Skip to main content
Has your work email already leaked?Run the 10-second check
Compliance services

Most audits are not failed on controls. They are failed on evidence.

Nearly every organization we assess already owns more security capability than it can prove it operated. An assessor does not ask what you bought. They ask for the record. That record is a byproduct of running a security operation properly, which is what this service is.

What this service is

Cybersecurity compliance services are managed security operations delivered so that the resulting monitoring, log retention, incident records and control evidence satisfy the technical requirements of a compliance framework.

Vijilan supports CMMC 2.0, HIPAA, PCI DSS, SOC 2, ISO/IEC 27001, NIST CSF and GDPR. Vijilan itself is certified for SOC 2 Type II and ISO/IEC 27001; for the other frameworks the service makes a customer audit-ready rather than claiming a certification that, in several cases, does not exist for a vendor to hold.

No managed security provider can make an organization compliant on its own. Compliance also covers policy, training, physical security and business process. What a managed service covers is the technical control families, and the evidence that they operated across the period under review.

Three different questions

Our certifications are not your compliance.

Providers answer all three of these with the same sentence, and it is why compliance conversations go in circles. They are separate things and they have separate pages.

What an assessor gets

Six things every framework asks for.

The wording differs between CMMC, HIPAA, PCI DSS and SOC 2. What they are asking for underneath does not differ nearly as much as the paperwork suggests.

Continuous monitoring

Almost every framework requires it, and almost none of them accept a product license as proof. What satisfies an assessor is a record of somebody actually watching, continuously, with the gaps visible.

Log retention and audit trail

Retention periods are where compliance projects quietly fail, because the requirement arrives after the logs were already discarded. ThreatLog™ is index-free, so keeping twelve months does not cost what it costs elsewhere.

Incident detection and response records

Frameworks ask what you did, how fast, and who decided. A ticket saying "resolved" is not that. What comes out of an engagement is a timeline with named decisions on it.

Vulnerability and exposure management

Identified, prioritized, tracked to closure, with the reasoning recorded. Assessors look for the reasoning, because a risk accepted deliberately is compliant and a risk missed is not.

Identity and access controls

Privileged access, authentication events, and the record of who could reach what and when. This is where audits spend their time, and it is the evidence organizations are least likely to have.

Reporting built for an assessor

Evidence packs mapped to the control families of your framework, produced on request rather than assembled by your team the week before the audit.

Coverage

Frameworks we work against.

CMMC 2.0 Level 2Defense contractors handling CUI. 110 controls.
HIPAACovered entities and business associates.
PCI DSSCardholder data environments.
SOC 2Service organizations proving controls to customers.
ISO/IEC 27001An information security management system.
NIST CSFThe framework most others map back to.
GDPRPersonal data of EU and UK residents.

Vijilan holds SOC 2 Type II and ISO/IEC 27001 certifications of its own, audited by A-LIGN. For the remaining frameworks the service makes you audit-ready; it does not make us certified in them, and for HIPAA in particular no such vendor certification exists. Why that distinction matters.

The deadline case

CMMC 2.0 Level 2, and where the time actually goes.

Level 2 is 110 controls, and the number is what makes it feel impossible. In practice the work is decided earlier than that: by where Controlled Unclassified Information genuinely lives in your environment. Scope it narrowly and honestly and a large share of those controls apply to a small part of the estate. Skip that step and you are implementing 110 controls everywhere, which is where the panic and most of the cost come from.

What a managed SOC covers directly is the continuous monitoring requirement, the audit logging and retention, the incident detection and response records, and the access control evidence. What it does not cover is your system security plan, your policy set or your organizational documentation. Those are advisory work, and pretending otherwise is how CMMC projects arrive at the assessment with half a file.

Questions

Asked by people with a deadline.

Can a managed security provider make us compliant?

Not on its own, and anyone saying otherwise is selling something. Compliance covers policy, training, physical security, vendor management and business process alongside technical controls, and a security provider touches only some of that. What a managed service can do is cover the technical control families and, just as importantly, produce the evidence that they operated. That is usually the half organizations are missing.

What is the difference between having controls and being audit-ready?

Most organizations we assess already have more controls than they can prove. An assessor is not asking whether you own a tool; they are asking for evidence it was configured, monitored and acted upon across the period under review. Controls are a purchase. Evidence is an operating record, and it can only be produced by actually operating.

Which frameworks do you support?

CMMC 2.0, HIPAA, PCI DSS, SOC 2, ISO/IEC 27001, NIST CSF and GDPR. Vijilan itself is certified for SOC 2 Type II and ISO/IEC 27001; for the others we get you audit-ready rather than claiming a certification in them, because in several cases no such certification exists.

Are you HIPAA or CMMC certified?

No, and neither is any other provider, because those frameworks do not certify vendors that way. HIPAA has no certifying body at all. CMMC certifies a specific organization against a specific contract requirement, which means it certifies you, not us. What we supply is the evidence your assessment needs. The trust page explains the distinction between a certification, a partner designation and an evidence pack.

We have a CMMC deadline. Where does this start?

With scope, because CMMC 2.0 Level 2 is 110 controls and the ones that matter are determined by where Controlled Unclassified Information actually lives. Most of the work is establishing that, and most of the panic comes from skipping it. From there the technical control families and the continuous monitoring requirement are what a managed SOC covers directly.

Do you provide the documentation, or do we write it?

We provide the evidence our service generates, mapped to your framework. The policy set, the system security plan and the organizational documentation are yours, and they are where a vCISO engagement is usually more useful than a monitoring contract. ThreatGovern™ exists for that half.

How long does retention need to be?

It depends on the framework, and it is worth checking before you choose a SIEM rather than after. Several require a year or more of retrievable logs, and per-gigabyte ingestion pricing is what turns that requirement into a budget problem. Index-free retention is the reason this is usually a smaller line item with us than the alternative.

We're online · book a SOC walkthrough today

Bring us the framework
and the deadline.

The useful first conversation is about scope, not tooling. Tell us which framework, what is in scope and when the assessment is, and we will tell you which half of it we can carry.