SOC 2 readiness

Prepare for a SOC 2 examination without managing the entire project yourself.

We handle scope, controls, policies, evidence, and auditor coordination. Your team makes the decisions and the changes — with a clear list, owners, and support at every step.

Type 1 versus Type 2.

Same criteria, different question — design at a point in time versus operation over a period.

SOC 2 Type 1

Design, at a point in time

  • Answers: are the controls suitably designed and in place today?
  • Faster path to a report — useful for unblocking near-term deals.
  • No observation window required.
  • Often a stepping stone: the Type 2 window starts right after.

SOC 2 Type 2

Operation, over a period

  • Answers: did the controls operate effectively across the window?
  • Observation window commonly 3–12 months.
  • What most enterprise security teams ultimately require.
  • Requires disciplined evidence generation throughout the window.

Security (common criteria) is required in every examination. Availability, confidentiality, processing integrity, and privacy are added based on what your customers actually require — we help you scope this deliberately.

What readiness involves.

A structured path from scoping to auditor handoff.

1 · Scope

System boundary, Trust Services Criteria selection, and a control matrix with named owners — decided in a scoping workshop, not discovered mid-audit.

2 · Assess

Gap assessment against the criteria, a risk register, and a remediation backlog ranked by audit impact and effort.

3 · Implement

Policies approved, access lifecycle and reviews running, SDLC and change management documented, vulnerability management operating, training completed, vendors assessed.

4 · Validate & hand off

Evidence collected and quality-reviewed, system description drafted, dry-run testing done, and a coordinated introduction to an independent CPA firm.

Typical evidence an auditor requests.

We build the request list early so nothing is a surprise in the examination.

  • Access control: MFA settings, role assignments, access review records
  • Change management: pull requests, approvals, CI/CD configuration
  • Infrastructure: encryption settings, network rules, hardening baselines
  • Monitoring: log retention, alerting rules, vulnerability scan results
  • People: onboarding/offboarding records, background checks, training completions
  • Vendors: risk assessments, contracts, subprocessor reviews
  • Governance: policies with approvals, risk register, incident records
  • Resilience: backup configuration, restore tests, continuity exercises

Where practical we plan evidence collection around your existing stack — cloud provider, identity, source control, ticketing, endpoint management, and HR systems — so evidence generates itself as your team works.

Auditor independence, by design.

The value of a SOC 2 report comes from the auditor's independence. We are not a CPA firm and we do not issue reports. We prepare you, coordinate requests, and help you respond to findings — and we keep a clean line between preparation and examination, disclosed to every party. The audit engagement, opinion, and fee belong to the independent firm you select.

The package.

Full inclusions and pricing — the CPA examination fee is always separate.

SOC 2 Readiness

B2B SaaS companies that need a SOC 2 Type 1 or Type 2 report to close customers.

$9,500 implementation

+ from $750/month ongoing

Plus the independent CPA audit fee, quoted separately by the audit firm.

Target: 6–12 weeks

Timelines are targets, for a reasonably mature startup; the CPA audit and report timeline is separate.

Included

  • Scope workshop and system boundary definition
  • Trust Services Criteria selection
  • Readiness / gap assessment
  • Control matrix and ownership assignments
  • Risk assessment and risk register
  • Policy customization and approval workflow
  • Asset, vendor, personnel, and access inventories
  • Evidence-request list and evidence quality review
  • Cloud, identity, source-control, ticketing, endpoint, and HR integration plan
  • Joiner/mover/leaver and access-review process
  • Secure-development and change-management process
  • Vulnerability-management program
  • Security-awareness training
  • Incident response and business-continuity exercises
  • Vendor-risk process
  • Audit project management and CPA-firm introductions
  • System-description support
  • Exception remediation support
  • Readiness letter stating scope and limitations (not an attestation report)

Not included unless purchased

  • The SOC 2 examination itself (performed by an independent CPA firm)
  • Penetration testing
  • Legal opinions
  • Hands-on cloud remediation

Serving healthcare customers too? The combined HIPAA + SOC 2 program does both with one control library.

SOC 2 FAQ

Is SOC 2 a certification?

Technically, no. SOC 2 is an attestation: an independent, qualified CPA firm examines your controls and issues a report with its opinion. There is no certificate from a standards body. Everyday usage says "SOC 2 certified," but your buyers' security teams know the difference — and so do we.

Type 1 or Type 2 — which do we need?

Type 1 evaluates control design at a point in time and is faster to reach. Type 2 tests operating effectiveness over an observation window (commonly 3–12 months) and is what most enterprise buyers ultimately require. A common path: Type 1 to unblock near-term deals, with the Type 2 window running immediately after.

Who performs the audit?

An independent CPA firm — never us. We prepare you, introduce you to qualified firms, manage the request list, and support you through report issuance, while preserving the auditor's independence. The audit engagement and fee are directly between you and the firm.

How long does readiness take?

Our target is 6–12 weeks for a reasonably mature startup. The examination and report timeline afterward belongs to the CPA firm, and a Type 2 additionally requires its observation window. Published industry estimates vary; treat any timeline — including ours — as an estimate that depends on your readiness, not a guarantee.

What does it cost?

Readiness implementation starts at $9,500, with ongoing readiness from $750/month. The CPA firm quotes its own examination fee separately — we deliberately do not bundle or estimate it, because it depends on scope and firm. See pricing for what affects the total.

Which Trust Services Criteria should we include?

Security is required in every SOC 2 examination. Availability, confidentiality, processing integrity, and privacy are optional and should be added only when your customers actually ask for them — each one adds controls and evidence. We help you choose during scoping based on real customer requirements, not maximalism.

Scope the examination before you commit to it.

In 30 minutes we'll outline your likely system boundary, criteria, gaps, and timeline.