SOC 2 readiness & audit support

Get ready for a SOC 2 Type I or Type II examination: scope the Trust Services Criteria, close gaps, and support the audit.

SOC 2 is an attestation report produced by a licensed CPA firm against the AICPA Trust Services Criteria (security, and optionally availability, processing integrity, confidentiality and privacy). A Type I report assesses control design at a point in time; a Type II report assesses operating effectiveness over a review period.

Readiness work gets your controls and evidence in order before the auditor starts, so the examination is predictable and the report has no surprises.

What the engagement covers

Criteria selection

Decide which Trust Services Criteria belong in scope based on customer expectations and what you actually do.

Gap assessment

Assess current controls against the selected criteria and produce a prioritised remediation plan with owners.

Control implementation

Implement or adjust access management, change management, monitoring, vendor management, incident response and HR security controls.

Evidence collection

Set up how evidence is produced and retained so the Type II review period generates a clean population.

Auditor liaison

Help you select an audit firm, prepare the description of the system, and work through the auditor request list.

Common questions

Talk through SOC 2 for your team

A short call to confirm scope, timeline and a firm price — before you commit to anything.