Security — mandatory
The common criteria: access control, change management, risk assessment, monitoring, incident response and vendor management. Every SOC 2 report includes this, and for many companies it is the only criterion required.
Governance, Risk & Compliance
SOC 2 produces a report, not a certificate, and only a licensed CPA firm can issue it. Our job is upstream of that: design the controls against the Trust Services Criteria you actually need, build the evidence trail, and make the audit a formality rather than a discovery process.
SOC 2 is an attestation performed under AICPA standards. A licensed CPA firm examines your controls and issues a report containing their opinion. There is no certificate, no certification body, and no such thing as being "SOC 2 certified" — which is why enterprise procurement teams ask to see the actual report and check who signed it. A vendor whose website claims certification is telling a security reviewer something useful about their rigour before the review has even started.
The second thing buyers underestimate is the observation window. A Type I report says your controls were suitably designed on one specific date. A Type II report says they operated effectively across a period — typically three to twelve months, most commonly six for a first report. That window is real elapsed time during which the controls have to actually run, and evidence has to actually accumulate. It cannot be compressed by working harder in the final fortnight.
The third is scope. Security is the only mandatory criterion. Availability, Processing Integrity, Confidentiality and Privacy are scoped in based on what your product does and what your contracts commit you to. Platforms that bundle all five as standard are selling you audit hours you may not need, and every additional criterion is additional cost in perpetuity.
Coverage
We scope to the commitments in your contracts and the questions in your customers’ security questionnaires — not to whatever produces the largest engagement.
The common criteria: access control, change management, risk assessment, monitoring, incident response and vendor management. Every SOC 2 report includes this, and for many companies it is the only criterion required.
Relevant when you have made uptime commitments in a contract or SLA. Covers capacity planning, environmental protection, backup and disaster recovery.
Relevant where your product processes transactions or performs calculations customers rely on for accuracy and completeness. Frequently not needed, and frequently sold anyway.
Data classification, encryption in transit and at rest, retention and secure disposal — for information designated confidential by agreement.
Notice, choice and consent, collection, use, retention and disclosure of personal information. Distinct from Confidentiality, and often confused with it during scoping.
Type I tests design at a point in time and is sometimes used as an interim milestone. Type II tests operating effectiveness over a window and is what most enterprise buyers actually mean when they ask for a SOC 2.
Approach
The readiness work is ours. The examination is your auditor’s. We are explicit about the boundary, and we work alongside your chosen CPA firm rather than around them.
Which criteria you genuinely need, whether Type I is a useful milestone or a distraction, and an honest gap list against current-state controls.
Close the gaps — access reviews, change management, logging, vendor risk, onboarding and offboarding — grounded in what testing actually found rather than what a template assumed.
Policies that describe what you really do, plus the collection cadence your auditor will sample against. Evidence that has to be assembled by hand will be assembled badly, once.
A point-in-time report for buyers who need something now while the Type II window runs. Optional, and we will tell you when it is not worth the money.
The three to twelve months where controls have to operate rather than exist. We keep evidence collection on schedule and flag drift early, while it is still cheap to fix.
We work directly with your CPA firm through fieldwork and sampling. They test independently and they issue the report — that independence is the entire value of the thing.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Which Trust Services Criteria your contracts actually require, in writing, with the reasoning — so you are not paying to be audited against criteria nobody asked for.
Every control mapped to the criteria it satisfies, with an owner, a frequency and the evidence it produces.
Access, change management, incident response, vendor risk, business continuity and development — written for your organisation.
Organised and dated for CPA sampling, collected continuously rather than reconstructed in the week before fieldwork.
Handed to your CPA firm with nothing left for them to discover, so fieldwork is examination rather than excavation.
Control drift flagged during the window, while it can still be corrected without restarting the period.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No. SOC 2 reports are issued only by licensed CPA firms under AICPA attestation standards. We do the readiness, control design and evidence work that gets you through the examination cleanly, and we work alongside the CPA firm you appoint. If a consultancy tells you they can issue the report, they are describing something that does not exist.
No, and the distinction is worth getting right before a customer corrects you. SOC 2 produces an attestation report containing a CPA firm’s opinion, valid for the period examined. There is no certificate and no certification body. Enterprise buyers ask for the report itself, not a logo.
Almost always Type II. Type I only confirms that controls were suitably designed on a single date, which is a weak signal and one sophisticated buyers discount accordingly. Type I earns its place as an interim deliverable when a deal is waiting and the Type II window has months left to run.
The observation window itself is typically three to twelve months, most commonly six for a first report (as of August 2026), and readiness work happens before it starts. Budget realistically: readiness, then the window, then fieldwork and report issuance. Starting the window before evidence collection works is the most common and most expensive mistake.
No. Security is mandatory. Availability, Processing Integrity, Confidentiality and Privacy are scoped based on your product and your contractual commitments. Each additional criterion adds audit cost every year, so they should be added because a customer requires them, not because they were on a package.
Yes, and it is usually the right call if both are on the horizon. The control overlap is substantial — access management, change control, risk assessment, vendor management and incident response serve both. We map shared evidence once so you are not running two disconnected programmes over the same systems.
Usually not as a priority. ISO 27001 carries more weight with Indian, European and Middle Eastern buyers and tender processes, and DPDP Act readiness is a legal obligation rather than a commercial preference. SOC 2 becomes relevant the moment US or global SaaS buyers enter your pipeline.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.