Frequently Asked Questions

Everything we get asked, answered honestly. Most of these came from real customers.

Pricing & licensing

1. How much do these packages cost?

FrameworkLiteStandardPro
NIST CSF 2.0$49$79$129
PCI DSS v4.0$59$89$149
HIPAA$59$99$159
All 3 Bundle$129$249

Pro tier is the most popular for organizations actually implementing — it's the tier that includes the full policy set, risk matrix, and implementation roadmap.

2. Is there a refund policy?

Yes. 30-day, no-questions-asked money-back guarantee. Email support@dorseyreports.com from the address you used for purchase, and we'll process the refund within 5 business days. No forms, no friction.

3. What does "lifetime access" mean?

You permanently own the version you purchased. When that version is updated for major regulatory changes (NIST CSF revisions, new PCI DSS minor versions, HHS guidance updates), you receive the update for free as long as the underlying framework is the same major version. A move to a new major version (e.g., a hypothetical NIST CSF 3.0) is treated as a new product with a discounted upgrade path for existing customers.

4. Can I use these for multiple clients (MSP / consultant use)?

The standard license covers one organization. For multi-client use, contact us about MSP / volume licensing — pricing is structured per-client at a fraction of typical consultant rates and includes:

  • Multi-org licensing terms
  • Co-branding option for client deliverables
  • Priority support
  • Quarterly framework update calls

Volume packages start at 10 clients.

5. Can I resell these as my own?

No — direct resale, repackaging as your own product, or distributing the unmodified files is prohibited. However: consultants and MSPs may customize the documents for individual client engagements, deliver tailored versions as part of their services, and charge for that work. The license you're buying is to use the documents as the foundation of your work, not to substitute them for our work.

Customization & format

6. What formats do I get?

Every package includes:

  • Markdown (.md) — easy to edit, diff, version-control
  • PDF — for distribution and audit evidence
  • Word/.docx — for editing in Microsoft Office workflows

Open and edit in any tool you like. The Markdown source is the canonical format; PDF and Word are generated from it.

7. Are the policies fully customizable?

Yes. They're written to be edited. Bracketed placeholders ([Company Name], [Effective Date]) make obvious where your details go. Section structure, terminology, and specific control values (password length, retention periods, review cadences) can all be adjusted to fit your environment as long as you don't drop below regulatory minimums.

8. How long does it take to customize for my organization?

Typical experience:

  • Solo practice / startup: 1–2 days of focused work to customize all policies
  • Mid-market organization: 1–2 weeks with stakeholder reviews
  • Enterprise: 2–4 weeks with legal review and approval workflows

The package replaces drafting time, not review time. Internal review is on you.

Audit & compliance

9. Will this package pass an external audit?

The artifacts are designed to be audit-ready. But: passing an audit depends on:

  1. Customizing the documents to actually reflect your environment
  2. Implementing the controls described in the policies
  3. Generating evidence that you operate those controls (logs, screenshots, training records, scan results, etc.)

The package gives you (1) a head start on documentation and (2) a clear list of evidence to collect. Operational reality is on you.

10. Do you provide audit support?

Pro tier includes email support for 30–60 days depending on the framework — useful for "how should I handle X" questions while you're customizing. Hands-on audit support, sitting next to you while a QSA or OCR investigator is in the room, is a separate service. Contact us if you need it.

11. How does this compare to your competitors (template sites, consulting firms)?

Generic templates ($20–40)Consulting firm ($25K–$200K)Us
Audit-ready depthNoYesYes
All artifactsNoYesYes
Editable Markdown sourceNoNoYes
Mapped to specific citationsNoYesYes
Worked risk-matrix scenariosNoYesYes
Cost$20–40$25K–$200K$49–$159
Customization speedDaysMonthsDays

We sit between "cheap and generic" and "expensive and bespoke." For most organizations, that's the right place.

Updates & currency

12. How often are the packages updated?

  • Material regulatory changes: updated within 60 days, free for existing customers
  • OCR / SSC bulletins and guidance: incorporated quarterly
  • Editorial improvements: continuous; existing customers can re-download from the same Gumroad link

13. How will I know when there's an update?

Email notification to the address you purchased with. Also visible from your Gumroad library — the file timestamp updates when we ship a new version.

Specific to each framework

14. (NIST) Is this NIST CSF 2.0?

Yes — aligned with the 2024 update, including the new Govern function as the sixth top-level domain.

15. (PCI) Is this PCI DSS v4.0?

Yes — current with v4.0 and tracked for v4.0.x bulletins. Includes all the v4.0 expansions: MFA across all CDE access, payment-page script integrity (Req 6.4.3), anti-phishing technical controls (Req 5.4.1), Targeted Risk Analyses, customized vs. defined approach.

16. (HIPAA) Does this cover HITECH and the Omnibus Rule?

Yes. Business Associates and their subcontractors are treated as directly liable per HITECH/Omnibus, breach-notification timelines are included, and BAA terms reflect post-2013 requirements.

17. (HIPAA) Does this satisfy the Security Rule risk analysis requirement?

The package gives you the methodology, the matrix, and 10 worked examples. Operating the analysis — identifying your specific assets/threats and getting leadership signoff — is your work, as OCR expects. The package shaves weeks off that effort.

18. (NIST) Will this help with FedRAMP, CMMC, or ISO 27001?

NIST CSF maps naturally to NIST SP 800-53 (which underpins FedRAMP) and CMMC, and overlaps significantly with ISO 27001 Annex A. The package is a strong starting point for those programs but isn't a one-to-one replacement — those frameworks have specific deliverables (FedRAMP SSP, CMMC SSP+POAM, ISO Statement of Applicability) that you'll need to layer on top.

19. (PCI) Do I still need a QSA or ASV?

Depends on your level. ASV scans are required quarterly for almost everyone with internet-facing CDE — those are external. QSA-attested Reports on Compliance are required for Level 1 merchants and most service providers; smaller merchants typically self-assess via SAQ. The package supports both paths and includes guidance on selecting both.

20. Can the SaaS dashboard replace these download products?

No — they're complementary. The downloads are the artifacts (policies, checklists, roadmap). The SaaS dashboard is the operating layer (track progress, generate reports, manage evidence over time). Many customers buy the download to start, then add the dashboard once they're past initial implementation.

Support

21. How do I contact support?

22. Do you offer custom work?

Yes — engagements include:

  • Customization workshops (your stakeholders + our team) to tailor the package to your environment
  • Mock-audit / readiness assessment
  • Fractional / virtual CISO services for ongoing program operation
  • MSP partnership programs

Contact sales@dorseyreports.com with your scope and we'll scope and quote.

Still have a question? Email support@dorseyreports.com — we read everything, and many of the FAQs above came from real customer questions.

Ready to get started?

Browse frameworks, compare tiers, or jump straight to the dashboard.

View Pricing Start Assessment