SOC 2 Type I & Type II Readiness
SOC 2 is the report enterprise customers ask for before they'll sign. We get your controls designed, operating and evidenced - so the audit is a formality, not a scramble.
What is SOC 2?
SOC 2 (System and Organization Controls 2) is an attestation report, not a certificate, issued by an independent CPA firm based on the AICPA's Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.
A Type I report assesses whether your controls are suitably designed at a single point in time. A Type II report goes further, assessing whether those controls actually operated effectively over an observation period - typically 3 to 12 months - which is what most enterprise buyers actually require.
What's included
Scoping Trust Criteria
Scoping - selecting the Trust Services Criteria relevant to your business.
Gap Assessment
Gap assessment against your chosen criteria.
Control Design & Implementation
Control design and implementation, including policies and technical controls.
Evidence Collection
Evidence collection process for the observation period.
Readiness Assessment
Readiness assessment ahead of the formal audit.
Auditor Coordination
Coordination with your independent CPA auditor through Type I or Type II.
Our approach - Plan, Do, Check, Act
The same continuous-improvement cycle behind every compliance programme we run.
Plan
Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.
Do
Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.
Check
Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.
Act
Run the audit, then keep improving through continual, corrective and preventive action.
Other compliance frameworks
Questions we get asked first
Do you issue the SOC 2 report?
No - SOC 2 reports are issued only by a licensed, independent CPA firm. We get your organisation ready and manage the evidence collection; the CPA firm performs the actual attestation.
Type I or Type II - which do we need?
Type I is faster and proves your controls are designed correctly; Type II proves they worked over time and is what most enterprise customers and procurement teams expect. Many organisations start with Type I and move to Type II.
How long is the Type II observation period?
Typically 3 to 12 months, set by your auditor based on your industry and customer requirements - we help you prepare evidence collection so that period runs cleanly.
Ready to get audit-ready for SOC 2?
Tell us where you're starting from and we'll come back with a scoped proposal within two working days.
