Skip to content
All services
Cloud foundations & networkingBuild

Guardrails as code and evidence pack

Up to about 30 preventive guardrails for AWS, Azure or Google Cloud, each with a test that proves it refuses a non-compliant change, and evidence mapped to CIS, ISO 27001 Annex A and NIST CSF.

When you need it

Your customers send long security questionnaires, and each answer means another round of screenshots. Your cloud has some policies, but nobody has checked that they block what they claim to block.

What sets the quote

  • One cloud per engagement: AWS, Microsoft Azure or Google Cloud.
  • About 2 weeks for up to 15 preventive controls, and about 4 weeks for up to 30.
  • Where the controls are assigned sets the testing effort: the root and OUs on AWS, management groups on Azure, or the organisation and folders on Google Cloud, with up to 5 assignment points.
  • Pipeline policy checks on Terraform plans, with OPA/Rego and Conftest or with Checkov, in up to 10 repositories.
  • One exception process, agreed with your security owner.
  • Larger control sets, more assignment points or more clouds are quoted after sizing.

What changes

  • Security rules are written, reviewed and versioned as code, and the cloud platform enforces them.
  • Each control has a test that proves it refuses a non-compliant change.
  • Non-compliant infrastructure changes fail in the pipeline, before anyone applies them.
  • You answer security questionnaires with evidence from the platform, mapped to the frameworks your customers ask about.

What you get

  • Preventive controls as code (SCPs and RCPs, Azure Policy or Organization Policy), assigned where you agreed
  • A test for each control that attempts a non-compliant change and records the refusal
  • Pipeline checks with OPA/Rego and Conftest, or Checkov, matching the preventive controls
  • Audit-mode report of existing resources that would break each control, with their owners
  • Exception process with an owner, a reason and an expiry date for each exception
  • Control mapping to CIS Benchmark IDs, ISO 27001 Annex A and NIST CSF
  • Evidence pack for customer security questionnaires
  • Handover session for your platform team

What we build on each cloud

AreaAWSAzureGoogle Cloud
Preventive controlsSCPs and RCPsAzure Policy with the deny effectOrganization Policy constraints, including custom constraints
Assigned atRoot and OUsManagement groupsOrganisation and folders
Before blockingImpact checked against CloudTrail activityAudit effect first, then denyDry-run policy first, then enforced
Proof of refusalTest call denied by the SCP or RCPTest deployment refused with RequestDisallowedByPolicyTest change refused as a constraint violation

Not included

  • Fixing existing resources that break a new control (listed with owners, quoted separately)
  • Certification audits or audit opinions; the mapping shows where you stand, it does not replace an audit
  • Detection rules and alert routing
  • Legal advice on what a framework or regulation requires

What we need from you

  • AWS: AWSOrganizationsFullAccess in the management account, or a delegated administrator for policies, plus a sandbox account for the tests.
  • Azure: Resource Policy Contributor at the management groups in scope, plus a sandbox subscription for the tests.
  • Google Cloud: Organization Policy Administrator at organisation level, plus a sandbox project for the tests.
  • Write access to your infrastructure repositories and CI configuration for the pipeline checks.
  • Your security owner to choose the controls and approve exceptions, about 2 hours a week.

How it works

  1. Free 30-minute call, then a written fixed quote.

  2. Choose the controls that matter most for your customers and risks, and map each one to the frameworks.

  3. Write each control with a test that feeds it a deliberately non-compliant change.

  4. Run in audit mode first where the platform allows it, then switch to blocking.

  5. Assemble the evidence pack and walk your team through it.

At a glance

Duration
2–4 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Assess Popular

Cloud foundation check

In 1–2 weeks, we review your AWS, Azure or Google Cloud foundation against the CIS benchmark and tie every finding to evidence, the affected resources and a fix.

Duration:1–2 weeks
Assess

Zero Trust network review

A one-week review of how traffic enters, leaves and crosses your AWS, Azure or Google Cloud networks, with evidence for every finding, a target Zero Trust design and a prioritised roadmap.

Duration:1–2 weeks
Assess

Migration check

In 1–2 weeks, we assess what you run on-premises or in another cloud, with a migration approach per application, a wave plan and a cost estimate for AWS, Azure or Google Cloud.

Duration:1–2 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.