How it works
A clear process, stated up front.
Every phase has named deliverables, a meeting cadence, and an honest statement of what your team must contribute. No mystery, no drift.
The 12-week combined readiness plan, phase by phase.
Use the tabs to see each phase's work and deliverables. HIPAA-only or SOC 2-only engagements follow the same shape with a shorter track.
Week 1
Kickoff & discovery
Stakeholder interviews, systems, data flows, vendors, workforce, and contracts.
Deliverables: Project plan, responsibility matrix, system inventory.
Model 12-week plan for combined HIPAA + SOC 2 readiness. Actual timelines depend on client responsiveness, system complexity, existing control maturity, remediation effort, and auditor availability. A SOC 2 Type 2 report additionally requires a 3–12 month observation window plus audit and reporting time.
Meeting cadence.
Weekly working session
45 minutes with your program owner: progress, blockers, decisions needed, next week's priorities. Recorded actions, not vibes.
Shared project channel
Day-to-day questions answered where your team already works, with response targets defined in the agreement.
Milestone reviews
At assessment completion and readiness delivery: leadership review of risk posture, exceptions, and the go-forward plan.
What your team commits.
Timelines depend on this being real — so we put it on the page.
| Role | Typical time | What it covers |
|---|---|---|
| Executive sponsor | ≈ 1 hour / week | Kickoff, weekly status visibility, decisions on risk acceptance and budget-affecting remediation. |
| Program owner (ops or eng lead) | ≈ 3–5 hours / week | Weekly meeting, evidence coordination, unblocking task owners, reviewing policies. |
| Engineers / IT | Varies by gaps | Implementing technical remediation in your systems — MFA, logging, access, backups — with our prioritized list and guidance. |
| All staff | ≈ 1–2 hours total | Training completion and policy acknowledgment. |
Timeline assumptions: prompt responses (within two business days), a functioning cloud environment, and leadership willing to fix high-risk gaps. The service agreement defines what happens when client tasks run late — typically the timeline shifts with them.
After readiness.
- Launch the SOC 2 examination with your chosen independent CPA firm — we coordinate requests and responses
- Start the Type 2 observation window with evidence generating on schedule
- Move to Continuous Compliance for the standing operating cadence
- Publish your Trust Center and answer customer questionnaires from a maintained library
Want the plan in your hands first? Request the sample project plan through the HIPAA + SOC 2 startup checklist, which includes the full phase breakdown.
See the plan applied to your company.
Contact us and leave with a recommended scope, realistic timeline, and budget range.