Get in touch

Contact Us

Talk with RESTIV about the compliance requirement in front of your organization, the evidence you already have, and the practical work needed to move forward.

Start with the requirement

Use the form to tell us what is driving the conversation: a customer request, defence contract, board priority, audit finding, renewal, or the need to build a program from the ground up. You do not need a finished scope or a complete control inventory before contacting us.

What to include

  • The framework or certification you are considering, if known.
  • Your target date, contract milestone, audit stage, or customer deadline.
  • Where you are stuck: scoping, gap assessment, remediation, evidence, questionnaires, or ongoing control testing.
  • Who needs to be involved, such as security, finance, IT, legal, procurement, or executive leadership.

What happens next

RESTIV will review the context you provide and use it to structure the next conversation. The goal is to clarify the applicable requirement, identify the most important unknowns, and determine whether you need readiness guidance, a managed compliance program, continuous evidence support, or a more focused assessment.

Bring the framework. Or bring the question.

If you are comparing requirements, RESTIV can help separate what is mandatory from what is useful, map overlapping controls, and focus the first phase of work on the evidence and decisions that matter most.

CMMC

Assess the CUI boundary, the required CMMC level, current NIST SP 800-171 alignment, evidence gaps, and preparation for the applicable assessment path.

CPCSC

Clarify the Canadian defence-supplier requirement, the relevant CPCSC level, protection of Specified Information, and overlap with a CMMC program.

ISO 27001

Define the information security management system scope, understand existing policies and risk practices, and identify what is needed for certification readiness.

SOC 2

Review the service boundary, customer expectations, Trust Services Criteria, control ownership, and the evidence needed to prepare for an examination.

Common questions before you contact us

Do we need to know which framework applies?

No. Share the contract, customer, regulatory, or assurance need that started the conversation. RESTIV can help you compare CMMC, CPCSC, ISO 27001, and SOC 2 based on that context.

Can finance and security join the same conversation?

Yes. Compliance decisions affect risk, operating cost, contract access, staffing, and audit scope. Bringing CISO, CFO, compliance, IT, or procurement perspectives together can make the initial assessment more useful.

What if we already have policies and evidence?

Describe what exists and where it lives. RESTIV can help assess whether the current material supports the target requirement, where evidence is incomplete, and which controls need operational follow-through.

Can RESTIV help after readiness work?

RESTIV supports organizations that need more than a one-time checklist, including managed compliance work, evidence organization, control testing, remediation planning, and security questionnaire support where appropriate.

Our Office

Visit us at our headquarters or use the form above to start a compliance conversation with our team.

Address

101-119 6 Ave SW

Calgary, AB, Canada

T2P 0P8

Business Hours

Monday - Friday: 9:00 AM - 5:00 PM

Saturday - Sunday: Closed

Contact Information

Ready to clarify your compliance path?

Share the requirement, deadline, or open question you are working through. RESTIV will use that context to make the first conversation specific to your organization.