CISA-Led NIST CSF Audit
Budget: $1,500 – $3,000 USD
We are a two-employee SaaS startup preparing for our first full-scale assessment against the NIST Cybersecurity Framework and I need a CISA-certified consultant who has already carried out internal NIST audits and can share redacted examples of past reports.
The engagement will focus on all five CSF Functions—Identify, Protect, Detect, Respond and Recover—with an emphasis on practical, actionable findings that map directly to our SaaS architecture (AWS) and cloud-native workflows.
What I expect from you
• A clear audit plan scoped to our size and risk profile
• Evidence-based control testing and gap analysis for the five Functions above
• A concise executive report plus a technical remediation roadmap, both suitable for board and engineering audiences
• Post-audit support: walkthrough of findings, prioritised recommendations, and ad-hoc advisory hours as we close gaps
Strong written and spoken English is essential; most of our collaboration will be remote and documentation must be client-ready. If the first engagement runs smoothly, I’d like to establish a long-term relationship for future maturity assessments and continuous improvement cycles.
Please confirm your CISA status, briefly outline your NIST CSF audit approach, and attach or link to prior sample work (redacted is fine). I’m ready to start as soon as we find the right partner.
The engagement will focus on all five CSF Functions—Identify, Protect, Detect, Respond and Recover—with an emphasis on practical, actionable findings that map directly to our SaaS architecture (AWS) and cloud-native workflows.
What I expect from you
• A clear audit plan scoped to our size and risk profile
• Evidence-based control testing and gap analysis for the five Functions above
• A concise executive report plus a technical remediation roadmap, both suitable for board and engineering audiences
• Post-audit support: walkthrough of findings, prioritised recommendations, and ad-hoc advisory hours as we close gaps
Strong written and spoken English is essential; most of our collaboration will be remote and documentation must be client-ready. If the first engagement runs smoothly, I’d like to establish a long-term relationship for future maturity assessments and continuous improvement cycles.
Please confirm your CISA status, briefly outline your NIST CSF audit approach, and attach or link to prior sample work (redacted is fine). I’m ready to start as soon as we find the right partner.
Related categories:
Health & Medicine
Audit
Compliance
Risk Management
Documentation
Cloud Security
Data Protection