Skip to content
All insights
AlignMicrosoft SecurityComplianceJuly 22, 2026

Phase 0 for a compliance project: the gap assessment before remediation

The Short Version
  • Phase 0 for a compliance project is a fixed-fee gap assessment and roadmap, because remediation can't be priced until the gaps and the boundary are known.
  • It maps every control to an owner, inherited from Microsoft, operationalized by your IT partner, or your own evidence and procedures.
  • Defining the boundary, the enclave where controlled data lives, is usually the single largest finding, not a footnote.
  • The assessment routinely finds that a framework everyone assumed applied doesn't touch the system in scope, or that the tenant can't support the controls yet.
  • If you proceed with remediation within three months of the assessment closing out, 100% of the fee is credited toward it.
Bottom line: A fixed fee on compliance remediation is only meaningful once someone has defined the boundary and mapped the controls, and the gap assessment is where that happens.

Recently, the owner of a small Navy and marine parts distributor walked us through his plan to meet the Department of Defense's cybersecurity requirements. He had the right instinct, to wall off his controlled data rather than drag the whole company through compliance, but when we asked what the wall did in practice, he was refreshingly direct: they hadn't specced it, and didn't fully understand what that one box was and wasn't allowed to do.

That gap, between knowing you need to comply and knowing exactly what the framework requires of your systems, is what a compliance Phase 0 closes. And until it closes, nobody can put a real fixed fee on the remediation.

What Phase 0 is here

Phase 0 for a compliance project is a fixed-fee gap assessment and roadmap. The worked example throughout this piece is the Cybersecurity Maturity Model Certification (CMMC) and the NIST SP 800-171 controls it is built on, because that is where most of this work lands, but the same discipline applies to HIPAA, SOC 2, and FDA 21 CFR Part 11.

The reason it is a standalone engagement is simple: you cannot quote remediation against controls you have not yet mapped, in a boundary you have not yet drawn. The assessment produces the map. Its output is a documented gap list rated by severity, a remediation roadmap sequenced by risk and effort, and the core compliance documentation, so the follow-on project can be quoted against confirmed scope rather than guessed at.

If you proceed with remediation within three months of the assessment closing out, we credit 100% of the fee toward it. The assessment is groundwork the remediation would have to cover anyway.

What a gap assessment inventories that other Phase 0s don't

  • A control-by-control mapping against the framework, tagged by owner. Every control lands in one of three buckets: inherited from Microsoft's platform, operationalized by your IT partner, or requiring your own evidence and procedures. That shared-responsibility split is the difference between a checklist and a plan, and it is what a remediation quote prices against.
  • The boundary. Where does the controlled data live, and what is in scope versus out. For controlled defense information this is the enclave design; for health data it is wherever Protected Health Information (PHI) flows. Scoping is not a preliminary step to the findings, it usually is the largest finding.
  • The documentation package. A System Security Plan (SSP), a Plan of Action and Milestones (POA&M) for the gaps you can't close immediately, and the supporting policies and procedures.
  • Technical versus administrative controls. Some gaps are a configuration change; many are a written policy, an assigned owner, and evidence that the policy is followed. The assessment separates them, because they get remediated by different people.
  • Whether the tenant can even support the controls. Sometimes the finding is that the environment isn't ready to be remediated yet: a consumer-grade tenant that can't enforce device management, or a commercial tenant where controlled data really needs to sit in a separate Government Community Cloud High (GCC High) tenant.

Note what stays out of scope: the formal certification. A gap assessment is pre-audit readiness. When a Certified Third-Party Assessor Organization (C3PAO) is involved, that engagement is separate, and the assessment is designed to get you ready for it, not to replace it.

What discovery tends to turn up

The most common surprise is that the boundary is fuzzier than anyone assumed, exactly the distributor above, whose plan hinged on a wall he had not yet defined. Pinning that down is where most of the value is.

The second is that a framework everyone assumed applied doesn't touch the system in question. One aerospace-services company came to us flagging four regimes at once. Discovery deflated two of them: its health-data obligation ran through the benefits and human resources relationship, not any patient records, and nothing in its ERP met the definition of controlled defense information, which was almost all engineering data. Two of the four fell away, and the remediation got materially smaller and cheaper. The assessment's first job is often to establish which frameworks reach which systems.

The third is an organization that believed it was close and wasn't. A small research contractor expecting funded defense work was still running on a consumer-grade tenant that couldn't enforce basic device management, which surfaced the day a departing employee kept a laptop nobody could wipe. In that case the roadmap started earlier and moved slower, because the groundwork had to come before the controls.

And sometimes the answer is to live in two worlds at once. A mid-size science and engineering contractor with several hundred people had only a few dozen people handling controlled data, so the design stood up a separate GCC High tenant alongside the existing commercial one rather than dragging the whole company into the stricter environment.

When you don't need one

If you already have a current control mapping, a defined boundary, and your System Security Plan and Plan of Action and Milestones in hand, you don't need someone to produce them. Bring us the remediation project.

The assessment earns its place when the boundary is undefined, when you are not certain which framework touches which system, when you need a fixed fee on remediation, or when a customer requirement, an audit, or an insurer's questionnaire is forcing the question on a timeline.

If that is roughly where you are, bring us the requirement you are being held to and we will walk through what a gap assessment would cover for your environment, and what it would leave for the remediation that follows.

See where you stand. Then move forward.

Book a free intro call. We'll talk through where you are today and map a plan for growth, protection, automation, and alignment.

30 minutesNo obligationGet an initial estimate within one week