SOC 2 readiness

SOC 2 readiness, with the evidence already collected

We map your controls to the AICPA Trust Services Criteria, close the gaps before your CPA firm arrives, and collect evidence continuously through the observation period.

Book a SOC 2 assessmentSee a sample report
CriteriaAICPA Trust Services Criteria
Maintained byAICPA
Structure5 categories · Security required
Suited toSaaS and service providers selling to US enterprises
01 · The framework

Trust Services Criteria

Security, the common criteria, is in every SOC 2 report. You choose which of the other four categories apply to the services you provide.

CCSecurityRequired. Protection against unauthorised access, disclosure and damage.
AAvailabilitySystems are available for operation and use as committed.
PIProcessing integrityProcessing is complete, valid, accurate, timely and authorised.
CConfidentialityInformation designated as confidential is protected.
PPrivacyPersonal information is collected, used and disposed of as committed.
02 · Report types

Type I and Type II

Reports are issued by a licensed CPA firm. Most customers ask for Type II.

Type IPoint in timeAssesses whether controls are suitably designed on a specific date.
Type IIObservation periodTests that controls operated effectively over a period, typically 3 to 12 months.
03 · How we assess

Evidence first, interviews second

Every rating is backed by evidence from your environment, so the result reflects what is running, not what the policy says. A baseline typically takes two weeks.

  1. 01ScopeAgree the target, the systems in scope and who we need to speak to.
  2. 02CollectInterviews, document review and live data from Pulse and Trace.
  3. 03ScoreRate every requirement against your target, with evidence for each rating.
  4. 04ReportA prioritised roadmap and a short board briefing.
04 · What you receive

A result you can act on

Findings map across frameworks, so work done for SOC 2 counts towards the others you hold.

✓Scored gap analysisStatus for every requirement against your target, backed by evidence.
✓Prioritised roadmapP1 to P3 work packages with owners, dates and exit criteria.
✓Board briefingA short summary of where you stand and the decisions needed.
✓Evidence kept currentResults live in Attest and update as your environment changes.
Often assessed together
ISO/IEC 27001:2022 NIST Cybersecurity Framework 2.0 CIS 18 (CIS Controls v8.1)

Know where you stand against SOC 2 in two weeks

A baseline assessment with a prioritised roadmap and a board-ready summary.

Book a SOC 2 assessment