Evidence and control checks
We gather evidence while your controls run, check that each control still works, and track every failure to a named owner until it is fixed.
Compliance as a service (CaaS)
A certification project gathers proof for one audit and then stops, while your systems, suppliers and people keep changing. We run audit readiness and control checks as a retainer instead, so the evidence behind ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 or ISO/IEC 42001:2023 stays current, with a date and an owner on every record.
What the retainer covers
Three kinds of work run for the whole retainer, whichever frameworks are in scope.
We gather evidence while your controls run, check that each control still works, and track every failure to a named owner until it is fixed.
Where a rule can be written as configuration, we write it as a policy-as-code blueprint: a rule your systems can check automatically, not a document someone has to remember.
Twice a year we review your cryptographic standard and your secure development standard. Evidence shows a control ran. These reviews check that the rule behind it is still the right one.
Want risk and governance run as one program alongside the evidence? See GRC as a service. For a live risk register, see risk management as a service, and for a security lead, vCISO services. Evidence about your suppliers sits under third-party risk management.
Cryptographic standard. The algorithms, key lengths and key management rules it allows, and which of those choices should now be retired or replaced.
Secure development standard. Reviewed rule by rule: how code is reviewed, how dependencies and secrets are handled, and which rules the engineering team can no longer show it follows.
NIST SP 800-204C says code-based policy should be versioned, documented and access-controlled like application code. How a blueprint reaches your release pipeline is specified under DevSecOps consulting.
The common mistake
Many companies run certification as a project. A team gathers screenshots, gets policies approved and closes gaps before the audit, then disbands when the result arrives. Nobody collects evidence after that. By the next audit, or the next customer questionnaire, the file is an accurate record of a company that no longer exists.
The standards never treated the audit as an ending. ISO/IEC 27001:2022 requires internal audits of your information security management system (ISMS) and reviews by top management, both at planned intervals (that is, on a set schedule). So new records should keep arriving between certification audits. A SOC 2 Type 2 report covers whether your controls operated throughout a stated period. Once that period has passed, evidence for it cannot be produced. Our SOC 2 readiness page explains how the period runs.
Any one of these means your evidence is out of date. The aim is an audit position you can defend on any day, not only in audit season.
Records that go stale
Each row names a record, the framework behind it, and what makes it go stale.
| Record | Framework | What makes it stale |
|---|---|---|
| Internal audit of the ISMS | ISO/IEC 27001:2022, clause 9.2 | A planned interval passes with no audit completed |
| Management review | ISO/IEC 27001:2022, clause 9.3 | Top management misses a review at its planned interval |
| Statement of Applicability (your list of controls, with a reason for each) | ISO/IEC 27001:2022, clause 6.1.3 d) | A control or system changes and its row does not |
| Evidence of controls operating | SOC 2 Type 2 | A gap in the period that records cannot fill later |
| Current Profile (where you stand today) | NIST CSF 2.0 | Systems and suppliers change after it was scored |
Each framework has its own page: ISO 27001, SOC 2, NIST CSF 2.0 and, for AI management systems, ISO/IEC 42001.
How it runs
Four steps, repeated for the length of the retainer.
We map every control to each framework in scope. A single access review or change record then counts toward ISO/IEC 27001:2022 and SOC 2 wherever both ask for one.
Evidence gathering runs continuously in Drata or Vanta, compliance automation platforms that pull records from the systems where your controls run. Records no integration can reach, such as management review minutes, are added on a schedule, not when an auditor asks.
A control that fails a check becomes a Jira ticket (a tracked task) with a named owner and a due date, instead of a finding someone rediscovers while preparing for the next audit.
When the auditor's fieldwork starts or a customer questionnaire lands, your team answers from evidence already collected, date-stamped and mapped. Nobody has to rebuild last quarter from memory.
Scope and limits
"Monitoring" can mean two different jobs, and only one is part of this service. The retainer also has a minimum term.
We follow your controls and their evidence: access reviews held on schedule, failed controls fixed, and records still mapped to each framework. These are the records an auditor samples.
Watching systems for threats is security monitoring, and we don't operate a security operations center (SOC). Our threat detection and SOC readiness work sets up the logging and alerts, and helps your team, or the provider you choose, run them.
Controls need time to show that they work, so we don't offer a shorter term. The tier sets your monthly hours: see managed security and compliance services.
What this service does not include. Compliance as a service is not an audit and produces no certificate or audit report of its own. An ISO certificate comes from an accredited certification body, and a SOC 2 report is signed by an independent licensed CPA firm. SecWiz is neither: we keep your evidence ready for them.
FAQ
Platforms, frameworks, monitoring and contract terms. For anything else, ask us directly.
Compliance as a Service (CaaS) is a retainer that keeps audit readiness and control validation running between audits instead of rebuilding them before each one. SecWiz's version covers ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 or ISO/IEC 42001:2023, with evidence gathering, remediation tracked to named owners, policy-as-code blueprints and reviews of cryptographic and secure development standards twice a year.
Drata and Vanta are compliance automation platforms, and SecWiz gathers evidence in one or the other. Each vendor describes its product in terms of automation and continuous monitoring. Someone still has to set the scope, see that each failed control gets fixed and keep policies in step with the current edition of every standard. Compliance as a service is that work, carried on for the length of the retainer.
SecWiz's compliance as a service covers ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 and ISO/IEC 42001:2023, alone or in any combination. The four differ in kind: the two ISO standards define management systems, a SOC 2 Type 2 report looks at how controls operated over a stated period, and NIST CSF 2.0 describes outcomes rather than a checklist. Records are kept in the form each one uses.
Yes. ISO/IEC 42001:2023 is one of the four frameworks the retainer covers. The records that age fastest under it are the AI system inventory and the impact assessments behind it, because an AI system can change after certification without anyone rewriting its paperwork. Under the retainer, both are revisited when a system changes, rather than when a surveillance audit is due.
No. The monitoring inside compliance as a service follows controls and their evidence: whether an access review happened on schedule, whether a failed control was fixed and whether records still map to each framework. Watching systems for threats is security monitoring: SecWiz sets up the logging and alerts as part of its threat detection and SOC readiness work and helps your team, or the provider you choose, run them. We don't operate a SOC. An auditor sampling your controls reads compliance records; an intrusion alert comes from security monitoring.
SecWiz runs compliance as a service on a retainer with a 6-month minimum term and a 12-month default. Evidence proves little until it shows controls operating over time, and a short term ends before that record builds. There are two tiers. On mid-market / growth, SecWiz commits around 20 to 25 fractional (part-time) executive hours a month, with continuous automated compliance monitoring. On enterprise, it commits around 40 to 50 dedicated hours a month, including direct board-level reporting and incident escalation coordination.
Let's talk
Tell us which frameworks apply to you, when your last audit closed and where the evidence sits today. We reply within one working day.