Establish a security baseline
Use a focused assessment when you need a documented starting point for access controls, system protection, recovery, and other core security practices.
Our entry-level assessment: an advisor reviews 25 core security checks, identifies key gaps, and gives you a written action plan. Start with a focused scope before deciding whether you need a deeper assessment or help with implementation.
$1,500-$5,000 one-time for small-scope engagements of up to 25 people. Larger or more complex scopes are estimated separately. No retainer required.
Use a focused assessment when you need a documented starting point for access controls, system protection, recovery, and other core security practices.
We distinguish implemented, partial, missing, and unverified safeguards so your team can see what needs attention and what still needs evidence.
A gap assessment reviews a defined set of checks. Choose the full risk assessment when you also need detailed analysis of threats, business impact, and remediation priorities.
Best fit: businesses starting from nothing or near it: no framework being demanded yet, no recent assessment, and an owner who wants a fast, honest read on where things stand.
Not the right fit: organizations being held to a specific framework by a customer or regulator (go straight to that framework under Compliance Services), or those ready for the full in-depth risk assessment.
A framework of cybersecurity outcomes across Govern, Identify, Protect, Detect, Respond, and Recover. It does not prescribe a fixed set of 25 controls.
Our 25-check baseline is mapped to the framework. We confirm its applicability to your systems and record any scope limits before the review.
A status for each check, supporting evidence, identified gaps, and recommended actions. This focused review is not a NIST certification or a complete CSF assessment.
| NIST CSF 2.0 | SOC 2 | ISO 27001 | |
|---|---|---|---|
| Who it applies to | Any organization; the recognized starting bar | Vendors facing US enterprise security reviews | Organizations whose customers or markets demand certification |
| Scope | Outcomes across six functions: Govern, Identify, Protect, Detect, Respond, Recover | Controls relevant to the applicable Trust Services Criteria | A management system with risk-based control selection and a Statement of Applicability |
| Who assesses | Self-assessed, evidence on file | Licensed CPA firm audit | Accredited certification body, two-stage audit |
| Assessment output | Documented findings and framework mapping | Independent CPA examination report | Certification decision by an independent body |
These are different assessment approaches, not interchangeable credentials. This engagement covers Hardenwell's selected checks, not a complete assessment of every NIST CSF outcome. Read the NIST CSF 2.0 overview.
Each phase is a set of sub-services with documents you keep. You can follow progress phase by phase, and nothing assumes you have anything in place today.
Phase 01 · The foundation
We list what actually exists before judging anything. Asset discovery: every device, application, cloud service, and the places your important data lives. Access review: every account and admin, and whether MFA is truly on everywhere. You get the inventory and the access review in writing.
Phase 02 · The assessment
25-control gap analysis: each selected check scored met, partial, missing, or unverified against evidence, not answers. Risk prioritization: gaps ranked by what they could actually cost your business, so the fix order makes sense before any money is spent.
Phase 03 · The remediation
Policy crafting: the core rules written to match how you actually operate: passwords and MFA, data handling, offboarding, backups. Action plan: every fix on one tracked list with an owner, a target date, and a rough cost, ready for your IT to work from.
Phase 04 · The safety net
Incident response blueprint: the one-page plan naming who to call and in what order, with your insurer's breach line on it. Backup verification: we confirm a copy is isolated from ransomware and restore a real file to prove the safety net holds.
The free snapshot on this site gives you a working price range. Your written quote itemizes each phase and sub-service, so you see exactly what each part costs before anything starts.
A named, CISSP-certified advisor leads your engagement, with specialist support where needed. Responsibilities and the agreed deliverables are documented before work begins.
We do not receive referral commissions from auditors, testing firms, brokers, or software vendors. External services are identified separately so you can review their scope and fees.
Your report records the status of each selected check, the supporting evidence, and the recommended improvements.
Aprio
The assessment brought up the right uncomfortable questions around access, client data, and old accounts. The consultants at Hardenwell handled it professionally and helped us separate urgent work from cleanup work.
Stewart Title / Stewart Information Services
The hard part was not finding things to improve. It was knowing which improvements mattered most. Our Hardenwell advisor helped weigh risk, effort, and business impact so the plan felt practical.
Cenikor Foundation
Our hesitation was budget. Their consultants helped us avoid overbuying while still taking the security gaps seriously. That was exactly the balance we needed.
No. NIST does not certify CSF implementations. This service documents the results of Hardenwell's selected checks and their mapping to NIST CSF 2.0; it does not assess every framework outcome.
It provides a common structure for discussing cybersecurity risk with leadership and technical teams. We use that structure to organize findings; the scope of this service remains the 25 checks agreed for the engagement.
Relevant evidence and findings can be reused, but those engagements have different scope and assessment requirements. We identify what can carry forward and what additional work is needed.
The gap assessment checks a defined security baseline. The full cybersecurity risk assessment examines the agreed systems, data flows, threats, vulnerabilities, likelihood, and business impact, then produces a scored risk register and remediation roadmap.
We cover your organization, your deadline, and who is asking for what. You leave knowing the likely scope, the timeline, and your next step, with the price fixed in writing before any work starts.
Prefer phone or email?
(754) 216-9664 [email protected]
Do not include PHI or sensitive records in booking notes. See our Privacy Policy.