02 · Compliance
SOC 2 Readiness
Get through your first SOC 2 without derailing the roadmap.
We design your Trust Services Criteria controls, put the evidence collection on rails, run a readiness assessment against the criteria your auditor will use, and coordinate with the CPA firm through Type I and the Type II observation window.
The context
Why this matters
SOC 2 is where most North American SaaS deals get unblocked, and where most first-time teams lose a quarter. The failure pattern is predictable: controls are written to sound impressive, then nobody operates them, and the Type II observation window closes with gaps the auditor has to qualify.
We design controls you can actually run every month, wire them to evidence that generates itself where possible, and pressure-test the whole set in a readiness assessment before your auditor ever looks at it.
If you are pursuing ISO 27001 as well, we map the two frameworks against each other from the start. The overlap is substantial, running them as one programme rather than two saves months.
What is covered
Scope of the engagement
- 01
Trust Services Criteria selection
Decide which categories you are reporting on, Security is mandatory, and Availability, Confidentiality, Processing Integrity and Privacy are chosen based on what your customers actually contract for.
- 02
Control design & narrative
A control set mapped to the TSC points of focus, written as operable procedures with named owners, frequencies and evidence sources.
- 03
Readiness assessment
A dry-run audit against your control set, identifying design gaps and evidence gaps before the CPA firm does.
- 04
Evidence pipeline
Setting up the recurring collection, access reviews, change management, vendor reviews, security training, incident records, so the observation window does not become a scramble.
- 05
Auditor selection & coordination
Help choosing a CPA firm, scoping the engagement, and managing the request list through fieldwork.
- 06
ISO 27001 crosswalk
A mapping between your SOC 2 controls and ISO 27001 Annex A so one body of evidence serves both frameworks.
What you receive
Deliverables
Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.
- Trust Services Criteria scoping decision and rationale
- Full control matrix with owners, frequencies and evidence sources
- Readiness assessment report with remediation backlog
- System description draft for the audit report
- Evidence collection calendar and templates
- SOC 2 ↔ ISO 27001 control crosswalk
Questions
SOC 2 Readiness FAQ
Type I is a point-in-time opinion on whether your controls are suitably designed. Type II covers a window, usually three to twelve months, and tests whether those controls actually operated. Most enterprise buyers want Type II eventually; Type I is a reasonable first milestone that unblocks deals while the observation window runs.
No. A SOC 2 report is issued by a licensed CPA firm and independence rules prevent the same party from both building and attesting the controls. We prepare you and manage the process; the CPA firm issues the opinion.
It depends on who is asking. US enterprise buyers typically ask for SOC 2; European, UK, Middle Eastern and APAC buyers usually ask for ISO 27001. If both are on your roadmap, run them together, the control overlap is roughly 80%, and doing them sequentially means paying for the same evidence work twice.
Often paired with
ISO 27001 Certification
End-to-end ISO 27001 implementation: gap analysis, ISMS build, evidence and audit support, right through Stage 2.
Read more03Penetration Testing
Manual testing of web apps, APIs, mobile clients and authentication flows, with a report your engineers can act on.
Read more04Cloud Security Assessment
AWS, Azure, GCP, DigitalOcean, Linode and Vultr reviews covering IAM, exposure, data protection, logging and workloads.
Read moreKnow exactly what an auditor, and an attacker, would find.
Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.
No sales sequence. A scoping call and a written proposal cost nothing.