Frequently asked questions.
FAQs
The questions buyers ask before hiring a virtual CISO. Engagements, pricing, frameworks, working style, data handling. If you do not see your question, the discovery call is the fastest way to get a real answer.
General FAQs
Vendors
Frameworks
Industries
General FAQs
-
What is a virtual CISO (vCISO)?
A virtual Chief Information Security Officer (vCISO) is an experienced security leader who helps your business build and manage its cybersecurity program without the cost of hiring a full-time executive. A vCISO develops your security strategy, prepares your business for SOC 2, ISO 27001, HIPAA, PCI DSS, and other frameworks, manages risk, supports customer security reviews, and helps you meet enterprise security requirements while your team stays focused on growing the business.
-
How is a vCISO different from a full-time CISO?
A full-time CISO is a permanent executive hire, often costing hundreds of thousands of dollars per year when salary, benefits, and equity are included. A vCISO delivers the same strategic leadership on a flexible basis, allowing growing companies to access senior security expertise without the long hiring process or full-time overhead. This makes a vCISO an ideal solution for startups, SaaS companies, healthcare organizations, fintechs, and other regulated businesses.
-
What are the engagement options?
Security Sprint is a short, fixed-scope engagement that identifies your biggest security gaps and delivers a prioritized roadmap.
Strategic vCISO provides ongoing monthly guidance, compliance leadership, policy reviews, customer questionnaire support, and security planning.
Leader vCISO is designed for organizations that need hands-on security leadership, audit preparation, remediation support, executive reporting, and an experienced security partner working alongside their team.
-
Which security frameworks do you support?
CloudSapio helps organizations prepare for and maintain compliance with leading cybersecurity and privacy frameworks, including:
SOC 2
ISO 27001
HIPAA
PCI DSS
GDPR
NIST Cybersecurity Framework (NIST CSF)
AI Security & Governance
We also support organizations using Vanta, Drata, and other compliance automation platforms.
se we're experienced. Because we know what we're doing, and because we genuinely believe we can help you rank higher on Google, and attract more potential clients.
-
Who actually does the work on my engagement?
You'll work directly with senior security practitioners. Every engagement is led by an experienced vCISO who understands security, compliance, audits, and enterprise customer requirements. When specialized expertise is needed, we bring in trusted specialists while maintaining a single point of contact throughout your engagement.
-
Are your vCISOs trained and certified?
Yes. CloudSapio is led by CISSP-certified security professionals with experience building security programs across SaaS, healthcare, fintech, AI, and other regulated industries. We are also a verified Vanta service provider with expertise across leading compliance frameworks and security best practices.
Vendors FAQs
-
How long does SOC 2 take with Vanta and CloudSapio?
Most companies reach SOC 2 Type I in roughly 6–10 weeks from kickoff, depending on how mature your existing controls are. Type II then requires an observation window — commonly 3 to 12 months — during which Vanta collects evidence continuously in the background.
-
Do I need a partner, or can I do Vanta myself?
You can absolutely run Vanta yourself, and some teams should. A partner makes sense when nobody internally owns compliance, when a deal is blocked on a deadline, or when the engineering time it would consume is worth more than the engagement fee.
-
What does Vanta cost, and is CloudSapio extra?
Vanta is licensed separately from our services, priced primarily by company size and the number of frameworks you’re pursuing. Our implementation and advisory fees are quoted per engagement based on scope. We give you both numbers together on the first call so you see the total.
-
Does Vanta actually get me certified?
No — Vanta is compliance automation software, not an audit firm. An independent CPA firm (SOC 2) or accredited certification body (ISO 27001) issues the certification. Vanta prepares and maintains the evidence; CloudSapio prepares you and your organization; the auditor issues the report.Because we're experienced. Because we know what we're doing, and because we genuinely believe we can help you rank higher on Google, and attract more potential clients.
-
We already use Vanta but it’s a mess. Can you take it over?
Yes. Remediation of a stalled or misconfigured Vanta instance is one of our most common engagements. We audit the current configuration, re-scope the controls, clear the failing checks, and take you into the audit.
-
Which frameworks does Vanta support?
Vanta supports SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS, CMMC, and a range of additional standards and custom frameworks. CloudSapio advises on which ones your buyers and regulators actually require, so you’re not certifying against three when one would close the deal.
-
How long does SOC 2 take with Dranta and CloudSapio?
Most companies reach SOC 2 Type I in roughly 6–10 weeks from kickoff, depending on the maturity of existing controls. Type II then requires an observation window — commonly 3 to 12 months — during which Drata collects evidence continuously without ongoing effort from your team.
-
Do I need a partner, or can I do Dranta myself?
You can run Drata yourself, and some teams should. A partner earns its cost when nobody internally owns compliance, when a deal is blocked on a deadline, or when the engineering hours it would consume are worth more than the fee.
-
What does Dranta cost, and is CloudSapio extra?
Drata is licensed separately from our services, priced primarily by company size and the number of frameworks in scope. Our implementation and advisory fees are quoted per engagement. We give you both figures together on the first call so you're comparing a total, not a starting point
-
Does Drata issue the certification?
No — Drata is compliance automation software, not an audit firm. An independent CPA firm issues a SOC 2 report; an accredited certification body issues ISO 27001. Drata prepares and maintains the evidence, CloudSapio prepares your organization, and the auditor issues the report.
-
Is Thoropass a platform or an audit firm?
Both. Thoropass operates a licensed CPA firm registered with the AICPA alongside its audit platform, so the same organisation delivers the software and the independent assessment. Most competitors provide only the platform and require you to engage a separate audit firm.
-
If Thoropass does the audit, why would I need CloudSapio?
Because your auditor can't remediate the controls it's auditing. Independence standards prevent an audit firm from designing, implementing, or fixing the control environment it will later issue an opinion on. Building that environment — controls, policies, remediation, and readiness review — is separate work, and it's ours.
-
We're pursuing HITRUST and SOC 2 together. Is that realistic?
It depends on whether your bottleneck is getting certified or staying trusted. Vanta and Drata are strongest as fast, focused paths to SOC 2 and ISO 27001; TrustCloud casts a wider net across GRC, security reviews, and vendor risk, which matters more once certification is behind you and questionnaires are the recurring cost. CloudSapio is a certified partner for all three, so we'll recommend based on your stack, your buyers, and your headcount rather than our incentives.
-
How long does a Google Workspace migration take?
Most migrations for companies under 100 users complete within two to four weeks from kickoff, including planning, a pilot group, and full cutover. The variables are mailbox volume, how much history you're moving, and whether you're consolidating multiple domains or tenants.
-
Will we lose email or files during the migration?
No — mail, calendars, contacts, and Drive content migrate with history intact, and we run a pilot group before full cutover to catch problems while they're small. Your old environment stays available in parallel until the new one is verified.
-
Can you migrate us from Microsoft 365?
Yes — Microsoft 365 and Exchange are the most common sources we migrate from, along with legacy IMAP servers and other Google Workspace tenants during acquisitions. Mail, calendars, contacts, and files all transfer.
-
Is Google Workspace secure enough for SOC 2 or HIPAA?
Yes, provided it's configured correctly — Google supports the necessary controls and will sign a Business Associate Agreement for HIPAA, but the default settings are not audit-ready on their own. Two-factor enforcement, admin role separation, external sharing restrictions, audit log retention, and a documented offboarding process all need to be configured deliberately. That configuration is a substantial part of what we do.
-
What's the difference between Microsoft 365 Business Premium and E3?
Business Premium is capped at 300 users and bundles more security capability for the price, while E3 has no seat cap and adds enterprise management, compliance, and voice features. For most companies under 300 staff, Business Premium is the better value — the usual reason to move to E3 is crossing the seat cap or needing a specific enterprise feature.
-
Is E5 worth the upgrade from E3?
It depends on whether you'll deploy what it adds — advanced threat protection, advanced compliance and eDiscovery, identity protection, and Power BI Pro. E5 pays for itself when it replaces third-party tools you're already buying separately, and wastes money when those capabilities sit unconfigured. We model that comparison against your actual stack before recommending it.
-
Is Microsoft 365 secure enough for SOC 2 or HIPAA?
Yes, provided it's configured correctly — Microsoft supports the necessary controls and will sign a Business Associate Agreement for HIPAA, but the default configuration is not audit-ready on its own. MFA enforcement, conditional access, admin role separation, audit log retention, data loss prevention, and a documented offboarding process all need deliberate configuration. That work is a substantial part of what we do.
Frameworks FAQs
-
How long does SOC 2 take?
Type I is typically 8–12 weeks from kickoff to report. Type II adds an observation window, usually three to twelve months, that runs after your controls are in place.
-
Type I or Type II?
Type I confirms your controls are designed correctly at a point in time. Type II confirms they operated correctly over a period. Most customers eventually want Type II. If a deal is blocked now, Type I gets you a report faster and counts as progress toward Type II.
-
How much of my team's time does this take?
Expect two to four hours a week from an engineering lead during remediation, and roughly an hour a week from you for decisions and sign-off.
-
Do we need a compliance platform?
Not to start. If you already have Vanta, Drata, or TrustCloud, we work inside it. If you don't, we will tell you whether one is worth the cost for your size and stage.
-
How long does ISO 27001 take?
Four to eight months from kickoff to certificate for most companies without an existing programme. The main variables are your scope, how much documentation already exists, and how quickly your engineers can close technical gaps.
-
Should we do ISO 27001 or SOC 2?
SOC 2 is what US buyers ask for. ISO 27001 is what UK, EU, and most international buyers ask for. If your pipeline is mixed, we usually recommend starting with whichever is blocking revenue now and building the second on top, since the underlying controls overlap heavily.
-
Can we do both?
Yes, and it is cheaper than running them separately. Once the ISMS exists, most of the evidence a SOC 2 auditor wants is already produced. We scope combined engagements regularly.
-
Can we get HIPAA certified?
No. There is no official HIPAA certification, and any vendor selling one is selling their own badge. What you can have is a documented, defensible programme, which is what customers and HHS actually ask to see. We can also produce an attestation of compliance you can send to prospects.
-
How long does HIPAA take?
Six to ten weeks to a documented programme for most companies, depending on how much PHI mapping is involved and how many technical gaps we find.
-
How much of my team's time does this take?
Expect three to five hours a week from an engineering lead during remediation, and roughly an hour a week from you for decisions and sign-off.
-
Our customer sent us a BAA. Should we just sign it?
Have it reviewed first. Customer BAAs often push obligations onto you beyond what HIPAA requires, including indemnities and notification windows shorter than the law. We review these as part of the engagement.
-
CMMC was paused. Do we still need to do this?
Only part of it was paused. In July 2026 the Department suspended the third-party certification phase and the milestones after it. Self-assessments, SPRS scores, annual affirmations, and DFARS 252.204-7012 remain in force, and the Department has said it will keep enforcing NIST 800-171 through self-assessment and government-led checks. A review is due to report in mid-September 2026. Contractors who stopped work will be behind whatever comes next.
-
Our prime still wants certification. Does the pause override that?
No. Primes can require whatever they want in a subcontract, and many are holding their expectations regardless of the federal timeline. Ask each prime in writing what they still expect and when. The clause on your existing contract also stays until that contract is actually modified.
-
What is a SPRS score and why does it matter?
Six to ten weeks to a documented programme for most companies, depending on how much PHI mapping is involved and how many technical gaps we find.
Industries FAQs
-
When does a SaaS company need a vCISO?
Most often at the first enterprise questionnaire the founder or CTO cannot answer in an afternoon. Second, when a SOC 2 audit lands on the calendar. Third, when the board asks for a documented programme.
-
Do you work with our Vanta or Drata account?
Yes. We administer the platform, set up integrations, move evidence collection toward completion, and turn failing checks into remediation work. The platform records the programme; it does not run it.
-
Can you do SOC 2 and ISO 27001 in parallel?
Yes, and most companies with European deals should. One control set, two outcomes, one engagement.
-
How fast can you start?
Most engagements begin within a few weeks of signing. The discovery call sets the level and first priorities so the scope stays tight.
-
When does a fintech need a vCISO?
Three triggers: a sponsor bank or BIN sponsor diligence package, a PCI scoping decision that will set your compliance burden for years, or an enterprise questionnaire that exposed how thin the programme is.
-
Can you reduce our PCI scope?
Often, and it is the highest-leverage thing we do here. Most companies default to a heavier validation path than their model requires because nobody designed the data flow first. Designing it properly can move you down a tier, and the savings on audit fees and ongoing burden usually exceed our fee within the first year.
-
Do you handle bank diligence questionnaires?
Yes. We answer them, defend the answers on the joint call, and own the security side of the partnership through launch.
-
Do you work with neobanks, BNPL, lending, and BaaS?
Yes. The common thread is bank diligence, PCI scope decisions, and SOC 2 for B2B distribution. The specifics differ: BNPL has different fraud-control expectations, lending has different state regulatory exposure, BaaS has different partner-bank dynamics.
-
What is the difference between HIPAA and HITRUST?
HIPAA is federal law setting baseline expectations for handling PHI, and there is no certificate for it. HITRUST CSF is a private certification that prescribes how to implement those expectations at much higher rigour, drawing in controls from ISO 27001, NIST, and others. Being HIPAA compliant does not make you HITRUST certified — that requires a third-party assessor and a multi-month engagement.
-
Do you handle EHR vendor security reviews?
Yes. The major EHR vendors each run distinct review processes. We answer the questionnaire, defend the answers on the joint call, and own the security relationship until you go live. It is one of the slowest parts of healthcare go-to-market.
-
Do you have experience with PHI on AWS and GCP?
Yes. Both publish HIPAA-eligible service lists and sign BAAs, but the problems that catch healthtech companies are not in the provider documentation. They are in storage policies, key rotation, IAM drift, and default network exposure.
-
Is SOC 2 still enough for AI companies?
It is necessary and no longer sufficient. Buyers assume it and then ask AI-specific questions a SOC 2 report was never designed to answer, including whether customer data trains your models and who sits in your subprocessor chain.
-
What is ISO 42001 and do we need it?
It is the first international certifiable standard for AI management systems — governance over how AI is built, deployed, and monitored, rather than how data is secured. It is voluntary, but enterprise and regulated buyers increasingly require it contractually. The honest answer on timing: pursue it when a buyer names it, an investor asks for it, or the question keeps recurring across deals. Certifying before anyone asks spends real money on a document nobody is checking yet.
-
How long does ISO 42001 take?
Roughly six to twelve months from a standing start. If you already hold ISO 27001, expect that to drop by around a third to a half, because the management system structure and risk methodology are shared.
-
Does the EU AI Act apply to us?
Probably in some form if your output reaches the EU. The transparency obligations under Article 50 — telling people they are interacting with an AI system, labelling AI-generated content — took effect on 2 August 2026 and are live now. The heavier high-risk regime was deferred by the Digital Omnibus: December 2027 for standalone Annex III systems and August 2028 for AI embedded in already-regulated products. The deferral covers the high-risk obligations, not everything, and penalties reach €35 million or 7% of global turnover.
-
Our model provider is compliant. Does that cover us?
No. Their terms govern what they do with data you send them. Your buyer is asking what you do, which provider terms you have actually selected, and whether tenants are isolated from each other. That is your programme to document.