A business technologist, not an English major.
Your SOC 2, CMMC, or ISO 27001 audit is scheduled. The documentation isn't ready. I can usually deliver the complete set (policy suite, control matrix, gap list, evidence checklist) in two to three weeks.
Fixed fee. Quoted up front. Risk free: I absorb overages.
Book a scoping call →Free · 30 minutes · No pitch
Free · 30 minutes · No pitch
If the policy says quarterly and you have zero artifacts, that's a finding.
Templates assign roles to titles you haven't hired.
The procedure says same-day revocation. Your ticket history says nine days.
A plan with no tabletop exercise date is a document, not a control.
If it says "the organization's identity provider" instead of your IdP's name, the auditor knows nobody operationalized it.
So the work isn't writing. The work is extraction:
Your total time in the process: one 90-minute interview, one review pass. I do the rest.
Typically 15 to 25 documents for SOC 2, or SSP plus POA&M for CMMC. Written in your tool names, your role titles, your real frequencies. Because that's the only version that survives sampling.
Every in-scope control traced to the document and section that satisfies it, because "where is this covered?" is the question auditors ask most and the one that burns the most billable audit hours when you can't answer it.
The controls no document can save, flagged before your auditor finds them, ranked by what's fixable in a sprint versus what needs budget.
What to collect monthly and quarterly from day one, because a Type I tests your documents but a Type II tests your artifacts, and companies that pass the first routinely fail the second for lack of a paper trail.
Director- and VP-level cybersecurity at institutions where audits never stop and findings follow you.
I do one thing: security and compliance documentation. Not marketing content, not user manuals, not "technical writing."
I'm a business technologist who knows how to defend your business.
If you have no MFA, I won't write a policy that claims you do. That turns a gap into an audit failure and, in some frameworks, a false attestation. You'll get it on the punch list instead.
Compliance automation platforms are good at evidence collection; I'm the layer they don't do well: documentation that matches your reality. And I write the policies; a CPA firm audits them. Independence rules mean those should never be the same person anyway.
Multi-framework, multi-entity, or CUI environments may run longer. I'll tell you the real timeline on the scoping call, not after you've paid.
If you want someone to paper over an empty program a week before fieldwork, I'm the wrong hire. If you operate reasonably well and need documentation that proves it, this may be the fastest version of that available.
Thirty minutes: you tell me the framework, the deadline, and the stack. I count your gap and quote a fixed price with a delivery date. No hourly meter, no scope creep, because you're buying a deliverable, not my time.
The guarantee: every delivered document maps to a named control, every in-scope control maps to a delivered document, and if your auditor rejects any deliverable as non-responsive to its control, I rewrite it free until it's accepted. You carry the audit risk on your practices. I carry it on the paper.
I take a limited number of documentation engagements at a time (the interview and drafting are me, not a team), so scheduling is first-scoped, first-slotted.
Book a scoping call →Free · 30 minutes · No pitch