Home: Northstar Security Advisors
Northstar Security Advisors

Security assessment

A 2 to 3 week review of your security against NIST CSF, CIS Controls or SOC 2, delivered as a written report with a ranked list of fixes.

Length
2 to 3 weeks
Price
$15,000 to $30,000
First 30 days
The report is delivered by day 21 and the readout is booked the same week.

Who this fits

An assessment fits SaaS companies that want a clear baseline before committing to a larger program. It is often requested before a board security review, after an incident, or to size the work ahead of SOC 2. The report is written so your team can act on it with or without Northstar.

What is included

  • Framework choice: NIST CSF 2.0, CIS Controls v8, or SOC 2 criteria
  • Review of existing policies and documentation
  • Interviews with 3 to 5 people
  • Configuration review of your cloud, identity and source control settings (no penetration testing)
  • A 15 to 25 page report with a ranked list of fixes
  • A one-hour readout with your leadership team

The first three phases

Every Assessments engagement opens with the same phases of the Northstar Maturity Framework.

  1. 1Discovery 2 weeks

    Data-flow map, frameworks in scope, and where your program stands today.

    You keep: Discovery Document, 6 to 12 pages

  2. 2Roadmap 1 week

    Prioritized work with owners and a budget, reviewed with your leadership team.

    You keep: 12-month roadmap

  3. 3Build 8 to 16 weeks

    Policies written, controls configured, and your compliance platform collecting evidence.

    You keep: Policies, controls and evidence collection in place

Other services

  • Part-time CISO (vCISO)

    Mara joins your leadership meeting every week, owns the security roadmap, and answers customer security questions for you.

    Length
    6 to 18 months
    Price
    $8,000 to $18,000 a month
  • SOC 2 readiness program

    A 90-day program that takes you from no formal compliance work to ready for a SOC 2 Type II audit window.

    Length
    90 days to audit-ready
    Price
    $40,000 to $75,000, fixed after scoping
  • Security awareness training

    Live onboarding sessions, quarterly phishing tests and short monthly scenarios, written for engineering-heavy teams.

    Length
    12 months, renewed yearly
    Price
    $24,000 to $48,000 a year

Common questions

Anything else goes on the fit call, or email hello@northstar-demo.example.

A vCISO engagement is $8,000 to $18,000 a month depending on scope. A SOC 2 readiness program is $40,000 to $75,000 for 90 days. An assessment is $15,000 to $30,000. You get a written scope and a fixed price after the fit call, before anything is signed.

90 days from kickoff to audit-ready if you already have cloud infrastructure, source control and single sign-on in place. Starting from scratch takes 4 to 5 months. The audit window itself adds 3 to 12 months for Type II, set by you and your auditor.

Northstar works with SaaS companies under 200 employees, including B2B fintech. Hardware, government contractors and companies over 250 people get a referral to a firm that specializes in them.

It takes 30 minutes. Mara asks what is driving the work, such as a deal, an audit date, an incident or a board request. If Northstar fits, you get a written scope and price within three business days. If it does not, she names a firm that does.

Mara Chen, on every engagement. Northstar does not subcontract. Penetration tests are run by an outside firm you contract directly, and Mara coordinates them.

Yes. When a client is ready, Mara helps write the job description, sits in on interviews, and hands over the program. The engagement has a 30-day exit clause for this.

Most clients move to a one-day-a-month retainer covering quarterly reviews, preparation for the annual audit, and incident response readiness.

Book a 30-minute fit call with Mara.

Tell her what is driving the work. If Northstar fits, you get a written scope and price within three business days.

Book a 30-minute fit call