How is a Rapid Assessment different from an ongoing GRC engagement?
+
A Rapid Assessment is fixed-price and fixed-scope: it benchmarks one part of your environment and ends in a report. Ongoing GRC support, including vCISO advisory, continues past that point for organisations that want continuous governance leadership rather than a single benchmark.
Which frameworks does Tecala benchmark against?
+
Tecala’s Rapid Assessments benchmark against ISO 27001, the NIST Cybersecurity Framework and the Australian Essential 8, depending on which assessment you choose.
How long does a Rapid Assessment take?
+
Policy Review runs over 7 days. NIST CSF Rapid and Essential 8 Rapid each run over 2 weeks.
Do we need an existing compliance program to start?
+
No. Rapid Assessments work for organisations validating a mature program and for those benchmarking their governance for the first time.
What happens after the assessment?
+
You’ll have the option of a follow-up consultation to walk through the findings. Many organisations use that conversation to scope a broader GRC uplift or ongoing vCISO support, and each Rapid Assessment can be credited toward the matching Full Assessment if you decide to go deeper.