Productized service — $2,500 one-time

GRC Foundation Sprint

A complete risk & compliance baseline delivered in two weeks. Before we start, here's everything we'll need from you (or your client).

1. Company & engagement details

We need to scope the workspace, tailor the risk universe, and understand the regulatory landscape.

  • Company legal name & primary domain
  • Industry / vertical (e.g. fintech, healthcare, SaaS, manufacturing)
  • Company size (headcount & approximate annual revenue range)
  • Primary office locations & any remote-workforce considerations
  • Engagement sponsor name, title & email (the person who will own the workspace after handoff)
  • Any secondary stakeholders who should have workspace access (names, emails, roles)

2. Target compliance framework

The Sprint includes one framework gap assessment — we need to know which one to run.

  • Which framework? (SOC 2 Type II, ISO 27001, NIST CSF 2.0, HITRUST CSF, HIPAA, or ISO 27002)
  • Have you started any prior compliance work against this framework? If yes, share any existing evidence or gap analysis
  • Are you pursuing certification/attestation, or is this for internal readiness?
  • Target audit date or compliance deadline (if any)

3. Risk landscape

This seeds the initial risk assessment and populates the risk register with real, relevant entries.

  • Any existing risk register, risk assessment, or threat model (spreadsheet, PDF, or other format)
  • Known top concerns or past incidents (ransomware, data breach, vendor failure, natural disaster, etc.)
  • Existing security policies or an information security policy document
  • Cyber insurance coverage summary (if applicable)

4. IT & infrastructure overview

Understanding the environment lets us identify the right technical risks and map controls accurately.

  • Cloud providers in use (AWS, Azure, GCP, other)
  • Key SaaS tools (e.g. Google Workspace, Microsoft 365, Salesforce, Jira, GitHub)
  • On-premise infrastructure summary (if any)
  • Identity provider & SSO setup (Okta, Azure AD, Google, none)
  • Data classification — what sensitive data types do you handle? (PII, PHI, PCI, financial, IP)
  • Backup & disaster recovery approach (cloud snapshots, tape, third-party, none)

5. Five critical business processes (for BIA)

We build a Business Impact Analysis for your five most important processes. Tell us what keeps the business running.

  • List your five most critical business processes (e.g. customer onboarding, payment processing, production deployment, patient scheduling, order fulfillment)
  • For each process: who owns it, which systems support it, and what happens if it goes down for 4 hours / 24 hours / 72 hours
  • Existing RTO (Recovery Time Objective) and RPO (Recovery Point Objective) targets, if defined
  • Any known single points of failure

6. Key vendors & third parties

Third-party risk is almost always in scope. Knowing your critical vendors helps us assess concentration risk.

  • List of critical vendors / subprocessors (hosting, payment, HR, legal, managed IT)
  • Any existing vendor risk assessments or SOC 2 reports from vendors
  • Vendor SLAs or contractual recovery commitments (if available)

7. Existing documentation (share whatever you have)

Anything you've already written saves time and ensures we build on your existing work rather than starting from scratch.

  • Information security policy
  • Acceptable use policy
  • Incident response plan
  • Business continuity or disaster recovery plan
  • Previous audit reports or penetration test summaries
  • Org chart or RACI for security responsibilities
  • Network diagram or architecture overview
Two-week timeline

How it works

Once you submit the checklist above, here's what the next 14 days look like.

1

Day 0

Kickoff call

60-minute walkthrough of your submitted materials, confirm scope and framework, set up workspace access.

2

Days 1–3

Risk assessment & register

We analyze your environment, identify threats, and populate the risk register with scored, owned entries.

3

Days 4–6

Framework gap assessment

Control-by-control review against your chosen framework. Every gap is documented with remediation guidance.

4

Days 7–9

BIA for five processes

Impact analysis, dependency mapping, RTO/RPO recommendations for each critical process.

5

Days 10–12

Remediation roadmap

Prioritized, executive-ready action plan: what to fix first, estimated effort, and quick wins.

6

Day 14

Handoff call

Walk through every deliverable in your configured NovaGRC workspace. Q&A, next steps, 90-day access begins.

What you receive

Initial risk assessment with scored threats
Populated risk register (5×5 heat map)
One framework gap assessment with remediation notes
BIA for five critical business processes
Executive remediation roadmap (prioritized)
Fully configured NovaGRC workspace
90 days of platform access included
Kickoff + handoff calls with the founder
Sprint intake form

Start your Sprint

Fill in what you can below. We'll review your submission and schedule a 60-minute kickoff call within one business day.

1. Company & engagement

2. Target compliance framework

3. Risk landscape

4. IT & infrastructure

5. Five critical business processes (for BIA)

6. Key vendors & third parties

7. Existing documentation & anything else

Only company name, your name, and email are required. Send what you have — we'll cover any gaps on the kickoff call.