What the examiner asks for — already written, already mapped.
An SEC examination request list asks for specific things by name: your written policies, your vendor due-diligence file, your training records, your incident response plan. Premium membership is those things, already built. The template library is the same set of policies and frameworks we use in our own consulting engagements. Vendor due diligence comes pre-researched — a 600+ vendor catalog, with independently sourced answers concentrated on the high-sensitivity providers against Reg S-P. Employee training runs on its own and keeps the completion records examiners request. And incident response is covered from both ends: the Plan Builder writes your firm’s plan before you need it, and the Incident Response Assistant walks you through the day you do.
Membership works as a four-step program — Assess your documentation (free), Map your vendors and data, Build the written program, Operate & Respond — backed by three interactive tools, 61 editable templates, FieldCraft training, and the Quarterly External Exposure Snapshot (beta). See how the program works →
Everything a compliance program needs — in one membership.
BrainTrust Premium is more than a document library. It packages the work an SEC-registered firm is most often asked to show: that it vets its vendors, that it trains its people, that its policies are written down and mapped to the rules — and now, tools that build those documents for you.
The Reg S-P vendor program, already built
A living evidence database of 600+ vendors RIAs actually use — CRMs, custodians, planning, portfolio, AI platforms — each scored against a 90-field due-diligence questionnaire. Every answer independently verified from a public source with a citation and capture date, or flagged for direct vendor attestation. Select your stack, print your Rule 204-2 vendor file.
Security awareness, automated
Phishing simulations, quiz tracking, and audit-ready completion reports for up to 50 employees — the training evidence Reg S-P's Safeguards Rule expects.
Your incident response plan, generated
Answer five minutes of questions; the IRP Builder generates your firm's complete Reg S-P incident response plan as an editable Word document — every section mapped to §248.30, with a printable quick-reference card. And if an incident ever starts, the Incident Response Assistant walks you through it live and produces the timestamped record Rule 204-2 expects.
Every policy the request list names
Sixty-one editable Word templates spanning thirteen categories — from the cybersecurity policy manual to exam-production checklists — enough to build the written program end to end.
Adopt AI without failing an exam
The AI Compliance Framework, governance workbook, output validation protocol, and AI marketing claims checklist — plus an AI supplemental track inside the vendor portal.
See what the internet sees — every quarter
A passive scan of your firm’s public exposure — look-alike domains, forgotten subdomains, email-spoofing gaps, exposed services — summarized against Reg S-P and Reg S-ID and delivered to Premium members quarterly. Nothing to install — tell us your domains once and it runs every quarter.
Email support on compliance questions
Members email MTradecraft directly with cybersecurity compliance questions — answers from the practice, not a help desk.
All of it — $2,500 a year, flat. The same library and tools our $36,000 consulting engagements are built on.
The Reg S-P Vendor Due Diligence Portal.
Evidence for the service-provider oversight procedures amended Reg S-P now requires — already researched and continuously maintained. A living database of the vendors RIAs rely on, each scored against our 90-field due-diligence questionnaire, now including an AI supplemental section covering model training, data retention, and AI subprocessors. Every answer is independently verified from a public source (with a link and capture date) or flagged as requiring direct vendor attestation. High-sensitivity vendors are fully covered today; coverage expands continuously.
Maintained as the rules change — and cited to them.
The BrainTrust is not a marketing handout. Every template cites the specific rule it supports — Reg S-P, Rule 206(4)-7, Rule 204-2 — and the library is revised as SEC rulemaking and examination priorities move, so the version you download reflects current requirements.
Cybersecurity Policies & Procedures Manual (Reg S-P), NPI Data Inventory, Access Control & MFA, Annual Risk Assessment, Data Disposal.
Incident Response Plan, Tabletop Exercise Kit, Wire-Transfer & Disbursement Verification — plus the interactive IRP Builder and the live-incident Incident Response Assistant.
AI Compliance Framework & Governance Workbook, AI Output Validation Protocol, AI Marketing Claims Review Checklist.
Vendor Due-Diligence Questionnaire and Confidentiality Agreement — alongside the 600-vendor evidence portal.
206(4)-7 Annual Review, Compliance Calendar, Compliance Meeting Agenda.
Code of Ethics, Conflicts of Interest, Gifts & Entertainment, Political Contributions, Outside Business Activity.
Client Communication Letter Suite, Form ADV Amendment Checklist, Reg S-ID Red Flags.
Marketing Procedures Policy, Firm & Employee Social Media Policies, Promoter & Solicitor Oversight.
Best Execution Evaluation, Trade Error Policy & Log, Proxy Voting, Custody Rule Compliance Checklist.
Employee Technology Use Agreement, Whistleblower Policy, and acknowledgement forms.
Business Continuity Plan, Books & Records Policy, Written Supervisory Procedures.
SEC Exam Document Production Checklist, First-Time Examination Guide, Cybersecurity Request Bundle.
61 editable templates across 13 categories, each mapped to the rule it supports. Browse the full library →
Start before you subscribe
The Securing Compliance report, the SEC Exam Cybersecurity Preparedness Brief, the Reg S-P Impact Summary, and our ongoing BrainTrust posts — no payment required.
Security awareness for up to 50 staff
Phishing simulations, quiz tracking, and audit-ready completion reports — the training evidence retained for your examination file.
Two tiers. One Premium price.
The Free tier is built to put real material into the hands of CCOs and IT managers who are still organizing their cybersecurity program. The Premium tier adds everything above — the Reg S-P vendor due-diligence portal, automated employee training, the full policy and framework library, and the interactive builders.
The BrainTrust
A practical starting point for firms that need better direction before engaging a consultant or building a more formal cybersecurity compliance program.
- Securing Compliance — what SEC examiners actually ask for
- BrainTrust Posts — cybersecurity commentary and SEC enforcement updates
- SEC Exam Cybersecurity Preparedness Brief
- Mock SEC Cyber Exam
- Cybersecurity Compliance Document Review Matrix
- Reg S-P 2024 Compliance Impact Summary
The BrainTrust — Premium
Designed for firms that want what the examiner asks for already written — but do not yet need MTradecraft to operate the program on their behalf.
- Reg S-P vendor due-diligence portal — a 600+ vendor evidence database with cited sources concentrated on the high-sensitivity providers, plus the questionnaire & confidentiality agreements to run your program
- Automated employee training — FieldCraft security awareness, phishing simulations, quiz tracking & audit-ready reporting (up to 50 users)
- Incident Response Plan Builder — before the incident: generates your firm's complete incident response plan as an editable Word document
- Incident Response Assistant — during the incident: a live companion that walks you through a real incident on your own plan and produces the timestamped Incident Response Record Rule 204-2 expects
- Quarterly External Exposure Snapshot (beta) — a passive scan of your firm's public exposure, summarized against Reg S-P and Reg S-ID and delivered every quarter
- The full policy, framework & template library — 61 editable templates, each mapped to the rule it supports
- Cybersecurity core — AI Compliance Framework, Cybersecurity Policies & Procedures Manual, and Incident Response Plan
- 10 governance & regulatory policies — Code of Ethics, Business Continuity Plan, Books & Records, Conflicts of Interest, Whistleblower Policy, and more
- Annual compliance operations — 206(4)-7 review template, risk assessment template, compliance calendar
- SEC examination tools — document production checklist, first-exam guide, and cybersecurity request bundle
- Client & ADV documents — communication letter suite, ADV amendment checklist, and more
- Email support from MTradecraft on cybersecurity compliance questions
- Everything in the Free tier
By subscribing you agree to the BrainTrust Member Policy.
Built for firms in a specific situation.
A Premium membership fits if…
- You are a CCO or IT manager at an SEC-registered firm and you need real policy templates — not generic ones.
- You are a small RIA without the budget for a $36K consulting engagement but with examination obligations you cannot ignore.
- You are a compliance consultant who needs a defensible cybersecurity policy library to deliver to your own clients.
- You want to run FieldCraft Security Awareness Training for your staff without a separate training vendor relationship.
Premium is not the right fit if…
- You need someone else to operate the cybersecurity program, not just provide the documentation. The Cyber Compliance Consultant engagement exists for that.
- An insurance carrier or DDQ requires a named CISO. The Remote CISO engagement exists for that.
- You want active SEC examination support and direct involvement from cybersecurity counsel. That is consulting, not membership.
Questions members ask before subscribing.
Can I cancel anytime?
Yes. The subscription is managed through Memberful. You can cancel future charges at any time from your account portal — no phone calls, no penalty. You retain access through the end of the paid period.
Are the documents customized to my firm?
No. BrainTrust templates are provided as editable Word documents that the member adapts to their firm's specifics. If you need documents drafted to your firm, that is a Cyber Compliance Consultant engagement.
Can I list MTradecraft as my cybersecurity expert?
No. A BrainTrust membership is a resource subscription, not a consulting relationship. For DDQ and examination purposes requiring a named cybersecurity expert or CISO, the Remote CISO engagement is what's required.
What does FieldCraft cost beyond 50 users?
The Premium membership includes FieldCraft for up to 50 users. If your firm exceeds 50 users, additional seats can be added on a separate FieldCraft subscription at $4.00 per user per month (billed annually).
Will the templates pass an SEC examination?
Templates do not pass examinations — implemented programs do. A BrainTrust template gives you a defensible starting point written by a knowledgeable party. Whether your firm passes an exam depends on how the policies are adopted, implemented, reviewed, and documented over time.
Premium is $2,500 a year — and starts the moment you subscribe.
Free account first if you want to read the Securing Compliance report and access our posts. Upgrade to Premium when the exam notice, the carrier questionnaire, or the client DDQ makes it real.
By creating an account or subscribing you agree to the BrainTrust Member Policy.