SOC 2 Readiness

Pass the review
before the deal stalls.

An enterprise prospect asks for your SOC 2 report and a sales cycle suddenly depends on controls nobody has written down. Readiness work is what turns that from a year-long problem into a quarter.

Your Controls / Readiness ● in scope
01 Scoping
02 Gap Assessment
03 Policies
04 Technical Controls
05 Evidence
06 Auditor Handoff
Scoping Gaps Policies Controls Evidence
What's Involved

Readiness,
not the audit.

To be clear about the boundary: we are not your auditor and cannot be. A CPA firm issues the report. Our job is to get you to the point where that firm has nothing to write up.

Scoping

Which trust services criteria apply, Type I or Type II, and which systems are genuinely in scope — decided early, because scope creep here is expensive.

Gap Assessment

A honest read of where you are against the criteria, ranked by how long each gap takes to close rather than by how bad it sounds.

Policy Set

The policies you actually need, written to match how your team really works — because an auditor tests whether the policy is followed, not whether it exists.

Technical Controls

Access management, logging, encryption, change control, and vulnerability handling implemented in the systems rather than described in a document.

Evidence Automation

Evidence collected continuously from the systems themselves, so the observation window doesn't become a quarterly screenshot exercise for someone.

Auditor Handoff

Working alongside the audit firm you choose, answering their requests so your engineers aren't pulled into it for weeks.

Two Ways In

Scramble,
or ready.

Type II reports test controls over a period, which is why starting the week the auditor arrives cannot work. The observation window has already begun or it hasn't.

× Controls written the week the auditor is booked
Policies in force long enough to produce evidence
× Screenshots gathered by hand every quarter
Evidence collected automatically from the systems
× Access reviews nobody has ever actually performed
Quarterly reviews that run and get recorded
× A security questionnaire answered three different ways
One security narrative everyone answers from

Buyers often ask for a code-level review alongside the report — see technical due diligence. Most of the technical controls land in your cloud setup.

Start Early

Ready before they ask.

Tell us who's asking and by when. We'll assess the gap, tell you honestly whether the date is achievable, and what the fastest defensible path looks like.