Offices in The Woodlands and Humble, Texas

IT compliance services
that turn requirements into working controls.

Defense contracts, patient records, customer financial data and card payments all come with security rules. Chrysalis puts technical controls in place, documents them and helps you prepare evidence for the review your customer, regulator, insurer, payment processor or contract requires.

  • Cybersecurity Maturity Model Certification (CMMC) readiness for defense suppliers
  • Health Insurance Portability and Accountability Act (HIPAA) security controls
  • Federal Trade Commission (FTC) Safeguards Rule and Payment Card Industry (PCI) controls

What do IT compliance services include?

IT compliance services support your readiness for the security requirements in frameworks such as CMMC, HIPAA, the FTC Safeguards Rule and PCI. Chrysalis maps each requirement to your systems, works through technical gaps such as multi-factor authentication (MFA), encryption, logging and backup, and helps build the evidence customers, regulators, insurers, payment processors or government reviewers may ask for. We help with readiness. We are not an auditor or a certification assessor.

Who we help with compliance

Businesses where a customer, regulator or insurer has started asking for proof.

Defense suppliers and subcontractors

Manufacturers, engineering firms and service companies that handle federal contract information or controlled unclassified information (CUI) and may need cybersecurity readiness for federal defense contracts.

Healthcare providers and their vendors

Practices, labs and the companies that handle patient information for them, all of which have security duties under the HIPAA Security Rule.

Non-bank financial businesses

Mortgage brokers, tax preparers, auto dealers that arrange financing and other businesses covered by the FTC Safeguards Rule.

Businesses that take card payments

Retailers, restaurants and service companies that must meet the PCI Data Security Standard their bank or payment processor requires.

Why compliance work stalls

The rules are written for lawyers and auditors. The work lands on whoever runs IT.

Requirements that do not translate

Frameworks describe outcomes such as access control and audit logging, not which settings to change in Microsoft 365 or on your firewall.

Paperwork that does not match reality

Policies get downloaded from a template, but nobody checks whether the systems work the way the policy says they do.

Controls that drift

MFA gets switched off for one person, a new laptop skips encryption, an old account stays active. Small exceptions pile up between reviews.

What our compliance services cover

Technical controls, documentation and upkeep for the frameworks that apply to you.

Gap assessment

We compare your systems and practices against the framework that applies and list what is missing, ordered by risk and effort.

CMMC readiness

We work through the National Institute of Standards and Technology (NIST) 800-171 controls behind CMMC Level 2, help write your system security plan (SSP) and plan of action and milestones (POA&M), and prepare the evidence your contract currently requires for self-assessment, annual affirmation or government review.

HIPAA security controls

Access controls, encryption, audit logging and backup for systems that hold patient information, plus help with the security risk analysis the HIPAA Security Rule calls for.

FTC Safeguards Rule controls

Multi-factor authentication, encryption of customer information, monitoring and the technical parts of the written information security program the rule requires.

PCI controls

Network segmentation that keeps card payments apart from guest Wi-Fi and office systems, plus firewall rules, patching and access controls that support your PCI self-assessment.

Not sure where you stand?

A complimentary risk assessment is a practical first look at your security gaps before a formal compliance review.

Request a risk assessment

What you gain

  • A clear view of what each framework asks of you and where you stand today.
  • Technical controls that are in place and documented, so the policy matches what your systems actually do.
  • Evidence you can give to a customer, regulator, insurer, payment processor or government reviewer when they ask.

From a Chrysalis client.

Impact Church of The Woodlands, on the security updates and recommendations Chrysalis provides.

Read more client stories
“Chrysalis has greatly enhanced our IT operations and overall security posture. Their team consistently provides updates on our security status and offers clear recommendations to strengthen our current practices. Their proactive communication and support have given us confidence that our systems are being properly maintained and protected”
Impact Church of The Woodlands

How compliance readiness works

The frameworks differ, but the work follows the same four steps.

  1. 1

    Scope

    We confirm which rules apply, which systems and data they cover, and what your customers or regulators expect.

  2. 2

    Assess

    We check your current controls against the requirements and rank the gaps.

  3. 3

    Remediate and document

    We put the technical controls in place with your team and record how each one works.

  4. 4

    Maintain

    We watch for drift as people, devices and systems change, and update the evidence before each review.

Frequently asked questions

What businesses ask before they start compliance work.

Can Chrysalis certify us or make us compliant?

No. No IT provider can make you compliant on its own, and Chrysalis is not an auditor or a CMMC certification assessor. We put technical controls in place, help with documentation and work with you on readiness. The result depends on your contract, your self-assessment and affirmation where CMMC currently requires them, and your policies and people as well as your systems. Your organization remains responsible for deciding which laws, regulations, contract terms and industry standards apply to it.

What CMMC level do we need?

Your contracts decide. Companies that handle only federal contract information generally need Level 1. Companies that handle CUI generally need Level 2, which follows the NIST 800-171 controls. Check the clauses in your contracts or ask your prime contractor, and we can help you read them.

Does HIPAA apply if we are not a medical practice?

It can. Companies that handle patient information for a healthcare provider, such as billing, IT or transcription vendors, are business associates under HIPAA and have security obligations of their own.

Will Chrysalis sign a business associate agreement?

Yes. Chrysalis signs business associate agreements with its healthcare clients. HIPAA calls for one between a healthcare provider and any IT provider that handles patient information on its behalf.

Who does the FTC Safeguards Rule cover?

Non-bank financial businesses such as mortgage brokers, auto dealers that arrange financing, tax preparers and some accounting firms. It requires a written information security program supervised by a Qualified Individual, plus controls such as multi-factor authentication, encryption and regular monitoring or testing.

How long does compliance readiness take?

It depends on where you start and which framework applies. A gap assessment shows the size of the job, and we give you a plan and timeline after that, not before.

Find out where you stand

Tell us which framework you are working toward and what your customer, insurer or regulator has asked for. We will explain what a readiness project would involve before you commit. Call sales at 713.575.2608.

Ready to get started? Let’s talk.