Fixed fee · fixed scope
Evidence Readiness Assessment
Before a matter is filed, three questions decide whether the evidence will hold: what data exists, where it lives, and whether it can be preserved and authenticated defensibly. This is a fixed-fee engagement that answers all three in writing, while the answers are still worth something.
It is not a proposal, a capability deck, or a scoping call. It is a piece of work with a price, an end date and a named examiner attached to it.
- Fixed fee
- $10,000
- Timeline
- One to two weeks
- Deliverable
- Written assessment + one-hour call
The fee is fixed, not estimated. Acquisition, collection and analysis of the sources the assessment identifies are separate engagements, quoted separately, and nothing here obliges you to buy them.
What the assessment answers
What data actually exists?
Custodians, devices, mailboxes, chat platforms, shared drives, cloud tenancies, backups and the systems nobody lists until week six. We reconcile the sources you know about against the ones your own retention settings, account inventories and device records say you have.
Where does it live, and how long will it survive?
Retention periods, auto-deletion policies, backup rotation, device reissue schedules and personal accounts holding work material. This is the part that has a clock on it: a source with a 30-day retention window is a source you either preserve this month or lose the argument about later.
Can it be preserved and authenticated defensibly?
For each source we say what a defensible acquisition looks like, and where one is not possible — full-disk encryption, a mobile secure enclave, a provider with no supported export path — we say that plainly rather than describing a logical collection as something it is not.
Who it is for
In-house counsel and litigation partners deciding what to freeze, in the window before those decisions become irreversible.
Litigation is reasonably anticipated but not filed
The duty to preserve has attached, or is about to, and devices are still overwriting themselves in the meantime. Every week between the trigger and the hold is a week of evidence you cannot get back.
In-house counsel inheriting an unmapped estate
You are asked what data the company holds and cannot answer from the org chart. The assessment produces the answer in writing, from the systems rather than from interviews alone.
A departing employee or suspected trade-secret loss
A returned laptop is often the only copy of what happened, and IT is queued to reimage it. The first decision is which sources to freeze, and it has to be made before anything is analysed.
You are about to negotiate an ESI protocol
Agreeing scope, formats and custodians before knowing what exists is how a party ends up bound to produce from a system it cannot defensibly collect from.
A collection already happened and you are unsure it holds
Self-collection, an IT export, a vendor with no forensic method. We assess what the approach could and could not have captured, and what it would take to remediate it now rather than at a spoliation hearing.
Exactly what you get
A written evidence map
Every identified source: custodian, system, data type, approximate volume, retention or deletion behaviour, and who controls it. Sources we could not confirm are listed as unconfirmed rather than omitted.
A preservation risk ranking
Sources ordered by how soon they are lost without action, so the first week of your budget goes where the clock is shortest rather than where the volume is largest.
A defensible-acquisition plan per source
For each source: the acquisition method we would use, what it captures, what it does not, and the standard it is measured against. Written so it can be handed to another examiner or attached to a protocol.
The authentication position, stated candidly
Where the evidence would be vulnerable on authentication or custody, and what can be done now to close it. If a source cannot be authenticated defensibly, the assessment says so.
A one-hour call with the examiner who did the work
Not an account manager and not a summary read by someone else. The examiner named on the assessment takes your questions, including the ones about what the assessment could not establish.
How the work is done
The method is the product. Everything below is the firm’s published practice, linked to the page where it is documented in full — an assessment written to a standard an opposing expert already knows how to check is worth more than one written to impress you.
Standards the other side will measure it against
Our procedures follow SWGDE best practices, NIST SP 800-86 and ISO/IEC 27037 for the identification, collection, acquisition and preservation of digital evidence.
Write-blocked acquisition
Source media is acquired through a hardware or software write blocker, so the original is never altered by the act of copying it — and the tool, version and operator are recorded.
Cryptographic hash verification
A hash is computed at acquisition and re-verified afterward, and again whenever a copy is made. A matching hash is what lets an examiner state that the image analysed today is bit-for-bit identical to the device seized months ago.
Documented chain of custody
Every transfer, storage location and access is logged from seizure onward, built to be produced rather than reconstructed later from memory — because a gap in custody is the first thing an opposing expert looks for.
Sources that cannot be write-blocked
Cloud and SaaS data lives on infrastructure nobody can touch, so defensibility shifts to the export: supported collection paths, provider-side metadata evidencing completeness, and recorded query parameters so another examiner can reproduce the set.
Written by people who testify to it
The assessment is prepared by an examiner from the Law & Forensics panel, and it is written on the assumption that it may be produced, deposed on, or attached to a motion.
Digital forensics experts who testify to this work
Full expert panel →
J-Michael Roberts
Senior Director
Digital Forensics · Incident Response · Malware Reverse Engineering

Daniel B. Garrie
Founder
Digital Forensics · Expert Witness Testimony · Incident Response

Roland Cloutier
Expert Consultant
Incident Response · Expert Witness Testimony
Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 40 appointments are listed by matter and citation.
Evidence Readiness Assessment — frequently asked questions
What does the Evidence Readiness Assessment cost?
$10,000, fixed. The fee covers the assessment, the written deliverable and the one-hour call with the examiner who performed it. It is a fixed fee rather than an estimate: if the work takes longer than we expected, that is our problem rather than a change order. Acquisition, collection or analysis of the sources identified is separate work, quoted separately, and you are under no obligation to engage us for it.
How long does it take?
One to two weeks from the point we have access to the people and systems we need. Two weeks is the normal case for an estate spanning several custodians, multiple cloud tenancies and on-premises systems; one week is realistic for a single-custodian departing-employee matter. If something in your environment would push it past two weeks, we tell you before you engage rather than after.
Is this the same as a legal hold?
No, and it is the step before one. A legal hold is a notice instructing people to preserve; the assessment establishes what there is to preserve, where it sits, and how long it survives without intervention. A hold issued against an unmapped estate frequently misses the sources with the shortest retention windows — which are the ones that get argued about.
Do you have to touch our systems?
Not necessarily. Much of the assessment is documentary: retention configurations, account and device inventories, backup schedules, and interviews with the people who administer the systems. Where a source needs to be examined directly, we do it under the same write-blocked, hash-verified method we would use in a live matter, so nothing done during the assessment becomes an authentication problem later.
Does the assessment commit us to anything further?
No. The deliverable is written to be usable by another firm or another examiner — the acquisition plan names methods and standards rather than proprietary process, so nothing in it is hostage to engaging us. Most clients do go on to the preservation work, but the assessment is priced and scoped to stand on its own.
Who performs the assessment?
A named examiner from the Law & Forensics expert panel, matched to the systems in play. The name appears on the assessment and the same person takes the one-hour call. Law & Forensics was founded in 2006, and its experts have been appointed as special masters, court-appointed neutrals and arbitrators; the assessment is written by someone who has had to defend this kind of work on the record.
Can you assess a collection someone else already performed?
Yes. Where an opposing party or an internal team has collected without forensic method, we examine what was produced, identify what the method could not have captured, and set out what a defensible re-collection would require. That is frequently the most valuable version of this engagement, because it is the one that produces a motion.
Start the assessment
The first step is clearance. Send the party names and we will confirm whether we can take the matter — no matter details, no engagement, no obligation. If we are clear, we will confirm the scope, the examiner and the $10,000 fee in writing before any work begins.
Not sure the assessment is the right first step?
Tell us the posture and the deadline. We'll say candidly whether this is what you need — or what is.

