Market leaders choose Johanson Group:
























Experienced Practitioners
Our audit team brings decades of combined experience across security and compliance frameworks — seasoned practitioners, not junior staff learning on your engagement.
Platform Experts
Former GRC platform experts on staff. We audit inside your existing tools — no manual exports, no spreadsheets.
Integrated Audits
Your CSM and audit project lead guide the engagement from kickoff to final report — one seamless experience.
Expert Network
Tap into our trusted ecosystem of MSP and vCISO partners to strengthen your full security posture — not just your audit.
Our services
Frameworks for Government & Public Sector
Government and public sector organizations operate under a distinct set of compliance obligations — driven by federal law, contract requirements, and the sensitivity of the data and populations they serve. Here is every framework Johanson Group covers for this industry, organized by what drives the requirement.
NIST 800-53
The comprehensive security control catalog for federal information systems — mandatory for federal agencies under FISMA and for cloud service providers seeking FedRAMP authorization. 1,196 controls across 20 families organized into Low, Moderate, and High impact baselines.
- Low (125 controls), Moderate (287), and High (370) impact baselines
- FedRAMP Moderate and High authorization both based on 800-53 baselines
- Annual continuous monitoring required following Authority to Operate (ATO) issuance
- All 20 control families from Access Control to Supply Chain Risk Management
- Required for any cloud service provider selling to US federal agencies
NIST 800-171
Required for any contractor handling Controlled Unclassified Information (CUI) under DFARS 252.204-7012. 110 security requirements across 14 families — and the foundation of CMMC Level 2. SPRS score submission to the DoD database is required before any contract award or renewal.
- 110 requirements across 14 control families covering all CUI protection areas
- SPRS score submission required before every contract award or renewal
- POA&M required for all deficient requirements with realistic remediation timelines
- Inaccurate self-assessment scores create False Claims Act criminal exposure
- Third-party assessment produces a defensible, documented score for government scrutiny
HIPAA Assessments
Federal and state government healthcare programs — Medicare, Medicaid, VA, DoD healthcare — involve protected health information governed by HIPAA. Government healthcare vendors and contractors handling PHI must comply with all three HIPAA rules and execute BAAs with every covered entity client.
- BAAs required with every government healthcare agency before any PHI is shared
- Security Rule: administrative, physical, and technical safeguards for all ePHI
- Breach notification to HHS and affected individuals within 60 days
- Annual Security Risk Analysis required — documented and defensible
- 2025 proposed Security Rule update: all safeguards mandatory if finalized in 2026
GDPR Assessments
Government contractors and agencies operating internationally or processing data from EU residents — including defense partners, foreign aid programs, and international government operations — face GDPR obligations regardless of their US government affiliation. GDPR applies based on where data subjects are located, not where the organization is based.
- Applies to any processing of EU residents' personal data regardless of organization location
- Data Processing Agreements required with all EU-based clients and subprocessors
- Data subject rights: access, deletion, and portability within 30 days
- 72-hour breach notification to supervisory authority — documented process required
- DPIAs required for high-risk processing activities involving EU personal data
CCPA Assessments
Government contractors and agencies operating internationally or processing data from EU residents — including defense partners, foreign aid programs, and international government operations — face GDPR obligations regardless of their US government affiliation. GDPR applies based on where data subjects are located, not where the organization is based.
- Applies to any processing of EU residents' personal data regardless of organization location
- Data Processing Agreements required with all EU-based clients and subprocessors
- Data subject rights: access, deletion, and portability within 30 days
- 72-hour breach notification to supervisory authority — documented process required
- DPIAs required for high-risk processing activities involving EU personal data
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."
.avif)
"Johanson Group has performed all of our SOC audits professionally, communicated well during the engagement, and delivered the reports within the expected time frames."

"The auditors we worked with were focused, friendly, and professional. We've spoken to many companies in this area before deciding for Johanson Group."
.png)
"They set clear expectations around the audit process and were very flexible working around our schedules. Johanson Group was a true partner. Very flexible and communicative throughout our audit process.""
.png)
"The coordination from their account management to the actual auditors and then the final follow-up on the operational and finance side was very well coordinated and seamless. It's very easy to work with them, and they create a lot of predictability in achieving our desired business outcomes."

"The communication has been great, and we have a very good portal to manage our data on, which altogether works out best for us. We appreciate everything they offer as part of our audit process."

"I truly appreciate Johanson Group's affordable pricing, which was a significant factor in my decision to transition from another provider. Overall, my experience with Johanson Group has been positive, as evidenced by my willingness to rate them a perfect 10 for recommendations."



.png)
.jpg)
.avif)

