Astra
16-week plan. First 3 decisions:
**1. Scope.** Are we certifying just the production product or the whole company? Recommendation: just product (faster, cheaper, satisfies most enterprise buyers). Locks in 60% smaller audit scope.
**2. Platform.** Vanta ($16K/yr) or Drata ($14K/yr) for control automation. Both connect to AWS, GitHub, Okta. I recommend Vanta if you have 50+ employees, Drata if smaller. They cut prep time from 9 months to 4.
**3. Auditor.** Schedule with Schellman, A-LIGN, or BSI. Stage 1 audit at week 15. They book 8-12 weeks out so we'd start procurement Week 6.
**This week I'll:**
- Draft the SoA mapping all 93 controls to your stack (you review Friday)
- Set up Vanta connectors to GitHub, AWS, Google Workspace
- Generate the 14 required policies, tailored to your 22-person team
**Next 4 weeks:** policies signed, Vanta gap analysis live, ~30-50 Linear tickets opened. By week 8 we should be at 80% controls passing.
Go?