For SaaS and service companies selling into the US market, SOC 2 is the ticket to the game. We prepare you for Type I and Type II examinations, choose the right Trust Services Criteria, and build controls that pass without exceptions, then keep passing, year after year.
SOC 2 is an examination by a CPA firm; our job is to make sure you walk into it with controls that operate and evidence that exists. We scope the criteria honestly: security always, the other four only where your customers genuinely need them.
Criteria selection, system description drafting, and a gap analysis against the Trust Services Criteria, with a clear reading of what Type I would find today and what Type II will demand over the observation period.
Controls built to operate inside your engineering and business workflows, with evidence generated as a by-product of work rather than a quarterly archaeology project.
Auditor liaison through the examination, then the monitoring cadence that keeps the next report clean, so renewal never means starting over.
Most SOC 2 exceptions come from the same handful of causes: access reviews that slipped, offboarding gaps, change management shortcuts, evidence that was never captured. Because our consultants audit for a living, we build your programme around exactly the failure modes examiners find, before they find them. Selling into both the US and Europe? We run SOC 2 and ISO 27001 on one integrated control set: one programme, both badges.
Security always; availability, confidentiality, processing integrity and privacy only where customers need them.
A realistic observation window and a monitoring cadence that makes Type II routine.
SOC 2 and ISO 27001 served by a single control set and evidence library.
Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.
Which systems, which Trust Services Criteria, Type I or Type II, and which CPA firm, settled up front with your commercial deadlines in view.
Gap analysis against the criteria and a draft system description, with remediation priced and prioritised.
Controls and evidence capture built into your workflows, with your engineers, not around them.
Support through the audit itself: evidence requests, walkthroughs and auditor questions handled without derailing your team.
Continuous monitoring so the observation period generates its own evidence, and next year's report is a formality rather than a fire drill.
Type I says your controls were suitably designed on a date; Type II says they operated over a period, typically six to twelve months, and it is what sophisticated customers actually want. A common path is Type I to unblock a deal, with Type II following after the observation window.
Readiness and remediation typically run two to four months depending on maturity, then the Type II observation period on top. If a customer deadline is looming, tell us at scoping and we will sequence around it honestly.
It is a market question: US buyers ask for SOC 2, UK and European buyers for ISO 27001, and companies selling into both increasingly need both. Built on one integrated control set, the second is a modest increment rather than a second programme.
A licensed CPA firm performs the examination and issues the report; consultants cannot. Our role is to make their examination uneventful, and we work alongside your chosen firm or help you select one.
A 30-minute scoping call, and you will know the realistic path and timeline to the report your customer wants.