How it works

A clear process, stated up front.

Every phase has named deliverables, a meeting cadence, and an honest statement of what your team must contribute. No mystery, no drift.

The 12-week combined readiness plan, phase by phase.

Use the tabs to see each phase's work and deliverables. HIPAA-only or SOC 2-only engagements follow the same shape with a shorter track.

Week 1

Kickoff & discovery

Stakeholder interviews, systems, data flows, vendors, workforce, and contracts.

Deliverables: Project plan, responsibility matrix, system inventory.

Model 12-week plan for combined HIPAA + SOC 2 readiness. Actual timelines depend on client responsiveness, system complexity, existing control maturity, remediation effort, and auditor availability. A SOC 2 Type 2 report additionally requires a 3–12 month observation window plus audit and reporting time.

Meeting cadence.

Weekly working session

45 minutes with your program owner: progress, blockers, decisions needed, next week's priorities. Recorded actions, not vibes.

Shared project channel

Day-to-day questions answered where your team already works, with response targets defined in the agreement.

Milestone reviews

At assessment completion and readiness delivery: leadership review of risk posture, exceptions, and the go-forward plan.

What your team commits.

Timelines depend on this being real — so we put it on the page.

RoleTypical timeWhat it covers
Executive sponsor≈ 1 hour / weekKickoff, weekly status visibility, decisions on risk acceptance and budget-affecting remediation.
Program owner (ops or eng lead)≈ 3–5 hours / weekWeekly meeting, evidence coordination, unblocking task owners, reviewing policies.
Engineers / ITVaries by gapsImplementing technical remediation in your systems — MFA, logging, access, backups — with our prioritized list and guidance.
All staff≈ 1–2 hours totalTraining completion and policy acknowledgment.

Timeline assumptions: prompt responses (within two business days), a functioning cloud environment, and leadership willing to fix high-risk gaps. The service agreement defines what happens when client tasks run late — typically the timeline shifts with them.

After readiness.

  • Launch the SOC 2 examination with your chosen independent CPA firm — we coordinate requests and responses
  • Start the Type 2 observation window with evidence generating on schedule
  • Move to Continuous Compliance for the standing operating cadence
  • Publish your Trust Center and answer customer questionnaires from a maintained library

Want the plan in your hands first? Request the sample project plan through the HIPAA + SOC 2 startup checklist, which includes the full phase breakdown.

See the plan applied to your company.

Contact us and leave with a recommended scope, realistic timeline, and budget range.