VERITY · COMPASS

VERITY COMPASS

Your next client is going to ask for proof.

Will you have it?

Continuous compliance management for regulated mid-market organizations. NIST, CMMC, HIPAA, SOC 2, ISO 27001, PCI DSS — one dashboard, one named advisor, audit-ready every day of the year.

Compliance frameworks are tightening in 2026. CMMC, HIPAA, PCI DSS, EU AI Act — all moving from policy review to evidence review.

Insurers void policies if requirements aren’t met. Enterprise clients require vendor compliance proof. Non-compliance costs 2-10x more than compliance.

6+

Frameworks covered

70%+

Evidence auto-collected

90+

Policy templates included

$249

To get compliant today

What VERITY Compass delivers

VERITY Compass is Armorstack’s continuous compliance management service for regulated mid-market organizations. Rather than treating compliance as an annual audit fire drill, Compass runs as a year-round program with real-time control evidence collection, gap remediation tracking, and executive-ready reporting. Every control maps to one or more frameworks — NIST CSF 2.0, HIPAA, SOC 2 Type II, CMMC 2.0, ISO 27001, PCI-DSS — so a single piece of evidence satisfies multiple audits. The goal is auditor-ready posture every day of the year, not a 90-day sprint before each examination.

Compass is run by Armorstack VERITY advisors with CISA, CDPP, and CISM credentials. Clients receive a named advisor, quarterly steering committee reports, and 24/7 access to the compliance dashboard. Evidence collection is automated where possible (cloud configuration, IAM audit logs, SIEM data) and supplemented with structured workflows for procedural controls that can’t be automated.

Who VERITY Compass is for

Compass is built for three common situations: (1) organizations in their first formal compliance program — usually SOC 2 Type II or HIPAA — who need structure and expertise without hiring a full-time compliance team; (2) mid-market firms with an existing compliance program that’s drifting because it depends on one person or a quarterly consultant scramble; (3) multi-framework environments where manual evidence collection has become unsustainable (for example: a healthcare system handling HIPAA, SOC 2, and HITRUST simultaneously, or a defense contractor layering CMMC 2.0 on top of NIST 800-171).

Typical client profile: 75-500 employees, regulated industry (healthcare, financial services, defense, legal, SaaS), annual revenue $10M-$250M, existing IT/security team of 1-5 that needs augmentation rather than replacement.

What’s included

A Compass engagement includes: (a) initial control maturity assessment against the primary framework; (b) multi-framework control crosswalk (so HIPAA controls also satisfy SOC 2 and ISO where they overlap); (c) System Security Plan (SSP) or equivalent authoring and maintenance; (d) continuous evidence collection via the Compass dashboard; (e) gap remediation project management with monthly status; (f) quarterly executive steering reports; (g) pre-audit readiness assessment 90 days before each formal examination; (h) vendor risk management (TPRM) for in-scope third parties; (i) policy and procedure library maintenance; (j) named Armorstack VERITY advisor accessible via email, phone, and scheduled working sessions.

Engagement model

Compass is a retainer-based subscription with three tiers: Foundation (single framework, quarterly cadence, suitable for first-time compliance clients); Multi-Framework (two to three frameworks with a unified control crosswalk); and Enterprise (four or more frameworks, weekly cadence, embedded advisor). All tiers include the compliance dashboard, named advisor, and executive reporting. Pricing is annual with no long-term lock-in; clients can cancel with 30 days’ written notice.

Most clients start with a 60-minute scoping call, followed by a fixed-fee Current State Assessment (2-4 weeks) that produces a gap analysis and implementation roadmap. The retainer begins once the roadmap is agreed.

Cheaper Than One Hour With a Compliance Consultant

The next RFP will ask for your compliance posture. Be ready.

Starter

$249/mo

Single framework + compliance score

  • Real-time compliance score
  • Single framework (NIST/CMMC/HIPAA/SOC 2/PCI DSS/ISO 27001)
  • Policy library access
  • Evidence auto-collection
  • Basic reports

Get Started

★ MOST POPULAR

Professional

$599/mo

Multi-framework + advisor + gap roadmap

  • Real-time compliance scores
  • 6+ frameworks covered
  • 90+ policy templates
  • 70%+ evidence auto-collected
  • Compliance advisor (monthly)
  • Gap roadmap & remediation
  • Quarterly business reviews
  • Audit-ready reports

Get Started

Enterprise

$999/mo

Continuous + 2 hr/mo advisory + audit prep

  • Continuous monitoring
  • All 6+ frameworks
  • Dedicated advisor (2 hrs/mo)
  • Audit preparation support
  • Custom policy development
  • Executive dashboards
  • Incident response guidance
  • Priority support

Get Started

Frequently Asked Questions

Do we need to replace our existing compliance tools?

No. Compass works alongside your existing GRC tooling (Vanta, Drata, Secureframe, ServiceNow GRC, ZenGRC) or runs standalone using Armorstack’s compliance platform. Our advisors are tool-agnostic and will integrate with whatever you already have.

How is Compass different from a compliance consultant?

A consultant engages for a defined project (SSP authoring, audit readiness, framework implementation) and leaves. Compass is a continuous program — your named advisor knows your environment, your auditors, and your control history. When a new framework like CMMC 2.0 is added, there’s no re-learning curve. When your organization changes (new SaaS, new office, new regulation), controls are updated automatically.

What happens during an actual audit?

Your Armorstack advisor is the single point of contact for auditors. We schedule walkthroughs, provide evidence directly from the Compass dashboard, manage auditor questions, and coordinate remediation if any findings occur. Clients typically spend 3-5 hours of leadership time per audit rather than 40-80 hours with the traditional model.

Can Compass handle CMMC 2.0 certification?

Yes. Compass includes CMMC 2.0 Level 1, Level 2, and (roadmap) Level 3 support, including SSP authoring, POA&M management, C3PAO coordination, and post-certification continuous monitoring. Most Level 2 clients reach assessor readiness within 90 days.

How much does Compass cost?

Retainer pricing ranges from $3,500/month (Foundation, single framework) to $15,000+/month (Enterprise, multi-framework, embedded advisor). The initial Current State Assessment is fixed-fee at $9,500-$24,500 depending on scope. All pricing is published; we don’t hide it behind a sales cycle.

The next RFP will ask for your compliance posture.

Be ready with real-time compliance scores across all major frameworks.

Start Your Compliance Score

No long-term contracts. No installs. Cancel anytime.