Skip to content

Compliance Is Evidence, Not Intent

HIPAA, SOC 2, and CMMC readiness — technical controls implemented, documentation written, and evidence collected continuously, so an audit becomes a retrieval exercise instead of a scramble.

All services

45 min · Free · No commitment

HIPAA
Security Rule technical safeguards
SOC 2
Trust services criteria support
CMMC
Level 1 and Level 2 readiness
Sound familiar?

The policy binder nobody could produce evidence for

Most compliance efforts begin with a template policy set purchased from a vendor, and end there. The documents state that access is reviewed quarterly and backups are tested. Then an auditor asks for the last four quarterly access reviews, and there is nothing to hand over — because the policy was written and the practice never actually started.

This fails in the direction that costs the most. You have paid for the framework, told clients you are compliant, and answered a questionnaire in good faith — and the finding surfaces during an audit, a breach investigation, or an insurance claim, when it is both expensive and public.

Facet MSP works the technical half: implementing the controls the framework genuinely requires, generating evidence continuously as a byproduct of operating your environment properly, and telling you plainly which parts are legal or organizational work that we are not the right party to do.

What's included

Controls implemented, evidence collected

01

Gap Assessment Against a Real Framework

We map your current state against the specific framework you are pursuing, not a generic checklist. The output separates technical gaps we can close from the policy and organizational work that needs your decision-makers in the room.

02

Technical Safeguard Implementation

Access control, encryption at rest and in transit, audit logging, MFA enforcement, automatic session termination, and device controls — the concrete requirements sitting underneath the framework language.

03

Continuous Evidence Collection

Access reviews, patch compliance, backup restore tests, and security training completion all recorded as they happen. Evidence generated as a byproduct of operations is the only kind that reliably survives an audit.

04

Written Policies That Match Reality

Policies describing what your environment actually does. A policy that overstates your controls is worse than having none, because it documents a failure to follow your own stated procedure.

05

Business Associate & Vendor Support

For HIPAA, tracking which vendors touch protected health information and whether agreements are in place. For SOC 2, the vendor management evidence auditors reliably request.

06

Audit Preparation & Support

When the auditor or assessor arrives, we assemble the technical evidence, answer the infrastructure questions, and remediate findings within scope. You are not left translating auditor language on your own.

07

Annual Review Cadence

Frameworks are not one-time projects. Risk assessments, policy reviews, and control testing on a schedule, so you do not rediscover the requirement three weeks before a renewal deadline.

What you'll notice

An audit becomes a retrieval exercise

  • Evidence exists because it was collected, not reconstructed
  • Policies describe what your environment genuinely does
  • Technical safeguards are implemented and verifiable
  • You know which gaps are ours and which are legal or organizational
  • Client security questionnaires get accurate answers
  • Renewal is a review rather than a project
Why Facet

We will not tell you that you are compliant

No MSP can certify your compliance.

Compliance is determined by an auditor, an assessor, or a regulator. We implement and evidence the technical controls — anyone claiming to make you compliant is misrepresenting what they sell.

Evidence is a byproduct, not a project.

If producing your access reviews requires a two-week scramble, the control is not really operating. We build collection into normal operations so the record simply exists when asked for.

We name what sits outside our scope.

Business associate agreements, workforce sanctions, breach notification decisions — these are legal and organizational. We tell you clearly rather than quietly leaving the gap.

Questions

Compliance questions

Can you make us HIPAA compliant?

No provider can. HIPAA compliance spans administrative, physical, and technical safeguards plus legal agreements and organizational policy. We implement and evidence the technical safeguards and support the rest — and we are specific about that boundary, because vendors who blur it leave their clients exposed.

We are pursuing SOC 2. Where do you fit?

We handle the infrastructure and security controls an auditor will test — access management, logging, encryption, change management, backup testing — and produce the evidence continuously. You will still need an auditor, and usually a compliance platform. We work alongside both rather than replacing either.

What is CMMC, and does it apply to us?

It applies if you handle federal contract information or controlled unclassified information, typically as a defense supply chain contractor. Level 1 is achievable for most small businesses; Level 2 is substantially heavier. We assess which one applies before anybody spends money on it.

We already have policy templates. Is that enough?

Templates are a reasonable starting point and worse than nothing if left unaligned with reality. The failure mode is a policy claiming quarterly access reviews you have never performed, which documents your own non-compliance. We align the documents with what actually runs.

Our client sent a security questionnaire we cannot answer.

Send it to us. Most of the questions concern technical controls we either operate or can assess quickly. Where the honest answer is no, we will tell you what closing that gap involves so you can decide whether the contract justifies the spend.

Let's talk

Ready to take this off your plate? Six questions.

Spend 90 seconds answering. We'll spend a few hours putting together a written assessment of where your IT stands — and a 45-minute call with one of our engineers.

Or call · (323) 510-1984