SECOMPSSECOMPS
CMP 01

SOC 2 readiness.

The certification your enterprise customers ask for by name, and the one most likely to be blocking a deal right now. We take you from gap assessment to a clean Type I or Type II report.

At a glance

Timeline
3 to 4 months to Type I, plus observation window for Type II
Trust criteria
Security, plus Availability, Confidentiality, Processing Integrity and Privacy as scoped
Our role
Readiness and evidence. The audit stays independent.
Audit fee
Paid separately to your auditor
Pentest
Expected as control evidence
01Overview

What this actually is.

SOC 2 is not a certification with a fixed checklist. It is an attestation that the controls you claim actually operate, which is why two companies with the same report can be in completely different security postures. The report is only worth what the scope and the controls behind it are worth.

02Scope

What we cover.

Scope definitionWhich trust services criteria, which systems and which period, decided deliberately rather than by copying a competitor.
Gap assessmentCurrent state against each in-scope criterion, with a plain list of what is missing, partial or already passing.
Control designAccess management, change management, incident response, vendor management, business continuity and monitoring.
Policy setWritten to describe what you actually do, because auditors test operation and not prose.
Evidence collectionAutomated where possible, organised by control, collected continuously rather than reconstructed the week before.
Type I readinessDesign effectiveness at a point in time, which is what unblocks most stalled enterprise deals fastest.
Type II observationOperating effectiveness across the window, with monitoring so a control failure is caught before the auditor finds it.
Auditor liaisonWe manage requests and translate between auditor expectations and your engineering reality.
03Fit

Who needs this.

  • SaaS companies where a customer has made SOC 2 a contract condition
  • Businesses moving upmarket into enterprise procurement
  • Teams that failed or stalled a previous attempt
  • Anyone told a security questionnaire is no longer sufficient
04Questions

Frequently asked.

Type I or Type II?

Type I proves your controls are designed correctly at a point in time and is the fastest route to unblocking a deal. Type II proves they operated over a period, usually three to twelve months, and is what most enterprise buyers eventually require. Many companies do Type I first and roll into Type II.

Do we need a penetration test for SOC 2?

There is no line item that says penetration test, but auditors expect evidence of independent security testing under the risk assessment and monitoring criteria, and enterprise customers reviewing your report almost always ask. Bundling both is cheaper than sequencing them.

Can we use a compliance automation platform instead?

Those platforms are good at evidence collection and bad at judgement. They will not tell you your scope is wrong or your control design will not survive testing. Use one for evidence and use people for the parts that require thinking.

What if we fail?

A SOC 2 report with exceptions is not a pass or fail, it is a report with exceptions noted, which customers will read. Our job in the observation window is to catch control failures while they are still fixable.

Find out what stands between you and certification.

Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.