Security gap assessment.

Our entry-level assessment: an advisor reviews 25 core security checks, identifies key gaps, and gives you a written action plan. Start with a focused scope before deciding whether you need a deeper assessment or help with implementation.

$1,500-$5,000 one-time for small-scope engagements of up to 25 people. Larger or more complex scopes are estimated separately. No retainer required.

NIST CSF 2.0 alignment seal
  • 25 checksA Hardenwell baseline mapped to NIST CSF
  • 1-2 weeksTypical review window, confirmed at scoping
  • Gap reportFindings and recommended actions, not certification
  • One advisorFrom scope through the findings review

When to use this service.

01

Establish a security baseline

Use a focused assessment when you need a documented starting point for access controls, system protection, recovery, and other core security practices.

02

Identify missing controls

We distinguish implemented, partial, missing, and unverified safeguards so your team can see what needs attention and what still needs evidence.

03

Decide whether to assess further

A gap assessment reviews a defined set of checks. Choose the full risk assessment when you also need detailed analysis of threats, business impact, and remediation priorities.

Best fit: businesses starting from nothing or near it: no framework being demanded yet, no recent assessment, and an owner who wants a fast, honest read on where things stand.

Not the right fit: organizations being held to a specific framework by a customer or regulator (go straight to that framework under Compliance Services), or those ready for the full in-depth risk assessment.

What NIST CSF is.

NIST CSF 2.0

A framework of cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond, and Recover. It does not prescribe a fixed set of 25 controls.

Hardenwell's assessment

Our 25-check baseline is mapped to the framework. We confirm its applicability to your systems and record any scope limits before the review.

Your report

A status for each check, supporting evidence, identified gaps, and recommended actions. This focused review is not a NIST certification or a complete CSF assessment.

NIST CSF 2.0SOC 2ISO 27001
Who it applies toAny organization; the recognized starting barVendors facing US enterprise security reviewsOrganizations whose customers or markets demand certification
ScopeOutcomes across six functions: Govern, Identify, Protect, Detect, Respond, RecoverControls relevant to the applicable Trust Services CriteriaA management system with risk-based control selection and a Statement of Applicability
Who assessesSelf-assessed, evidence on fileLicensed CPA firm auditAccredited certification body, two-stage audit
Assessment outputDocumented findings and framework mappingIndependent CPA examination reportCertification decision by an independent body

These are different assessment approaches, not interchangeable credentials. This engagement covers Hardenwell's selected checks, not a complete assessment of every NIST CSF outcome. Read the NIST CSF 2.0 overview.

One service, four phases.

Each phase is a set of sub-services with documents you keep. You can follow progress phase by phase, and nothing assumes you have anything in place today.

  1. Phase 01 · The foundation

    Define and locate

    We list what actually exists before judging anything. Asset discovery: every device, application, cloud service, and the places your important data lives. Access review: every account and admin, and whether MFA is truly on everywhere. You get the inventory and the access review in writing.

  2. Phase 02 · The assessment

    Analyze the gaps

    25-control gap analysis: each selected check scored met, partial, missing, or unverified against evidence, not answers. Risk prioritization: gaps ranked by what they could actually cost your business, so the fix order makes sense before any money is spent.

  3. Phase 03 · The remediation

    Fix and document

    Policy crafting: the core rules written to match how you actually operate: passwords and MFA, data handling, offboarding, backups. Action plan: every fix on one tracked list with an owner, a target date, and a rough cost, ready for your IT to work from.

  4. Phase 04 · The safety net

    Prepare for the worst

    Incident response blueprint: the one-page plan naming who to call and in what order, with your insurer's breach line on it. Backup verification: we confirm a copy is isolated from ransomware and restore a real file to prove the safety net holds.

The free snapshot on this site gives you a working price range. Your written quote itemizes each phase and sub-service, so you see exactly what each part costs before anything starts.

Why Hardenwell.

A dedicated advisor

A named, CISSP-certified advisor leads your engagement, with specialist support where needed. Responsibilities and the agreed deliverables are documented before work begins.

No referral commissions

We do not receive referral commissions from auditors, testing firms, brokers, or software vendors. External services are identified separately so you can review their scope and fees.

A documented gap report

Your report records the status of each selected check, the supporting evidence, and the recommended improvements.

Client reviews.

Aprio

The assessment brought up the right uncomfortable questions around access, client data, and old accounts. The consultants at Hardenwell handled it professionally and helped us separate urgent work from cleanup work.
Brent M.Chief Digital Officer and Partner

Stewart Title / Stewart Information Services

The hard part was not finding things to improve. It was knowing which improvements mattered most. Our Hardenwell advisor helped weigh risk, effort, and business impact so the plan felt practical.
John H.Chief Information Officer

Cenikor Foundation

Our hesitation was budget. Their consultants helped us avoid overbuying while still taking the security gaps seriously. That was exactly the balance we needed.
Bill B.President and CEO

Frequently asked questions.

Book your scope call.

Thirty minutes with an advisor.

We cover your organization, your deadline, and who is asking for what. You leave knowing the likely scope, the timeline, and your next step, with the price fixed in writing before any work starts.

Prefer phone or email?

(754) 216-9664 [email protected]

Do not include PHI or sensitive records in booking notes. See our Privacy Policy.

Book a call