Frequently asked questions.

Questions we've heard. Answers we'd give honestly over coffee. Organized into six sections so you can skip to what you need.


Don't see your question? Ask us directly

About TACSOP.

What is TACSOP?

TACSOP is a compliance documentation kit. One 174-page implementation guide plus 48 supporting templates. Built around a 90-day program that takes 4-8 hours per week of part-time work. Sized for 5-99 employee businesses with cyber insurance, customer questionnaire, state safe harbor, or audit-prep compliance needs.

What does TACSOP stand for?

Tactical Standard Operating Procedure. The name comes from military doctrine, where a TACSOP is the unit's written set of standard operating procedures for routine operations. The brand reflects what the kit produces: a working set of standard operating procedures for the foundational cybersecurity controls a small business needs.

What framework is TACSOP built on?

CIS Controls v8.1 Implementation Group 1 (CIS IG1), with mappings to NIST CSF 2.0, SOC 2 Trust Services Criteria, and the state safe harbor statutes in Texas, Connecticut, Ohio, and Utah. IG1 is the foundational tier of the CIS Controls and is appropriate for businesses that don't have dedicated security staff.

Does TACSOP make my business compliant?

No. The kit gives you a written program. Compliance requires actually doing what the program says. The kit makes documentation easy; the work of operationalizing the documentation is yours. The implementation guide walks you through the operational work alongside the documentation.

What's the difference between TACSOP and using CIS Controls directly?

CIS publishes the Controls framework free at cisecurity.org. TACSOP isn't a license to use the framework; the framework is already free. What TACSOP saves you is the assembly work: translating framework controls into business-ready policies, customizing 48 templates for a small business context, sequencing the work into a 90-day program, mapping the controls to SOC 2 and the four state safe harbor statutes, and writing the implementation guide that connects all of it. If you have the time and inclination to do that translation yourself, you may not need TACSOP. Most small businesses don't.

Who built TACSOP?

The team at Foxtrot 7 Tech, a Texas IT and compliance consultancy. The kit reflects the documentation Foxtrot's own clients needed in the same order, over and over, until building it once was obviously the right answer.

Buying.

How much does TACSOP cost?

Three public tiers. Self-Service at $499 one-time, Onboarding at $748 one-time, Managed Implementation at $1,999 one-time. All three include 12 months of updates. After the first year, the annual maintenance plan is $99 per year.

Why three tiers if the content is the same?

The tiers vary in how much help you want with the implementation work, not in what you get. Self-Service is the kit on its own. Onboarding adds a one-hour scoping call to confirm your starting place. Managed Implementation adds eight hours of consulting time through Phase 1.

Which tier should I choose?

Self-Service if you have time and a clear starting place. Onboarding if you want a quick human check before you start. Managed Implementation if you want a partner alongside you for the heaviest phase. The pricing page has a side-by-side comparison.

Is there a free trial?

No. The kit is a delivered product, not a subscription, so a trial doesn't fit the structure. A sample chapter from the implementation guide and a sample policy template are both available on the Kit page; the sample content is enough to evaluate whether the voice and depth fit your business.

Do you offer refunds?

Yes. If the kit doesn't fit your business, request a refund within 30 days of purchase. Refunds are full and processed within five business days.

Is the price per business or per user?

Per business. One license covers everyone in your organization who needs access to the kit content.

Can I upgrade to a higher tier later?

Yes. Self-Service to Onboarding is $249 incremental, available within 12 months of your original purchase. Self-Service to Managed Implementation reflects the difference between the two tiers ($1,500). Talk to us first to schedule the consulting time.

Can my MSP or consultant buy this on my behalf?

Yes. The buyer field on the purchase form accepts a different name and email than the licensee. If you're an MSP buying for a client, talk to us first about whether a multi-client arrangement makes sense.

What if I'm a Foxtrot 7 Tech client?

TACSOP is included with Managed Compliance Services. You don't need to buy through the site; your consultant has everything you need.

Implementation.

How long does TACSOP take to implement?

90 days of part-time work, 4-8 hours per week. Roughly 36 to 72 hours of total effort across three months. The first 30 days (Phase 1) are the heaviest; Phases 2 and 3 are lighter and increasingly focused on cadence and maintenance.

Who can be the implementation lead?

One named person responsible for working through the 90-day program. For an owner-operator, this is usually the owner. For a 20-99 employee company, it might be the office manager, operations lead, or IT generalist. For a Foxtrot client, the consultant. Without a named owner, the program drifts.

Do I need a technical background?

No. The implementation guide assumes intelligence but not specialization. The procedures are step-by-step rather than abstract. Buyers without technical backgrounds have implemented the kit successfully; the limiting factor is usually time and owner sponsorship, not technical skill.

Can I buy now and start later?

Yes. Your license key and kit arrive at purchase; you can start whenever your calendar allows. CPA firms typically implement outside tax season, retail outside Q4, schools during summer. The 12 months of included updates run from your purchase date, so buying months before you start means a portion of your update window passes before you begin.

Can I pause once I've started?

Yes. The 90-day timeline assumes consistent weekly effort, but you can pause and resume as needed. Each pause adds calendar time. Resume Phase 1 fully rather than skipping ahead if the pause is long.

Can I run multiple workstreams in parallel?

Yes. The week-by-week structure in Phase 1 is a default, not a requirement. A capable implementer running parallel workstreams can compress Phase 1 to 2-3 weeks of focused effort. The sequencing matters less than the outputs.

What if owner sponsorship isn't in place?

The program will fail without it. Adopting a policy requires owner approval; the program's operational changes require owner backing when they create friction with employees. If the owner won't sponsor, the kit isn't the right solution at this moment, regardless of how good the implementation lead is.

Scope.

I'm a CPA firm. Does TACSOP satisfy the FTC Safeguards Rule?

CPA firms preparing tax returns are financial institutions under the FTC Safeguards Rule (16 CFR Part 314), which requires a written information security program with named coordinators, documented risk assessments, vendor management, employee training, and incident response procedures. TACSOP's policies, procedures, and templates align with each of those requirements. The kit produces the written program the rule expects. Your firm still adopts, customizes, and operationalizes the program; the rule requires doing the work, not just having the documentation.

I'm in Texas, Connecticut, Ohio, or Utah. Does TACSOP satisfy my state's safe harbor statute?

Yes. The kit's CIS Controls IG1 alignment is a recognized cybersecurity framework under each of the four state safe harbor statutes. Texas SB 2610 names CIS Controls explicitly. Ohio SB 220, Connecticut Public Act 21-119, and Utah's Cybersecurity Affirmative Defense Act each accept alignment with a recognized framework. The kit's State Safe Harbor Self-Attestation is the documented attestation that triggers the statutory liability protection in those four states.

I'm a law practice. Does TACSOP satisfy ABA Model Rule 1.1 and Formal Opinions 477R and 512?

The kit's documented procedures address what each of those touchstones describes. Model Rule 1.1's technology competence duty is supported by documented security procedures the firm can point to. Formal Opinion 477R's vendor management expectations are addressed by the kit's Vendor and Third-Party Management Policy and the Vendor Onboarding and Annual Review Procedure. Formal Opinion 512's AI use guidance is addressed by the kit's Acceptable Use Policy and Data Classification and Handling Policy. ABA opinions describe duties; TACSOP gives you procedures that demonstrate the duties are being met. Privilege determinations remain a matter for counsel.

I'm a manufacturer responding to customer security audits. Does TACSOP help?

Yes. The kit's policies and procedures are the documented program a customer auditor wants to see. The Customer Security Questionnaire Response Template lets you populate answers once and reuse them across customers. The Vendor Security Questionnaire (the one you send to your vendors) demonstrates that your supply chain is part of your security program. Customer audits become a presentation of an existing program rather than a project triggered by the audit notice.

Does TACSOP cover AS9100, IATF 16949, ITAR, NIST SP 800-82, or IEC 62443?

No. These manufacturing-specific frameworks need framework-specific work TACSOP doesn't address. TACSOP documents the IT side of your security program. OT and ICS systems (PLCs, SCADA, plant-floor controls) need vendor-specific guidance the kit doesn't replace. If your environment includes OT or specialized industrial systems, talk to us first about whether the kit and the consulting hours are the right fit before you buy.

Is TACSOP enough for SOC 2?

For SOC 2 Type 1, the kit gives you most of the documentation foundation. For SOC 2 Type 2, you need a continuous monitoring platform like Vanta, Drata, or Sprinto. TACSOP is the stage before Type 2; the work you do at TACSOP carries forward to the platform.

Does TACSOP cover HIPAA?

No. The HIPAA Security Rule has framework-specific requirements TACSOP doesn't address. HIPAA-specialized documentation vendors like Compliancy Group and HIPAA One are the right starting place for the framework-specific work. TACSOP can complement HIPAA documentation for secondary compliance needs (cyber insurance, vendor security questionnaires) but doesn't replace the HIPAA-specific work.

Does TACSOP cover NIST 800-171 or CMMC?

No. Defense contractors handling Controlled Unclassified Information need NIST 800-171 specifically. ComplianceForge specializes in CMMC documentation and is the right starting place. TACSOP can complement CMMC documentation if you also have cyber insurance, customer questionnaire, or state safe harbor needs, but it doesn't replace specialized contractor documentation.

What if my business has OT or ICS systems?

TACSOP documents the IT side of your security program. OT and ICS systems (PLCs, SCADA, plant-floor controls) need vendor-specific guidance the kit doesn't replace. Manufacturing-specific frameworks (NIST SP 800-82, IEC 62443, AS9100, IATF 16949, ITAR) need framework-specific work TACSOP doesn't address. If your environment includes OT or specialized industrial systems, talk to us first about whether the kit and the consulting hours are the right fit before you buy.

What about attorney-client privilege at my law firm?

TACSOP doesn't determine privilege questions; those remain a matter for counsel. The kit's documentation is your firm's documentation, written for your business by your business. How privilege applies to the documentation, and to any incident response work that draws on it, is a question for your firm's professional responsibility process.

What if my state isn't Texas, Connecticut, Ohio, or Utah?

The kit's framework alignment still supports general defensibility through documented evidence of due care. The four-state safe harbor protection requires the specific statutes. Consult counsel for state-specific implications outside the four covered states. The implementation guide also notes the safe harbor coverage applies to incidents affecting residents of qualifying states, which matters for multi-state operations.

What if my business operates in multiple states?

The kit's state safe harbor coverage applies to incidents affecting residents of qualifying states. If you operate in multiple states including TX, CT, OH, or UT, the safe harbor protection applies to incidents affecting residents of those qualifying states. The kit's general security program approach supports defensibility regardless of state.

What if my business has more than 99 employees?

TACSOP is sized for 5-99 employees. Companies in the 100-249 range can use the kit with some accommodation. Companies past 250 employees typically need either a vCISO consulting engagement, an enterprise compliance platform, or both. We're happy to refer you to options that fit your size if you ask.

What if I'm pursuing both TACSOP-covered needs and a framework TACSOP doesn't cover?

Most buyers with mixed compliance drivers can use TACSOP alongside specialized framework documentation. A defense contractor with CMMC needs can use ComplianceForge for CMMC and TACSOP for cyber insurance, customer questionnaires, and state safe harbor. A healthcare practice can use a HIPAA-specialized vendor for HIPAA and TACSOP for adjacent needs. TACSOP complements specialized documentation; it doesn't replace it.

Updates and maintenance.

What does the maintenance plan cover?

Every kit update we ship during the year. CIS Controls revisions when CIS publishes them. Updated framework crosswalks when NIST CSF or SOC 2 change. New stakeholder communication templates as buyer patterns surface. New FAQ entries based on what buyers actually ask.

Why is maintenance a separate plan?

Compliance frameworks change. State safe harbor statutes get amended. New threats emerge. The kit you buy on Day 1 should not be the same kit you have on Day 365 of Year 5. The maintenance plan funds the work of keeping the kit current.

How long is my first year of updates?

Twelve months from the date of purchase, included in the purchase price across all three tiers. After that, the maintenance plan is $99 per year and renews automatically.

What happens if I let maintenance lapse?

Your kit content is yours forever. The maintenance plan covers updates. If you let maintenance lapse, you can re-up at any time, but you pay catch-up for missed years (capped at two years). You don't lose what you bought; you just don't get newer versions until you renew.

Can I cancel maintenance?

Yes. Cancel any time from the customer dashboard. No phone call required.

How will I know when there's an update?

Email notification to the address associated with your license key. Updates are typically released annually with patch updates as needed for major framework or threat landscape changes.

What happens when CIS releases a new version of the Controls?

Foxtrot 7 Tech reviews the change, updates the kit's mappings and references, and ships an updated version to maintenance plan customers. Major version changes (e.g., CIS Controls v8 to v9) trigger a substantial revision; minor version changes trigger an update with limited rework.

Service and support.

How is the kit delivered?

A downloadable archive containing every artifact in two formats: editable Word documents for the policies, procedures, and templates, plus Markdown source files for buyers who prefer plain-text editing. The implementation guide is delivered as a PDF for reading plus Markdown for integration. Your license key arrives by email at the address you provide.

Can I customize the templates?

Yes. That's the point. Every policy, procedure, and template is a starting framework; the implementation guide walks you through customizing each one for your business. Names, scope, terminology, signature lines, and operational specifics all get adjusted to fit. You're not adopting Foxtrot's documentation; you're using Foxtrot's documentation as the starting place for yours.

Can my team contribute to the kit content over time? Does it work with version control?

Yes. The Markdown source files are designed for this. Teams that maintain documentation in git, Notion, or similar systems can manage the kit's policies and procedures the same way they manage anything else. Multiple contributors, version history, change review, and integration with existing documentation workflows all work normally because Markdown is just text. The Word versions are provided for buyers who don't have those workflows.

When I buy Onboarding, how does the scoping call get scheduled?

After purchase, a Foxtrot consultant reaches out to schedule the one-hour call. You don't need to book anything at checkout; we'll find a time that works.

What's covered in the Managed Implementation hours?

The eight hours cover Phase 1 work: inventorying your environment, customizing the Phase 1 templates for your business, and working alongside you through the foundational controls (Days 1-30). The specifics of how the hours are scoped and used are worked out on the kickoff call, including whether any time can be banked for later questions. If you'd like to know more before buying, talk to us first.

What if I have a question that isn't in the kit?

Self-Service tier buyers get email support for kit-related questions. Onboarding tier buyers get the same plus the one-hour scoping call. Managed Implementation tier buyers get the same plus the eight hours of consulting time. Foxtrot 7 Tech clients get questions handled through their existing service relationship.

What does the kit look like a year after purchase?

A documented program with a quarterly cadence. Quarterly access reviews, quarterly log reviews, quarterly compliance health checks, annual risk assessment, annual policy review, annual safe harbor attestation update. The implementation guide Section 6 walks through the Year 2+ cadence in detail.

When should I outgrow TACSOP?

When your business passes 100 employees with continuous monitoring needs, when customers demand SOC 2 Type 2 attestation, when regulators require more advanced controls, or when vendor risk volume requires continuous monitoring. TACSOP IG1 graduates to TACSOP IG2 (when available) or to SaaS platforms like Vanta, Drata, or Sprinto.

Still don't see your question? Ask us directly

Didn't find your question?

The FAQ above covers what we hear most often. If your question isn't here, three reasonable next steps.