There’s a lot of overlap between compliance standards, and often multiple are needed. So blending them together makes a lot of sense! How does that work?
At the start of 2021 (a year ago) we started our “all-you-can-eat cyber assurance” covering SOC 1, SOC 2, HIPAA, GDPR, Consumer Data Right, and CCPA. It was instantly popular. It’s common to see three, four, even all six of those as important business goals or requirements. We offered it to three existing clients that all went for it, and then we paused while we saw it play out in those pilots.
At the start of 2022 (this year), we've now added a few additional pieces to the list and offer three levels of blended standards; Establish, Expand and Excel. The new standards include:
Now our blends can cover all bases of what enterprise care about; bar perhaps US government, high security clearances, or nuanced regulatory compliance for specific industries like finance.
What’s blending?
The concept is; we blend multiple standards into one commercial arrangement and clients can add them when they want, and when they’re ready. With the efficiencies involved it works out to about double the cost and effort of a single standard, so if you need any two or more it’s generally worth it.
Why is it so popular?
Cost savings aside, there are a few reasons why the concept is really popular;
How do the blends work?
We have three tiers; Establish, Expand, and Excel, that each do what their names suggest:
What’s the catch? Why doesn’t everyone do blending?
Blending in this way just makes a lot of sense. In each model you get more for less. Even if you don’t want more, the simplicity of having it included for if and when you do, removes major headaches.
There’s efficiencies of this new way of looking at compliance; instead of individual projects and duplication. It works based on the underlying compliance attributes with many overlapping areas within each standard. Our software enables this without any duplication, so we have an edge when it comes to this style of approach. It’s a natural evolution of our clients needs that we’ve been supporting for years in the snowballing world of compliance standards. No one standard is enough.
There are a few circumstances where this new way may not be the best option for you:
Aside from those scenarios, the three blends should save costs and effort compared to any other approach. For example, even if you go for the bare minimum; straight to SOC 2 Type 2 and Security only, the Establish blend works out to the same costs but with monthly billing. The additional Type 1 report, Availability and Confidentiality are included if you later decide you want them (we think you will based on our experience, and it's a good option to have if you need them).
How do you get started?
Our award-winning product is free to use for your initial assessment; we always recommend this as the first step so you know what you're in for before committing to it. You can select as many of the standards as you like, and assess your current state against all of them in one assessment. We'll workshop the outputs with you, to guide you on deciding an action plan, perhaps a roadmap of when you want to incorporate each standard based on your growth strategy and customer requirements.
About AssuranceLab
AssuranceLab is a modern cybersecurity audit firm that provides assurance reports (ASAE 3150, SOC 1/2, and more!). Our award-winning, free software has helped over 500 companies prepare for their compliance goals. We're experts in the latest software and cloud providers. We guide your team through the compliance practices in a way that fits your environment and culture. We work closely with clients through our agile and collaborative approach; saving time, costs, and headaches along the way.