SOC 2 readiness.
The certification your enterprise customers ask for by name, and the one most likely to be blocking a deal right now. We take you from gap assessment to a clean Type I or Type II report.
At a glance
- Timeline
- 3 to 4 months to Type I, plus observation window for Type II
- Trust criteria
- Security, plus Availability, Confidentiality, Processing Integrity and Privacy as scoped
- Our role
- Readiness and evidence. The audit stays independent.
- Audit fee
- Paid separately to your auditor
- Pentest
- Expected as control evidence
What this actually is.
SOC 2 is not a certification with a fixed checklist. It is an attestation that the controls you claim actually operate, which is why two companies with the same report can be in completely different security postures. The report is only worth what the scope and the controls behind it are worth.
What we cover.
Who needs this.
- SaaS companies where a customer has made SOC 2 a contract condition
- Businesses moving upmarket into enterprise procurement
- Teams that failed or stalled a previous attempt
- Anyone told a security questionnaire is no longer sufficient
Frequently asked.
Type I or Type II?
Type I proves your controls are designed correctly at a point in time and is the fastest route to unblocking a deal. Type II proves they operated over a period, usually three to twelve months, and is what most enterprise buyers eventually require. Many companies do Type I first and roll into Type II.
Do we need a penetration test for SOC 2?
There is no line item that says penetration test, but auditors expect evidence of independent security testing under the risk assessment and monitoring criteria, and enterprise customers reviewing your report almost always ask. Bundling both is cheaper than sequencing them.
Can we use a compliance automation platform instead?
Those platforms are good at evidence collection and bad at judgement. They will not tell you your scope is wrong or your control design will not survive testing. Use one for evidence and use people for the parts that require thinking.
What if we fail?
A SOC 2 report with exceptions is not a pass or fail, it is a report with exceptions noted, which customers will read. Our job in the observation window is to catch control failures while they are still fixable.
Related services.
The international standard for information security management. Heavier than SOC 2 up front, more durable afterwards, and the one European and Asian enterprise buyers recognise immediately.
SVC 01Web ApplicationYour web application is your largest attack surface and the one your customers touch. We test it the way an attacker would: authenticated, unauthenticated, and everywhere your framework defaults do not reach.
SectorSaaS & TechSecurity is a sales blocker before it is a risk problem. Somewhere in your pipeline there is a deal waiting on a SOC 2 report or a penetration test you have not run yet.
Find out what stands between you and certification.
Start with a gap assessment. You get a specific list of what is missing and a realistic timeline, whether or not you continue with us.