Common questions
Straight answers to compliance questions
The questions SMBs actually ask us before signing up. No hedging, no marketing spin.
Getting Started
Which Scarlet Risk tier fits my company size?
Under 10 employees or just exploring: Scarlet Go ($25/mo). 10–50 employees with a real audit or enterprise deal in play: Scarlet Pro ($99/mo). 50–200 employees or multiple frameworks: Scarlet Elite ($250/mo). 200+ or multi-entity/MSP: Scarlet Team ($500/mo). Switch tiers any time.
How long does setup actually take?
First value in less than 20 minutes — sign up, pick your frameworks, and the platform generates your policy set, risk register scaffold, and initial posture score. A full baseline (vendor list, evidence uploads, initial gap analysis) is 1–2 hours of your time spread over the first week. No implementation project.
Do I need to talk to someone before signing up?
No. Every tier — Go, Pro, Elite, and Team — is fully self-serve. Pick your plan, enter a card, and you're in. If you want a live walkthrough before deciding, we offer them, but they're never required and there's no gatekeeping.
Can I switch tiers later?
Yes, any time, from Settings → Billing. Upgrades are prorated and take effect immediately. Downgrades take effect at the end of the current billing period so you don't lose paid time. No penalty, no phone call, no retention gauntlet.
What happens after I complete the Discovery Questionnaire?
You get an instant recommendation on-screen — the tier we'd suggest, the frameworks in scope for your stage, and the 3–5 things to prioritize first. A copy is emailed to you. No sales rep will call you unless you explicitly book a call from the results page.
Is there a contract or minimum commitment?
No. Monthly plans are month-to-month and cancel any time from Settings. Quarterly (5% off) and Annual (15% off) plans are optional discount cadences — you choose them, they're not required, and they still don't require a signed contract.
How is this different from hiring a compliance consultant?
A typical SMB compliance consultant runs $150–$300/hour and $30k–$80k for an initial engagement. Scarlet Risk starts at $25/mo, is live the same day, and stays in place after — so evidence keeps flowing between audits instead of expiring with the consultant's contract.
SOC 2
Do I need SOC 2 to sell to enterprise customers?
For most B2B deals over $100k ACV, yes — SOC 2 is a hard revenue gate. Below $100k, security questionnaires often work as a substitute. Above $250k, Type 2 (not Type 1) is usually required. Start Type 1 the moment enterprise deals enter your pipeline.
How long does SOC 2 take for a startup?
Type 1: 8–12 weeks for a prepared 20-person SaaS team with modern cloud infra. Type 2: add a 3–12 month observation window on top. Most startups target Type 1 first to unblock deals, then roll straight into Type 2.
What happens if I fail a SOC 2 audit?
You don't 'fail' SOC 2 like a certification exam. Auditors issue one of four opinions: unqualified (pass), qualified (some exceptions), adverse (systemic failure), or disclaimer (couldn't complete). A qualified report can still support enterprise deals if the exceptions are narrow and remediated.
How often do you recertify SOC 2?
SOC 2 is not a one-time certification — it's an annual attestation. Type 2 reports typically cover a rolling 12-month window and are re-issued each year. Most enterprise buyers require your report be dated within the last 12 months to remain valid for procurement.
HIPAA
CMMC
Is CMMC required for prime contractors and their subcontractors?
Yes. CMMC 2.0 flows down from prime contractors to every subcontractor that touches Federal Contract Information (FCI, Level 1) or Controlled Unclassified Information (CUI, Level 2). If your contract references DFARS 252.204-7012, you almost certainly need CMMC.
Do I need a vCISO for CMMC?
CMMC does not require a vCISO. But for Level 2 assessments, most SMBs without a full-time security lead benefit from a fractional CISO for 4–6 months during prep — especially through the POA&M and evidence phases. Beyond that, tooling replaces most of the ongoing work.
What is a POA&M in CMMC?
A POA&M (Plan of Action & Milestones) is a formal document capturing control gaps and the plan to close them. Under CMMC 2.0, POA&Ms are permitted at Level 2 assessment — but only for a limited set of controls, and every POA&M item must close within 180 days of assessment.
ISO 27001
Cost & Tooling
Have a question we didn't answer?
Book a live 20-minute walkthrough and we'll answer it in context.
