cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Pedro
Newcomer I

Recommendation for NIST auditor

We have a software product that is subject to a 'hybrid' NIST audit, and the quotes we are getting do not seem to fit the scope of work. Our responsibility is only 63 controls, but (in some cases) the quotes we are getting would appear to include hundreds of hours. They are truly all over the place.

 

Looking for a recommendation for a reasonable audit group that might give this better consideration. Perhaps, the groups we are contacting just have more work than they need... 

 

Thanks! 

2 Replies
wimremes
Contributor III

Are we talking about NIST 800-53? Are there any requirements regarding the auditor from the customer?

 

Feel free to DM me. I can put you in touch with my US-based colleagues who regularly work on this type of projects.



Sic semper tyrannis.
Kingsdajo
Newcomer I

I trust you will post more like that later on. Appreciative for sharing such mind blowing information.