Home All services
Start a project → Call Now

Compliance as a service (CaaS)

Keep your compliance evidence current — between audits, not just before them.

A certification project gathers proof for one audit and then stops, while your systems, suppliers and people keep changing. We run audit readiness and control checks as a retainer instead, so the evidence behind ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 or ISO/IEC 42001:2023 stays current, with a date and an owner on every record.

  • Evidence collected all year, not only at audit time
  • A named owner for every failed control
  • We reply within one working day.
  • ISO/IEC 27001:2022
  • SOC 2 Type 2
  • NIST CSF 2.0
  • ISO/IEC 42001:2023
  • NIST SP 800-204C
Illustration: a shelf of upright compliance folders, the newest glowing blue and the oldest faded grey with one amber tab, beside a clock, with a fresh file on a tray in front

In brief

What it is
A retainer that keeps audit readiness and control checks running between audits, for ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 or ISO/IEC 42001:2023, alone or combined. A control is a safeguard you operate, such as a regular review of who has access.
Why it matters
Evidence starts to age the day an audit closes. By the next audit or customer questionnaire, it no longer matches how your company works.
What you get
Evidence collected continuously, date-stamped and mapped to each framework. Every failed control is tracked to a named owner and a due date.

What the retainer covers

We keep your evidence current and your security rules up to date.

Three kinds of work run for the whole retainer, whichever frameworks are in scope.

Evidence and control checks

We gather evidence while your controls run, check that each control still works, and track every failure to a named owner until it is fixed.

Policy-as-code blueprints

Where a rule can be written as configuration, we write it as a policy-as-code blueprint: a rule your systems can check automatically, not a document someone has to remember.

Your encryption and coding rules, kept current

Twice a year we review your cryptographic standard and your secure development standard. Evidence shows a control ran. These reviews check that the rule behind it is still the right one.

Want risk and governance run as one program alongside the evidence? See GRC as a service. For a live risk register, see risk management as a service, and for a security lead, vCISO services. Evidence about your suppliers sits under third-party risk management.

What the twice-yearly standards reviews look at

Cryptographic standard. The algorithms, key lengths and key management rules it allows, and which of those choices should now be retired or replaced.

Secure development standard. Reviewed rule by rule: how code is reviewed, how dependencies and secrets are handled, and which rules the engineering team can no longer show it follows.

Policy as code and NIST SP 800-204C

NIST SP 800-204C says code-based policy should be versioned, documented and access-controlled like application code. How a blueprint reaches your release pipeline is specified under DevSecOps consulting.

The common mistake

An audit is a checkpoint, not a finish line.

Many companies run certification as a project. A team gathers screenshots, gets policies approved and closes gaps before the audit, then disbands when the result arrives. Nobody collects evidence after that. By the next audit, or the next customer questionnaire, the file is an accurate record of a company that no longer exists.

The standards never treated the audit as an ending. ISO/IEC 27001:2022 requires internal audits of your information security management system (ISMS) and reviews by top management, both at planned intervals (that is, on a set schedule). So new records should keep arriving between certification audits. A SOC 2 Type 2 report covers whether your controls operated throughout a stated period. Once that period has passed, evidence for it cannot be produced. Our SOC 2 readiness page explains how the period runs.

Signs your last audit is wearing off

  • Policies. They were approved before the last audit and show no review since.
  • Access reviews. User access was reviewed once for the auditor, and the next review has no date and no owner.
  • Scope. New systems, suppliers or AI models have arrived since the scope was written, and it still reads the same.
  • People. The person who assembled the evidence has left, and nobody else knows where it is kept.
  • Questionnaires. Every customer security questionnaire starts with a hunt for fresh screenshots.
  • Editions. Nobody can say which edition of each framework the controls were last mapped against.

Any one of these means your evidence is out of date. The aim is an audit position you can defend on any day, not only in audit season.

Records that go stale

Five records that must be up to date again by your next assessment.

Each row names a record, the framework behind it, and what makes it go stale.

Sources: ISO/IEC 27001:2022, clauses 9.2 and 9.3, for the first two rows; the rest restate SecWiz's ISO 27001, SOC 2 and NIST CSF pages.
RecordFrameworkWhat makes it stale
Internal audit of the ISMSISO/IEC 27001:2022, clause 9.2A planned interval passes with no audit completed
Management reviewISO/IEC 27001:2022, clause 9.3Top management misses a review at its planned interval
Statement of Applicability (your list of controls, with a reason for each)ISO/IEC 27001:2022, clause 6.1.3 d)A control or system changes and its row does not
Evidence of controls operatingSOC 2 Type 2A gap in the period that records cannot fill later
Current Profile (where you stand today)NIST CSF 2.0Systems and suppliers change after it was scored

Each framework has its own page: ISO 27001, SOC 2, NIST CSF 2.0 and, for AI management systems, ISO/IEC 42001.

How it runs

We collect evidence all year, so nothing is rebuilt for the auditor.

Four steps, repeated for the length of the retainer.

  1. Map each control once

    We map every control to each framework in scope. A single access review or change record then counts toward ISO/IEC 27001:2022 and SOC 2 wherever both ask for one.

  2. Collect evidence at the source

    Evidence gathering runs continuously in Drata or Vanta, compliance automation platforms that pull records from the systems where your controls run. Records no integration can reach, such as management review minutes, are added on a schedule, not when an auditor asks.

  3. Check controls and assign the failures

    A control that fails a check becomes a Jira ticket (a tracked task) with a named owner and a due date, instead of a finding someone rediscovers while preparing for the next audit.

  4. Answer from records that already exist

    When the auditor's fieldwork starts or a customer questionnaire lands, your team answers from evidence already collected, date-stamped and mapped. Nobody has to rebuild last quarter from memory.

Scope and limits

What this service covers, and what it does not.

"Monitoring" can mean two different jobs, and only one is part of this service. The retainer also has a minimum term.

Compliance monitoring: included

We follow your controls and their evidence: access reviews held on schedule, failed controls fixed, and records still mapped to each framework. These are the records an auditor samples.

Security monitoring: a separate job

Watching systems for threats is security monitoring, and we don't operate a security operations center (SOC). Our threat detection and SOC readiness work sets up the logging and alerts, and helps your team, or the provider you choose, run them.

What this service does not include. Compliance as a service is not an audit and produces no certificate or audit report of its own. An ISO certificate comes from an accredited certification body, and a SOC 2 report is signed by an independent licensed CPA firm. SecWiz is neither: we keep your evidence ready for them.

FAQ

Questions about compliance as a service.

Platforms, frameworks, monitoring and contract terms. For anything else, ask us directly.

Compliance as a Service (CaaS) is a retainer that keeps audit readiness and control validation running between audits instead of rebuilding them before each one. SecWiz's version covers ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 or ISO/IEC 42001:2023, with evidence gathering, remediation tracked to named owners, policy-as-code blueprints and reviews of cryptographic and secure development standards twice a year.

Drata and Vanta are compliance automation platforms, and SecWiz gathers evidence in one or the other. Each vendor describes its product in terms of automation and continuous monitoring. Someone still has to set the scope, see that each failed control gets fixed and keep policies in step with the current edition of every standard. Compliance as a service is that work, carried on for the length of the retainer.

SecWiz's compliance as a service covers ISO/IEC 27001:2022, SOC 2, NIST CSF 2.0 and ISO/IEC 42001:2023, alone or in any combination. The four differ in kind: the two ISO standards define management systems, a SOC 2 Type 2 report looks at how controls operated over a stated period, and NIST CSF 2.0 describes outcomes rather than a checklist. Records are kept in the form each one uses.

Yes. ISO/IEC 42001:2023 is one of the four frameworks the retainer covers. The records that age fastest under it are the AI system inventory and the impact assessments behind it, because an AI system can change after certification without anyone rewriting its paperwork. Under the retainer, both are revisited when a system changes, rather than when a surveillance audit is due.

No. The monitoring inside compliance as a service follows controls and their evidence: whether an access review happened on schedule, whether a failed control was fixed and whether records still map to each framework. Watching systems for threats is security monitoring: SecWiz sets up the logging and alerts as part of its threat detection and SOC readiness work and helps your team, or the provider you choose, run them. We don't operate a SOC. An auditor sampling your controls reads compliance records; an intrusion alert comes from security monitoring.

SecWiz runs compliance as a service on a retainer with a 6-month minimum term and a 12-month default. Evidence proves little until it shows controls operating over time, and a short term ends before that record builds. There are two tiers. On mid-market / growth, SecWiz commits around 20 to 25 fractional (part-time) executive hours a month, with continuous automated compliance monitoring. On enterprise, it commits around 40 to 50 dedicated hours a month, including direct board-level reporting and incident escalation coordination.

Let's talk

Is the evidence from your last audit still true?

Tell us which frameworks apply to you, when your last audit closed and where the evidence sits today. We reply within one working day.