nicwerks
COMPLIANCE READINESS · HIPAA · SOC 2 · CMMC · FTC SAFEGUARDS

compliance you can hand to an auditor.

Gap assessments, policies, written information security plans, evidence collection, and insurer questionnaires — readiness support that describes how your firm actually operates.

WHAT YOU GET

What nicwerks actually delivers.

01

Gap assessment

A plain-English review of how client data actually moves through your firm, mapped against the framework you need — with a prioritized fix list.

02

Written information security plans

FTC Safeguards WISPs drafted side-by-side with your operations team — plans that describe reality, not a template nobody has read.

03

Policies & procedures

Privacy, security, acceptable-use, and disaster recovery policies — written, reviewed in working sessions, and kept where your team works.

04

Control implementation

Encryption, MFA, least-privilege access, EDR, logging — the technical controls frameworks require, actually deployed and maintained.

05

Insurer questionnaires

Cyber-insurance applications answered accurately with evidence attached — before renewal deadlines make it urgent.

06

Audit preparation

Evidence collection, documentation review, and working alongside your auditors and counsel so examinations hold no surprises.

IN PRACTICE

A WISP that actually got written.

CASE STUDY · ENCURIO LLP · TAX & ACCOUNTING

FTC Safeguards, done properly.

Tax professionals are required to maintain a written information security plan — and most WISPs are templates nobody has read. nicwerks took Encurio through the real thing: a compliance review of how client data actually moves through the practice, a WISP drafted side-by-side with operations, alignment with the firm's insurance requirements, and the pieces most firms skip — a disaster recovery plan and privacy and security policies — refined over working review sessions.

“Working with Nick is the best. Relaxed, calm, and always takes the time to explain the technical stuff. He’s an essential part of our team.”
Mallory Sage · Operations Manager, Encurio · Quotient review
FTC SAFEGUARDS REVIEW
WISP DRAFTING
DISASTER RECOVERY PLAN
PRIVACY & SECURITY POLICIES
INSURANCE ALIGNMENT
AN HONEST FIT CHECK

Is this the right compliance help for you?

A strong fit if you are…

A tax or financial practice that needs a real WISP; a firm whose clients or insurers are asking security questions; a practice preparing for SOC 2 or CMMC; or anyone whose current “compliance” is a binder nobody has opened since it was printed.

Probably not a fit if…

You need the certification audit itself (we prepare you for auditors, we don't replace them), formal legal opinions (that's your counsel), or a checkbox PDF by Friday with no intention of implementing anything — we don't write fiction.

COMMON QUESTIONS

What buyers ask first.

What's the difference between readiness and certification?

Readiness is doing the work — controls, policies, evidence. Certification is an independent auditor attesting to it. We do the first and prepare you for the second; a readiness partner who also graded the exam wouldn't be worth much.

Does my firm really need a WISP?

If you prepare taxes or handle consumer financial data, yes — the FTC Safeguards Rule requires a written information security plan, a designated security coordinator, and specific controls. IRS guidance points preparers to the same requirement.

How long does it take?

A WISP engagement typically runs several working sessions over one to two months — assessment, drafting, review, rollout. SOC 2 and CMMC readiness are longer arcs, depending on your starting point; the gap assessment gives you the honest timeline.

Will this satisfy our cyber-insurance carrier?

Carriers ask about specific controls — MFA, EDR, backups, training, plans. Readiness work produces exactly the documentation those questionnaires want, answered accurately with evidence behind every yes.

get audit-ready before it's urgent.

Book a free compliance gap review — we’ll tell you exactly where you stand, in plain English.

Book a gap review →