SOC 2 · Trust Services

The report your American customers ask for.

For SaaS and service companies selling into the US market, SOC 2 is the ticket to the game. We prepare you for Type I and Type II examinations, choose the right Trust Services Criteria, and build controls that pass without exceptions, then keep passing, year after year.

We hold ourselves to the standards we audit: Cybercontrols is certified to
ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we deliver

Readiness, remediation, and a report that holds.

SOC 2 is an examination by a CPA firm; our job is to make sure you walk into it with controls that operate and evidence that exists. We scope the criteria honestly: security always, the other four only where your customers genuinely need them.

01

Readiness Assessment

Criteria selection, system description drafting, and a gap analysis against the Trust Services Criteria, with a clear reading of what Type I would find today and what Type II will demand over the observation period.

02

Remediation & Evidence Design

Controls built to operate inside your engineering and business workflows, with evidence generated as a by-product of work rather than a quarterly archaeology project.

03

Examination Support & Continuous Monitoring

Auditor liaison through the examination, then the monitoring cadence that keeps the next report clean, so renewal never means starting over.

Why Cybercontrols

Exceptions are predictable. We predict them.

Most SOC 2 exceptions come from the same handful of causes: access reviews that slipped, offboarding gaps, change management shortcuts, evidence that was never captured. Because our consultants audit for a living, we build your programme around exactly the failure modes examiners find, before they find them. Selling into both the US and Europe? We run SOC 2 and ISO 27001 on one integrated control set: one programme, both badges.

Criteria scoped honestly

Security always; availability, confidentiality, processing integrity and privacy only where customers need them.

Type I to Type II, planned

A realistic observation window and a monitoring cadence that makes Type II routine.

One programme, two badges

SOC 2 and ISO 27001 served by a single control set and evidence library.

Senior-led, always

Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.

How it works

From scoping to a clean report, without surprises.

Step 1

Scope & criteria

Which systems, which Trust Services Criteria, Type I or Type II, and which CPA firm, settled up front with your commercial deadlines in view.

Step 2

Readiness assessment

Gap analysis against the criteria and a draft system description, with remediation priced and prioritised.

Step 3

Remediate & embed

Controls and evidence capture built into your workflows, with your engineers, not around them.

Step 4

Examination

Support through the audit itself: evidence requests, walkthroughs and auditor questions handled without derailing your team.

Step 5

Monitor & renew

Continuous monitoring so the observation period generates its own evidence, and next year's report is a formality rather than a fire drill.

Questions we hear most

SOC 2, answered plainly.

Type I or Type II?

Type I says your controls were suitably designed on a date; Type II says they operated over a period, typically six to twelve months, and it is what sophisticated customers actually want. A common path is Type I to unblock a deal, with Type II following after the observation window.

How long does SOC 2 take?

Readiness and remediation typically run two to four months depending on maturity, then the Type II observation period on top. If a customer deadline is looming, tell us at scoping and we will sequence around it honestly.

SOC 2 or ISO 27001, or both?

It is a market question: US buyers ask for SOC 2, UK and European buyers for ISO 27001, and companies selling into both increasingly need both. Built on one integrated control set, the second is a modest increment rather than a second programme.

Who actually issues the report?

A licensed CPA firm performs the examination and issues the report; consultants cannot. Our role is to make their examination uneventful, and we work alongside your chosen firm or help you select one.

A deal waiting on SOC 2?

A 30-minute scoping call, and you will know the realistic path and timeline to the report your customer wants.