SOC 2 readiness

We help your team scope, prepare and test controls against the Trust Services Criteria before an independent CPA firm performs your SOC 2 examination.

On this page

What SOC 2 is

SOC 2 is an attestation report on controls at a service organization. A licensed CPA firm performs the examination under AICPA attestation standards and reports against the Trust Services Criteria. The report covers a defined system: the services you provide and the infrastructure, software, people, procedures and data behind them.

Customers ask for SOC 2 during security reviews and procurement, most often when you store or process their data. A current report lets their vendor risk team review your controls in one document instead of a long questionnaire. SaaS, fintech, healthcare technology and managed service providers are often asked for one.

Trust Services Criteria and report types

Security is always in scope. You add other categories based on what you commit to customers.

Security

Required in every SOC 2 report. Covered by the common criteria: control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management and risk mitigation.

Availability

Optional. Covers capacity planning, backups, recovery and the availability commitments you make to customers.

Processing integrity

Optional. Covers whether system processing is complete, valid, accurate, timely and authorized.

Confidentiality

Optional. Covers how information designated as confidential is protected from collection through disposal.

Privacy

Optional. Covers how personal information is collected, used, retained, disclosed and disposed of in line with your privacy commitments.

Type 1

Reports on the description of your system and the suitability of the design of your controls as of a specific date.

Type 2

Adds the operating effectiveness of those controls over a review period. Many customer security reviews ask for a Type 2.

How readiness works with us

We agree the system boundary with your team: products, cloud accounts, applications, data stores, people and key vendors. We help you choose which Trust Services Criteria categories to include based on your customer commitments, and whether to start with a Type 1 or a Type 2. We identify subservice organizations, such as your cloud provider, early because the report must state how their controls are treated.

What you receive

Each engagement has a fixed scope agreed at the start. These are the outputs your team keeps.

Gap assessment

  • System boundary and in-scope components
  • Control-by-control status against the selected criteria
  • Prioritized remediation plan with owners and target dates

Policies and controls

  • Policies updated where gaps exist
  • Controls implemented or improved in your environment
  • Control matrix mapped to the Trust Services Criteria

Evidence set

  • Evidence organized by control for the auditor
  • Defined evidence sources and collection frequency
  • Setup in your compliance platform if you use one

Testing and audit support

  • Pre-audit control testing results
  • Fixes for exceptions found in testing
  • Help with auditor requests during fieldwork

Control areas we commonly implement

Access control and identity

SSO, MFA, role-based access, joiner, mover and leaver steps, and periodic access reviews. We can deploy identity with Keycloak.

Vulnerability management

Scanning, patch timelines by severity and tracking of findings to closure. We also run application security testing when customers ask for a penetration test.

Logging and monitoring

Centralized logs, alerts on security events and a record that alerts were reviewed. We deploy open-source monitoring such as Wazuh.

Incident response

A written plan, defined roles, a tabletop exercise and records of incidents and follow-up actions.

Change management

Code review, approvals before production changes, separation of duties and deployment records.

Vendor risk

A vendor inventory, risk ratings, review of vendor SOC reports and security terms in contracts.

Backups and recovery

Backup schedules, restore tests and a documented recovery plan.

SOC 2 Type 1 and Type 2 compared

Some teams start with a Type 1 and move to a Type 2 for the next period. Your customers' requests usually decide which comes first.

TopicType 1Type 2
What the auditor reports onSystem description and design of controlsSystem description, design and operating effectiveness of controls
TimingA single dateA review period agreed with your auditor
EvidenceControls exist and are designed to meet the criteriaRecords showing each control operated throughout the period, which the auditor samples
Common useA first report when a customer needs one soonOngoing assurance for customers who want to see controls working over time
Readiness focusControl design and documentationControl design, consistent operation and evidence collection across the period

Who does what

We prepare your environment and evidence for the examination. We scope, assess, help implement controls, test them and support your team during fieldwork. We do not perform the examination or issue the report.

Your independent CPA firm plans and performs the examination, decides its own procedures, tests your controls and issues the SOC 2 report with its opinion.

Your team owns the system and the controls. Management provides the system description and signs the assertion. Control owners run their controls during the period. One person on your side coordinates with the auditor. We can help draft the system description for management to review.

Common questions

How long does readiness take?

It depends on your scope and how mature your controls are today. During scoping we give you a plan with dates for each phase. For a Type 2, also plan for the review period, because the auditor needs evidence that controls operated across it.

Can you work with our compliance platform?

Yes. If you use Vanta, Drata or a similar platform, we work inside it. We connect integrations, map controls, upload evidence and fix failing checks. If you do not use one, we organize evidence in a folder structure your auditor can follow.

Do you perform the SOC 2 audit?

No. A licensed CPA firm performs the examination and issues the report. We prepare your team for it and support you while it runs.

Can you help after the report is issued?

Yes, through a retainer. We can help address exceptions noted in the report, keep evidence collection on schedule for the next period and prepare for the next examination. If a customer asks about the time between your report period and today, your management can issue a bridge letter, and we can help gather the supporting information.

What do we need to prepare?

A named owner on your side, read access to your cloud accounts, identity provider, code repositories and ticketing system, your current policies if you have any, and a list of key vendors. Security questionnaires you have received from customers are also useful.

Will you sign an NDA?

Yes. We sign an NDA on request before we review your systems or documents.

How to prepare

List the products and services customers expect the report to cover, and the security commitments you have made in contracts and on your website. Note any customer deadlines.

Gather what you already have: policies, a system or asset inventory, a vendor list, an architecture diagram and a description of how people get and lose access. Gaps are expected. The gap assessment exists to find them.

Choose an internal owner with time to coordinate the work, and decide whether you will use a compliance platform. If you have already selected a CPA firm, share their contact so we can align on scope and timing early.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.