Practical Compliance. Real Impact.

Get Compliant.
Stay Compliant.

Impact Risk Advisors helps organizations build, implement, and maintain practical cybersecurity compliance programs across SOC 2, ISO 27001, HIPAA, NIST, and GLBA.

Whether you need to establish a compliance program or keep an existing program operating, we provide experienced support from initial readiness through ongoing compliance management.

SOC 2|ISO 27001|HIPAA|NIST|GLBA

The compliance road: from Non-Compliant through Risk Assessment, Implement & Remediate, Audit Ready, and SOC 2 Compliant to Impact Managed Compliance
Your compliance journey - Where are you today? Organizations that need to get compliant (SOC 2, ISO 27001, HIPAA, NIST, GLBA) move through Readiness & Implementation, while organizations with an established compliance program go directly to Impact Managed Compliance. Both paths lead to Impact Managed Compliance, offered as Impact Maintain (support for your internal compliance owner) or Impact Manage (your outsourced compliance function).

Not Sure Which Level Is Right for You?

Compare Impact Maintain and Impact Manage to see what's included in each service.

Compare Managed Compliance Options

Readiness, Implementation & Internal Audit

Build the Right Compliance Program From the Start.

Impact Risk Advisors helps organizations assess requirements, identify gaps, develop policies and controls, manage risk, address readiness issues, and establish the documentation and processes needed to operate an effective compliance program.

Implementation services are tailored to your actual environment rather than built around generic policies and checklists.

SOC 2 Security Implementation

Starting at$14,500

SOC 2 Security readiness and implementation, including scope definition, gap assessment, risk assessment, policy and control development, remediation guidance, evidence requirements, and audit readiness.

Standard Scope: SOC 2 Security Trust Services Category only.

Learn About SOC 2 →

GLBA Safeguards Rule Implementation

Starting at$13,500

GLBA Safeguards Rule implementation, including risk assessment, information security program development, safeguards, policies and procedures, service provider oversight, remediation planning, and supporting compliance documentation.

Standard Scope: FTC Safeguards Rule.

Learn About GLBA →

HIPAA Security Rule Implementation

Starting at$15,000

HIPAA Security Rule implementation, including the Security Risk Analysis, risk management, administrative, physical and technical safeguards, security policies and procedures, remediation planning, and supporting compliance documentation.

Standard Scope: HIPAA Security Rule.

Learn About HIPAA →

NIST SP 800-53 Rev. 5 Implementation

Starting at$18,000

NIST SP 800-53 Rev. 5 implementation, including scope and baseline definition, control tailoring, gap assessment, policy and control development, implementation guidance, remediation tracking, and supporting compliance documentation.

Standard Scope: One agreed NIST SP 800-53 Rev. 5 control baseline for one defined in-scope environment.

Learn About NIST →

ISO 27001 Implementation

Starting at$25,000

ISO/IEC 27001:2022 ISMS implementation, including scope definition, risk assessment and treatment, Statement of Applicability, policies and procedures, control implementation guidance, required ISMS documentation, and certification readiness.

Standard Scope: One defined ISMS and certification scope.

Learn About ISO 27001 →

ISO 27001 Internal Audit

Initial Certification Internal AuditStarting at $3,500
Years 2 & 3 Surveillance Cycle Internal AuditStarting at $2,500

Independent ISO/IEC 27001:2022 internal audit to evaluate the ISMS against applicable requirements, document audit results, and identify nonconformities and opportunities for improvement in preparation for certification or surveillance audits.

Standard Scope: One defined ISO 27001 ISMS and certification scope for an organization with 1–20 employees. Larger or materially more complex ISMS scopes may require adjusted pricing.

Learn About ISO 27001 Internal Audits →

Pricing & Scope

Implementation starting prices are based on one framework, organizations with 1–20 employees, one primary in-scope environment, and typical small-business technology and operational complexity.

Final pricing is based on scope and may increase for larger organizations, multiple entities or environments, additional frameworks, additional SOC 2 Trust Services Categories, complex infrastructure, significant remediation requirements, or other material increases in scope.

ISO 27001 Internal Audit pricing assumes one defined ISMS and certification scope for an organization with 1–20 employees. Larger or materially more complex scopes may require adjusted pricing.

Implementation and internal audit pricing does not include independent SOC examinations, ISO certification body audits, or other third-party audit, examination, or certification fees.

Impact Managed Compliance

Getting Compliant Is Only the Beginning.

Controls need to operate. Policies need to stay current. Risks change. Vendors need review. Evidence needs to be maintained. Findings need remediation. Auditors and customers come back.

Impact Managed Compliance provides ongoing support to keep your compliance program operating, current, and ready throughout the year.

Impact Maintain

Support for Your Internal Compliance Owner

For organizations that have someone internally responsible for compliance but need experienced support maintaining the program.

Impact Manage

Your Outsourced Compliance Function

For organizations that want Impact Risk Advisors to take a more active role managing the ongoing compliance program.

Managed Compliance pricing is based on one primary compliance framework, organizations with 1–20 employees, one primary in-scope environment, and a defined standard scope.

Standard framework scope generally includes SOC 2 Security only, HIPAA Security Rule, FTC GLBA Safeguards Rule, an agreed NIST SP 800-53 Rev. 5 baseline, or one defined ISO 27001 ISMS scope.

Additional frameworks, SOC 2 Trust Services Categories, entities, environments, significant vendor volumes, extensive security questionnaires, or other material increases in scope are priced separately.

Why Impact Risk Advisors

Practical Compliance. Experienced Guidance.

Tailored, Not Generic

Policies, risks, controls, and compliance activities are developed around your actual organization, systems, and requirements rather than generic templates.

More Than Control Monitoring

We help with the work behind the framework, including policies, risk assessments, control design, evidence, vendor risk, remediation, and audit readiness.

Technology Flexible

Already have a GRC platform? We can work within it. Need one? We can help implement and administer it. Don't need one? We can manage the program without requiring expensive dedicated compliance software.

Experienced Guidance

Senior-level experience across cybersecurity compliance, IT audit, risk management, security governance, and assurance.

Louis Van Der Westhuizen, Founder of Impact Risk Advisors

Founder-Led Expertise

Nearly Two Decades of Audit, Risk & Compliance Experience

Impact Risk Advisors was founded by Louis Van Der Westhuizen, bringing nearly two decades of cybersecurity, IT audit, risk management, and compliance experience, including leadership experience within major assurance and advisory practices.

CISSPCISACIAISO 27001 Lead Auditor

Impact Risk Advisors combines senior-level compliance expertise with specialized resources where needed, providing experienced support without the overhead and complexity of a large consulting firm.

About Impact Risk Advisors

Ready to Make an Impact on Your Compliance Program?

Whether you need to build a compliance program or keep an existing program operating, start with a conversation about where you are today.

Schedule a Consultation