Your obligations are continuous. Most engagements are not.
Compliance does not end at handoff. FedRAMP requires monthly scanning and POA&M management. SOC 2 Type II is assessed across an observation window, not a moment. HIPAA requires ongoing evaluation. But the engineering that satisfies those obligations usually stops the day a project closes, and the system starts drifting away from the documentation that describes it. This is the engagement that keeps them in agreement.
Quarterly assessment refresh included
The obligations that do not pause.
This is not a maintenance plan invented to create recurring revenue. Each of these is a continuous requirement of the framework itself.
Continuous monitoring is mandatory: monthly vulnerability scanning, POA&M management, and significant-change reporting. An ATO is harder to keep than to get.
Assessed over an observation window of six to twelve months. Controls have to hold for the entire period, not on the day the auditor looks.
The Security Rule requires periodic evaluation as the environment changes. Every architecture change is a re-evaluation trigger whether or not anyone files one.
What drift actually looks like.
Nothing dramatic happens. Someone adds a managed service that is not in the boundary. A retention policy gets relaxed to save storage cost. A role picks up a permission during an incident and keeps it. A pipeline stage gets bypassed for a hotfix and the bypass stays.
Each is reasonable in isolation. Together, over two quarters, they are the gap between your control narrative and your running system, and they surface at the worst possible time: during an assessment, or in a customer security review attached to a deal you were about to close. Drift is cheap to catch monthly and expensive to catch annually.
What the retainer covers.
Control drift detection
Monthly review of infrastructure state against the control baseline we established, with a written delta showing what moved and what it affects.
Evidence review
Confirmation that logging, retention, and audit trails are still producing what an assessor will ask for, and that nothing has silently stopped emitting.
Remediation of small findings
Drift that can be fixed inside the monthly scope gets fixed, not just reported. Anything larger is quoted separately before work starts.
Quarterly assessment refresh
Every third month, a fuller pass against the framework: updated control mapping, refreshed narratives, and a current findings list.
Auditor and security-review support
When an assessor or a customer's security team sends questions, you have an engineer who already knows the system and can answer in their language.
Architecture review on change
Before you add a service, region, or data flow, a review of what it does to the boundary. Cheaper than discovering it afterward.
What it is not.
- Production on-call, incident response, or an uptime SLA
- Break-fix support for application defects
- Unlimited engineering hours under a monthly cap
- Policy authoring, workforce training, or vendor risk management
- A replacement for your GRC platform or your assessor
If you need any of those, say so on the call. Some we can scope separately, and some we will point you elsewhere for. A retainer that quietly absorbs work it was never sized for goes bad for both sides within a quarter.
Who this fits.
The natural fit is a team that has just finished a build, ours or someone else's, and now owns a system with continuous obligations attached to it. The second is a team holding an ATO or a Type II report who has discovered that keeping it is a standing engineering commitment nobody was assigned.
If we have not worked together, start with the Two-Week Audit. It gives us the map we need and gives you a roadmap you own regardless of what happens next.
Questions.
Do I have to have worked with you before?
Is this a support contract or an SLA?
What if we need more work than the retainer covers?
Can we cancel?
How is this different from a GRC platform?
Who actually does the work?
Talk about a retainer.
Thirty minutes. Tell us what you are holding, what changed since your last assessment, and who currently owns keeping it defensible. If a retainer is not the right instrument, we will say so.
Book a 30-minute call →