Qantid
Class ADocumentation and assessment

Secure SDLC Programme Design

A secure development lifecycle your engineering team will actually follow, with the gates placed where they catch problems rather than where they slow releases.

Fee & intake

Sign in to see the engagement fee (plus 7.5% VAT), complete the intake form, save a draft if you need to, then pay to submit.

Standard
5 business days
Express
3 business days

Regulatory and standards basis

This engagement is performed against the following instruments. Each is cited in the deliverable at the point it is relied on.

  • OWASP Software Assurance Maturity Model
  • NIST SP 800-218 Secure Software Development Framework
  • PCI DSS v4.0.1 Requirement 6

Who this is for

  • Product engineering teams in regulated firms

What you receive

  1. 01Secure SDLC policy with stage gates and exit criteria
  2. 02SAST, DAST and SCA tooling design and pipeline integration plan
  3. 03Threat modelling procedure and templates
  4. 04Secure coding standards and code review checklist

How the engagement runs

  1. Phase 1

    Intake

    You complete a structured intake form and upload supporting documents. Autosaved, so it can be finished across several sittings.

  2. Phase 2

    Evidence review

    We review what you have provided and raise a document request list for anything material that is missing. We do not guess at gaps.

  3. Phase 3

    Analysis and drafting

    Your documents and answers are assessed against the applicable control universe. Findings are recorded with an evidence reference or explicitly flagged as an assumption.

  4. Phase 4

    Quality review

    A named reviewer works through every finding and section, and a partner approves. Their name and credentials appear on the report.

  5. Phase 5

    Delivery

    The deliverable is released in the portal within 5 business days of payment. Two revision rounds are included.

Questions

Who approves the deliverable?

A named member of the engagement team reviews it and a partner approves it. Their name, title and credentials are printed on the report, and the approval is recorded against the engagement in the portal.

What happens if we disagree with a finding?

You raise a review from the deliverable page, selecting the specific finding or assumption you are challenging and attaching supporting evidence. Two revision rounds are included. Factual corrections and any error on our side never count against those rounds and are never billed.

How quickly can this be turned around?

Standard delivery is 5 business days from payment. Express delivery in 48 to 72 hours is available when selected at intake.

Where do our documents live?

In private storage, accessible only through short-lived signed links, with every view and download logged. Nothing is attached to email. Our sub-processors and data residency are published on the trust page.

How do we pay?

By card through Stripe after you complete intake in the portal. You can save a draft without paying; submission happens only after payment succeeds.

Related engagements in Cybersecurity and Assurance

Business Continuity and Disaster Recovery Plan

Continuity and recovery planning built from a business impact analysis, with recovery objectives that reflect what your infrastructure can actually deliver.

CBN Risk-Based Cybersecurity Framework Assessment

An assessment against the CBN Risk-Based Cybersecurity Framework, producing the evidence base for your annual return.

Incident Response Plan and Playbooks

An incident response plan with scenario playbooks, written so an on-call engineer at 3am can follow it.