance, and report recipients in the service order. If the tenant has changed materially since the assessment, the first cycle re-verifies the baseline before anything is filed against it. The regular monthly cycle starts in the second month.

How does billing work, and can we stop?

A flat $950 per month per tenant for one framework, invoiced monthly, with no long-term contract: stop any month, and all we ask is payment of previously approved invoices. The binder, the control-to-evidence map, the policy calendar, and every monthly report live in your SharePoint and stay there — the retainer was built so that leaving it costs you nothing but the labor it was doing.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$950 per month
30 days
Start the compliance retainer