When this workstream fits
Determine the relevant baseline and evidence gaps before commissioning changes or making assurance claims.
Use this page to describe a requirement, then validate the delivery model with Atlant Security. Start from the systems you use and the responsibilities already assigned to your team or other providers.
What to specify in the proposal
- Scoped current-state assessment
- Prioritised improvement and evidence plan
- Management summary and clear assessment limitations
Agree which items are initial project deliverables, which recur and which remain with your organisation. A named owner and acceptance record make each output more useful than a generic promise of protection.
Inputs for a useful conversation
- Reason for assurance and intended audience
- Applicable contracts, frameworks and entities
- Existing assessments and evidence owners
Approximate counts and high-level descriptions are sufficient initially. Detailed configurations, access arrangements and sensitive documents can follow through an agreed confidential channel.
Questions that change the scope
- Which customer, insurer or authority requirement is driving the work?
- Is independent certification or attestation needed from a separate body?
Bring unresolved decisions into the RFP. An unknown is more useful than an invented licence, assumed staffing model or unapproved production change.
Service boundaries to confirm
Readiness work is not certification. Applicability, independence and formal reporting requirements must be resolved for the actual organisation.
Your requirements are not supplier commitments until the relevant proposal and agreement are accepted. Record exclusions, dependencies and how environment changes enter scope.
Published service context
Published service family: Atlant Security source ↗
Build your services RFP to match your platforms and support needs, or send an enquiry with your NDA or RFP.

