arclightcompliance.com
SENIOR-LED GRC CONSULTING
Most companies hire junior consultants and call it GRC. Arclight puts a senior CISSP-certified practitioner on your program from day one.
CISSP · SSCP · CySA+ · Security+ · Juris Master in Cybersecurity · NIST · SOC 2 · FedRAMP
WHAT WE DO
Every engagement is led personally by Anthony Addison — CISSP, former Director of GRC, and compliance practitioner with 15+ years in the field.
GRC PROGRAM DESIGN
Gap assessments, risk registers, control frameworks, and policy suites — built to last, not to check a box.
SOC 2 READINESS
From gap assessment through Type II audit — fixed fee, senior practitioner, every session.
VIRTUAL CISO
Board reporting, vendor risk, incident response planning — the strategic security voice your company needs, fractional.
FEDRAMP ADVISORY
SSP development, control narrative writing, 3PAO prep, and authorization support for cloud providers targeting federal markets.
THE ARC MODEL
The Arc Model moves every client from scattered controls to a defensible, scalable compliance program.
PHASE 01 — FOUNDATION
Current-state assessment, gap analysis, and control framework selection. We know where you are before we plan where you’re going.
PHASE 02 — GROWTH
Policy buildout, control implementation, evidence collection, and team enablement. The scaffolding goes up.
PHASE 03 — PEAK
Audit readiness, auditor liaison, and certification delivery. You cross the line audit-ready — not scrambling.
PHASE 04 — EVOLUTION
Ongoing program management, continuous monitoring, and regulatory horizon-scanning. Compliance as a living system.
ENGAGEMENTS
FOUNDATION
SOC 2 program
Gap assessment through audit-ready, fixed fee.
ADVISORY RETAINER
per month
Ongoing compliance leadership — vCISO-level access without the full-time hire.
CUSTOM ENGAGEMENT
scoped to your situation
FedRAMP, HIPAA, CMMC, custom frameworks, or multi-standard programs. We scope it together.
Book a free 30-minute scoping call. No pitch deck, no pressure — just a senior practitioner who can tell you exactly what your program needs.