SOC 2 Type II

Pass your SOC 2 Type II examination without the fire drill

Readiness work that gets your controls and evidence in order before the auditor starts, then supports you through a Type II examination against the AICPA Trust Services Criteria.

  • Against the AICPA Trust Services Criteria (security, plus any of availability, processing integrity, confidentiality, privacy)
  • Evidence set built to survive a Type II review period, not just a point in time
  • Auditor selection and request-list support included
  • Fixed scope and a firm price before you commit

Where do you stand?

A quick self-check before you get in touch

SOC 2 Type II readiness check

Six quick questions, about a minute. You see the result straight away — no email required.

Why this comes up

SOC 2 is an attestation report produced by a licensed CPA firm. A Type I report assesses whether controls are suitably designed at a point in time; a Type II report assesses whether they operated effectively over a review period — typically three to twelve months.

Enterprise buyers increasingly ask for Type II specifically. That means the controls and the evidence population have to hold up across the whole period, so the work needs to start before the clock does.

What the engagement covers

Criteria selection

Decide which Trust Services Criteria belong in scope based on customer expectations and what you actually do.

Gap assessment

Assess current controls against the selected criteria and produce a prioritised remediation plan with owners.

Control implementation

Implement or adjust access management, change management, monitoring, vendor management, incident response and HR security controls.

Evidence collection

Set up how evidence is produced and retained so the Type II review period generates a clean, complete population.

Auditor liaison

Help you select a CPA firm, prepare the description of the system, and work through the auditor request list.

How it runs

  1. 01

    Scope and gap assessment

    Select the Trust Services Criteria and assess current controls against them.

  2. 02

    Remediation

    Close the design gaps — access, change, monitoring, vendor, incident and HR controls — and assign every control an owner.

  3. 03

    Evidence set-up

    Wire up evidence collection so the review period produces a complete population with no gaps.

  4. 04

    Review period

    Controls operate for the Type II window while evidence accumulates. We run checkpoints so nothing drifts.

  5. 05

    Examination

    The CPA firm runs the Type II examination. We support the request list and help resolve any exceptions.

What you get

  • In-scope Trust Services Criteria and system description outline
  • Gap assessment and remediation plan
  • Control set with assigned owners
  • Evidence collection plan and calendar for the review period
  • Auditor request-list support through the examination

Common questions

More detail on the SOC 2 service page.

Frameworks and platforms we work across

AWS Security
Microsoft Azure
Google Cloud
ISO 27001
SOC 2
OWASP
PCI DSS

Scope your SOC 2 Type II

Book a short assessment call — we map where you are against the standard and agree the next step.