Request a proposal
Managed Security
MDR EssentialsMDR CompleteSMB Security EssentialSMB Full Stack Managed SecurityContinuous Compliance (Delve)Security Compliance SuiteSMB Premium + Compliance
Programs
Grid CommandMulti-Modal Threat IntelligencePhishing + Awareness TrainingTrust Center ManagedCompliance Audit + Remediation Project
Compliance Audits
SOC 2 Type I — Prep + Audit (Thoropass)SOC 2 Type II Audit (Thoropass)ISO 27001 Audit (Thoropass)HIPAA Compliance Audit (Thoropass)Full Compliance Build (HIPAA or SOC2)
Trust Center
Cybersecurity Trust Center BuildTrust Center Care Plan
Company
Managed PlansFree AssessmentAboutBlogContactRequest a proposal

Full Compliance Build (HIPAA or SOC2)

From zero to audit-ready: your complete HIPAA or SOC 2 program

Policies, controls, risk management, vendor management, training and continuous evidence, built by TenGrid on Delve or Vanta and handed over as a program your team can run.

$25,000

Reserve your build slot — $5,000 deposit Book a Scoping Call

The $5,000 engagement deposit reserves your audit window and is credited in full against the $25,000 project price. The balance is invoiced after the scoping call, before fieldwork begins. Deposits are refundable if we determine on the scoping call that we are not a fit.

How this is delivered

This program is fulfilled through TenGrid’s white-label platform partners Delve or Vanta (we pick the best fit for your stack on the scoping call). TenGrid scopes, manages and delivers the build; the compliance automation platform, continuous monitoring and evidence collection run on Delve or Vanta. This build is not delivered through Thoropass. When you are ready for the audit itself, the Thoropass-delivered audit offers pick up where this leaves off.

Who this is for

Companies with no existing compliance program that need to be audit-ready for HIPAA or SOC 2 in the next quarter, and want the platform and the people in one engagement.

What’s included

  • Framework scoping (HIPAA or SOC 2) and system inventory
  • Delve or Vanta platform selected, configured and integrated with your cloud, identity, HR and code tooling
  • Complete policy library (20+ policies) drafted, approved and published
  • Control implementation with your engineering and IT team, tracked to zero open items
  • Risk assessment, vendor management and security-awareness training program set up
  • Continuous monitoring and evidence collection live, with a runbook for your team
  • Audit-readiness review and auditor hand-off plan

How it works

  1. Scoping call: framework, platform selection, timeline
  2. Build: platform integrated, policies approved, controls implemented in defined sprints
  3. Prove: monitoring live, evidence flowing, readiness review passed
  4. Handover: runbook and audit plan; optionally continue into a Thoropass-delivered audit

Questions

Timeline?

10–14 weeks.

Is the platform license included?

Platform access is included during the build. Ongoing Delve or Vanta licensing after handover is quoted separately based on company size.

Is the audit included?

No. This is the build. Add SOC 2 Type I, SOC 2 Type II or the HIPAA Compliance Audit when you are ready.

Delve or Vanta?

We recommend one on the scoping call based on your stack, team size and framework. Both are fully supported.

Full Compliance Build (HIPAA or SOC2)

$25,000

Reserve your build slot — $5,000 deposit Book a Scoping Call

The $5,000 engagement deposit reserves your audit window and is credited in full against the $25,000 project price. The balance is invoiced after the scoping call, before fieldwork begins. Deposits are refundable if we determine on the scoping call that we are not a fit.