Industries we serve

Same compliance company. Ten industry playbooks.

vCISO Lite is a company, not a tool. Our compliance platform runs the continuous mechanics: evidence collection, framework attestation, quarterly delta reports. Our Other20 advisory team runs the human work: pre-bind calls, questionnaire completion, tabletops, incident response. Both know the specific playbook for your industry, because SOC 2 for a health-tech company reads different than SOC 2 for a marketing agency, and Coalition’s underwriting questions aren’t OCR’s.

100M+

Americans whose PHI was exposed in the Feb 2024 Change Healthcare breach, the largest HIPAA breach in US history and the moment every health-tech vendor’s BAA got re-read.

HHS Office for Civil Rights breach portal, 2024

Jul 2023

NYC Local Law 144 enforcement began, mandating bias audits for automated hiring tools. Colorado AI Act followed May 2024 with enforcement in Feb 2026.

NYC DCWP; Colorado SB 24-205

4 days

SEC-mandated Form 8-K cyber-incident disclosure window since Dec 2023. The deadline that made every public issuer’s auditor, counsel, and carrier formalize incident-response programs.

SEC Final Rule 33-11216

Jan 2026

DORA now fully applies across EU financial services and their critical ICT third parties (cloud, SaaS, MSPs). Named-vendor liability is real EU law, and every US carrier, auditor, or advisor touching an EU financial client is inside its scope.

DORA, EU Regulation 2022/2554

Pick your industry

What one program looks like when it’s tuned to your world.

Every industry we serve has a different auditor asking, a different buyer worrying, a different regulator writing rules. Here’s what the platform runs and where the vCISO shows up, for each.

Tech startups
SOC 2 ready in weeks. vCISO on the enterprise call.
Platform runs the evidence collection continuously. Other20 vCISO shows up for the first Fortune 500 security review your team hasn't sat through before.
Read the startup program
HR-tech companies
SOC 2 plus the AI-hiring compliance layer.
Five regulators, one program: enterprise SOC 2, NYC LL 144 bias audit, Colorado AI Act impact assessment, BIPA consent design, EEOC Title VII posture. Other20 vCISO drafts the bias-audit response.
Read the HR-tech program
Cyber-insurance buyers
The evidence bundle Coalition, Cowbell, and At-Bay all read.
Platform assembles the cryptographic evidence bundle. Other20 vCISO joins your broker for the pre-bind call. Two weeks off the application cycle. Fifteen percent off the premium.
Read the insurance program
Health-tech companies
HIPAA risk analysis filed. vCISO on the OCR inquiry.
Platform runs continuous HIPAA and HITRUST evidence and files the risk analysis. Other20 vCISO handles the OCR letter the day it arrives, not two weeks after.
Read the health-tech program
Accounting firms running cyber-attest
Every client, every framework, one console.
Platform runs SOC 2, ISO 27001, PCI QSA, HITRUST, and FedRAMP engagements side by side. Other20 vCISO backs your QSA on the calls that need judgment.
Read the audit-firm program
Law firms
ABA MR 1.6(c) documented. Bar-counsel packet ready.
Platform documents reasonable efforts continuously. Other20 vCISO drafts the bar-counsel response the day someone asks. The next SIG on Tuesday, the next cyber renewal in Q4, all defensible.
Read the law-firm program
Marketing agencies
Fortune 500 SIG answered in hours.
Platform assembles the audit pack from continuous evidence. Other20 vCISO fills the questionnaire fields your team doesn't know. Enterprise deals stop stalling on security review.
Read the marketing-agency program
EdTech companies
FERPA and COPPA ready. vCISO answers the district RFP.
Platform runs continuous FERPA, COPPA, and CIPA evidence. Other20 vCISO fills the district's security RFP the same week it lands.
Read the edtech program
Manufacturing / Defense Industrial Base
CMMC Level 2 ready when the prime asks. C3PAO briefing done.
Platform runs continuous evidence against all 110 NIST 800-171 Rev 3 controls, SSP + POA&M current. Other20 vCISO walks the C3PAO assessment with you. 8-12 weeks to certification-ready.
Read the manufacturing program
Government / Federal SaaS vendors
FedRAMP Moderate submitted by Q3. ATO letter by fiscal-year close.
Platform runs continuous 800-53 Rev 5 evidence across all 325 Moderate controls. Other20 vCISO walks the agency sponsor + 3PAO cycle with you. FedRAMP, FISMA, CJIS, StateRAMP.
Read the government program

Why one company fits many industries

The platform runs continuously. The advisory shows up when it matters.

Every industry we serve gets both, tuned to their regulator map.

The mechanics
Platform runs the mechanics.
50+ integrations collect evidence continuously. Framework attestation stays current across SOC 2, HIPAA, ISO 27001, PCI, FERPA, COPPA, and LL 144. Quarterly delta reports and signed evidence exports on demand.
The substance
Other20 handles the substance.
Real vCISOs on your pre-bind calls, application questionnaires, tabletops, incident response, denial-letter walk-throughs. Not a partner-network referral: our people, engaged by the hour on the moments that need judgment.
The line between them
Neither track fakes what the other does.
The platform doesn’t pretend to be a vCISO. The advisory doesn’t hand-jam evidence the platform already collected. Every industry card above shows the honest split for that ICP’s specific work.

The receipts, from our own program

We run the same program we sell.

Both tracks live against our own SOC 2 Type I evidence, not a slide. Here’s what each side has done for the company running this page.

Platform (vCISO Lite)
What the compliance platform runs on us.
  • Evidence collectionContinuous, across the same 50+ integrations we sell.
  • Framework attestationSOC 2 Type I in progress, tracked control by control.
  • Sub-processor registerQuarterly review cadence, delta reports on demand.
  • Signed evidence bundleExportable to auditors, carriers, or enterprise buyers.
Advisory (Other20)
What our own vCISOs run for us.
  • Tabletop exercisesSame cadence we run for clients. Not paperwork walk-throughs.
  • Incident-response drillsReal scenarios against real playbooks, quarterly.
  • Vendor risk reviewsEvery sub-processor onboarding, every renewal.
  • Questionnaire responseBecause someone asks us the same things they ask you.

Both tracks, one accountability chain. See the full posture →

Your industry not listed? Both tracks still work.

Platform runs the compliance mechanics from day one. An Other20 vCISO can join your first hard conversation this week. Two ways in, one program.