Menu
Assessments

Know where you stand before you spend.

Three structured, fixed-scope assessments — AI Readiness, Security Posture, and 201 CMR 17.00 — designed to answer the questions every technology leader is already being asked by their board, their auditors, or their counsel. Written deliverable, executive readout, prioritized roadmap.

Two offerings

Fixed scope. Clear deliverable.

All three assessments are priced as fixed-fee engagements with defined deliverable sets. None are discovery calls dressed up as deliverables. You finish each engagement with a written report, an executive readout, and a prioritized roadmap you can execute with or without us.

AI Readiness

Are we actually ready for AI?

A structured evaluation of data readiness, infrastructure fitness, organizational capacity, and use-case viability. Built for leadership teams who have piloted and now need to decide what — if anything — to scale.

What you get
  • Written readiness report across data, infrastructure, governance, and use case
  • Prioritized use-case shortlist with viability scoring
  • Governance gap analysis against NIST AI RMF
  • Executive readout and 12-month implementation roadmap
Duration
2–4 weeks
Engagement
Fixed fee
Audience
CIO, CTO, COO
Security Posture

Where are we actually exposed?

A four-lane assessment — identity and trust, network and firewall, cloud configuration, monitoring and response — aligned to NIST CSF 2.0 and CIS v8. Built for technology leaders who need an honest view before the next audit, board review, or insurance renewal.

What you get
  • Posture report across identity, network, cloud, and monitoring
  • Prioritized findings mapped to NIST CSF 2.0 and CIS v8
  • Threat model of your crown-jewel systems
  • Executive readout and phased remediation roadmap
Duration
2–4 weeks
Engagement
Fixed fee
Audience
CISO, CIO
201 CMR 17.00
Massachusetts

Is your WISP audit-ready?

A compliance assessment across all seven domains of Massachusetts's 201 CMR 17.00 — the regulation that applies if you own or license personal information about any Massachusetts resident. Built for general counsel, privacy officers, and technology leaders who need an honest view before the next audit or breach.

What you get
  • Compliance report against all seven 201 CMR 17 domains
  • WISP gap analysis with prioritized remediation list
  • Executive readout including breach notification readiness
  • Optional WISP drafting or update engagement
Duration
3–6 weeks
Engagement
Fixed fee
Audience
GC, CPO, CIO
How we work

Four phases, no theater.

Every Colossus assessment follows the same operating rhythm. Discovery is bounded. The written deliverable is the deliverable. The roadmap is executable — with or without us.

01
Week 1

Scope & kickoff

Working session with your leadership to lock scope, stakeholders, and success criteria. No moving goalposts once this signs.

02
Weeks 1–2

Discovery

Structured interviews, documentation review, and technical inspection against a fixed framework. Bounded interviews — your team gets their time back.

03
Weeks 2–3

Analysis & synthesis

Findings mapped to the relevant framework. Every finding has a severity, an owner, and an executable next action.

04
Weeks 3–4

Readout & roadmap

Written report, live executive readout, and a prioritized roadmap. Designed to travel — to the board, to insurers, to the next engagement.

Why Colossus

Operators, not slide-makers.

Our assessments are led by practitioners who have run security programs, built AI systems, and defended networks against nation-state adversaries. The deliverable reflects that.

11+ years
Decades of combined operational experience in high-consequence technology environments
Fixed scope
Price and deliverable defined before kickoff. No scope creep invoices.
NIST aligned
Security work maps to CSF 2.0 and CIS v8. AI work maps to the NIST AI RMF.
Executable output
Every finding has an owner, a priority, and a next action your team can run with.
Request an assessment

Tell us a little about the environment.

A Colossus principal will respond within two business days with a short scoping call and a fixed-fee proposal. No automated nurture sequence — every inquiry is read by a human.

We respond within two business days. Your information is never sold or shared.