Compliance — SOC 2
SOC 2 readiness for firms that sell to enterprises
Nobody wakes up wanting a SOC 2. A procurement team, a security questionnaire, or outside-counsel guidelines make it a condition of revenue. Readiness is the work between that email and a clean report — and readiness is the part we do.
Why this lands on your desk
SOC 2 demand is sales-driven, not regulator-driven. Enterprise clients send security questionnaires that run to hundreds of questions; outside-counsel guidelines increasingly name SOC 2 for law firms and their vendors; procurement gates stall deals in security review until a report appears. The buyer is not the government — it is your next contract.
Precision about what SOC 2 is: an attestation report issued by a licensed CPA firm after examining your controls against the AICPA’s Trust Services Criteria. We are not that CPA firm, and we are not an auditor or a law firm. What we sell is readiness — the controls, the documentation, and the evidence stream that make the audit itself uneventful. Anyone who offers to sell you the certificate directly is describing a different product than SOC 2.
Type I versus Type II
A Type I report examines whether your controls are suitably designed at a point in time. A Type II examines whether they operated effectively over a window — commonly three to twelve months. Sophisticated clients increasingly expect Type II, which means the calendar is part of the engineering: the observation window cannot start until the controls actually run.
The readiness path
Five stages, each with an artifact you keep.
Scope
Which Trust Services Criteria (Security is mandatory; Availability and Confidentiality are the common additions), which systems, which people. Tight scope is the difference between a project and a slog.
Gap assessment
Your current controls against the criteria, in writing, with a sequenced plan and honest effort estimates.
Remediate and implement
Close the gaps: access control, change management, monitoring, vendor management, and recovery, drawing on our security and business continuity practices.
Collect evidence continuously
Tooling plus discipline, so evidence accrues as controls operate — not a screenshot scramble the month before fieldwork.
Engage the auditor
We help you select a CPA firm, set the observation window, and support fieldwork — answering the technical questions so your team can keep shipping.
What we implement and operate
The criteria reward controls that run on their own schedule, with records to prove it.
Access control and identity
MFA, least privilege, and offboarding that happens the day someone leaves — the single most-examined control family.
Change management
Changes reviewed, approved, and traceable, at a weight appropriate to your team’s size.
Monitoring and alerting
Systems monitored around the clock by our tooling, with escalation to an engineer and records the auditor can sample.
Vendor management
An inventory of subprocessors and critical vendors, with reviews on a defensible cadence.
Backup and recovery
Tested restores and a recovery plan — the Availability criterion in practice, via business continuity.
Security awareness training
Recorded training for everyone in scope, because the auditor will ask for the completion report.
Policies and risk assessment
Policies that describe what you actually do, and a risk assessment revisited on a schedule rather than rediscovered annually.
A word about honesty in this market
Readiness vendors routinely blur the line between preparing for an audit and passing one. Compliance-automation platforms are genuinely useful — we deploy and operate them — but a dashboard showing 94% is not a report, and evidence a platform collected from systems nobody actually operates will not survive an auditor’s sampling. The work is the controls; the platform is filing.
Firms already operating under NYDFS Part 500 or HIPAA start closer than they think: the control families overlap, and evidence gathered for one regime often serves another. We maintain one operating program with per-regime mappings — the approach described at the compliance hub.
Good fit if
B2B software or services firm, roughly 10–200 people
An enterprise deal is sitting in security review right now
The questionnaire backlog owns your founders’ evenings
A client’s outside-counsel guidelines name SOC 2
You bought a compliance platform and it became shelfware
Common questions
How long until we can hand a client a report?
A Type I can follow soon after remediation is genuinely complete. A Type II adds an observation window of three to twelve months on top. From a standing start, six to twelve months to a first report is a realistic planning number — and anyone promising two weeks is selling something other than SOC 2.
Can't you just certify us?
No. A SOC 2 report is an attestation issued by a licensed CPA firm, and no readiness vendor can issue one. We prepare you, help you choose the auditor, and support the examination — the separation is what gives the report its value to your clients.
Do we need Type II, or is Type I enough?
Ask your buyers — their questionnaires usually say. Many firms use Type I as a milestone to unblock a pending deal, with the Type II window already running behind it. We plan the calendar so the first report is not the last.
Which Trust Services Criteria should we include?
Security is required; add Availability or Confidentiality when clients ask for them, and be slower to add the rest — every criterion adds controls and evidence obligations. Scope should follow contracts, not ambition.
We just failed a questionnaire. Answers first, or SOC 2 first?
Both, in that order. A questionnaire can be answered honestly today with a remediation narrative attached — buyers accept credible plans more often than firms expect. SOC 2 is what removes the questionnaire treadmill later. We do the first this week and start the second in parallel.
Make the audit the boring part.
A readiness assessment maps your controls to the criteria your buyers actually cite — findings are yours to keep.