All services
Compliance

SOC 2 Audit Readiness and Support

Guidance through every stage of a SOC 2 audit, from the gap assessment to handing evidence to your auditor

A customer asked for your SOC 2 report

It is usually a customer who starts this, not a regulator. A deal reaches security review, somebody asks for the report, and you find out what a SOC 2 audit involves with a contract waiting on it.

We guide you through every stage: what the gaps are, what to fix first, which trust principles you actually need, which auditor to use, and what evidence to hand them.

SOC 2 Audit Readiness overview (PDF)

Benefits

  • Assurance for the constituents asking
  • Less due diligence overhead
  • A competitive advantage in security review
  • Improved business processes
  • Better managed risk
AICPA SOC for Service Organizations

Features

Aligned to the AICPA Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Audit readiness

  • SOC 2 gap assessment
  • Comprehensive remediation plans
  • Policy and procedure templates
  • Guidance on trust principle selection
  • Auditor selection support

Audit support

  • Evidence provisioning
  • Reactive remediation
  • Do you perform the audit?

    No, and we could not. A SOC 2 report comes from an independent CPA firm. We prepare you for it and support you through it, and keeping those two roles apart is what makes the preparation worth anything.

  • What usually starts this?

    A customer, not a regulator. A deal reaches security review, somebody asks for the report, and you find out what a SOC 2 audit involves with a contract waiting on it. Starting before that happens is considerably cheaper.

  • How long does it take?

    It depends on where you are starting and which report you need, which is the first thing we establish. What we can say is that the work is sequenced rather than simultaneous, so you can see progress throughout rather than only at the end.

  • Could a compliance automation platform get us there instead?

    Those platforms collect evidence and watch controls well, once you know which controls you are running. They do not set your scope, write policies that match how you work, or answer the auditor when they push back. It is often a tool used by larger organizations, not smaller ones.

Tell us about your business.

A half-hour conversation about what you're being asked for and where you actually stand. If we can help, you'll have a proposal usually within a day.

Not ready to talk? Check your readiness in five minutes and see where to start.