We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance
  2. SOC 2
SOC 2 readiness for US companies

SOC 2 readiness that gets you through the observation period clean.

There is no such thing as SOC 2 certification. What exists is an attestation report, written by a licensed CPA firm about your controls, and the Type II version covers a stretch of months rather than a single day. Our job is getting you ready for that: scoping against what your buyers are genuinely asking for, having the controls actually running before the clock starts, and building evidence that piles up from ordinary work rather than being manufactured in a panic the fortnight before fieldwork.

Book a SOC 2 readiness assessmentSee what is involved
SOC 2 readiness preparation for US technology companies
  • Type I or IIPoint in time, or a period
  • 5 categoriesSecurity is the usual scope
  • A CPA firm issues itWe do readiness, not the report
  • 6-12 monthsTypical Type II observation period
What SOC 2 readiness involves

Eight things to settle before an auditor starts work.

The measuring stick is the AICPA Trust Services Criteria, the 2017 set with revised points of focus published in 2022. Readiness means making certain that when a CPA firm samples your controls across an observation window, the evidence is there and stands up to being questioned.

Confirming SOC 2 is what your buyers actually want

The honest first question. SOC 2 is what American enterprise buyers ask for, and for most US companies selling B2B software or services it is the right answer. But if your pipeline includes European or Asian enterprise buyers, ISO 27001 may be requested alongside or instead, and the underlying evidence overlaps heavily. Establish who is actually asking before committing.

Type I against Type II, and why buyers almost always mean the second

Type I speaks to whether your controls were well designed on one specific day. Type II speaks to design and operation across a period, normally six to twelve months. Buyers want the second one overwhelmingly, because knowing a control looked correct on a Tuesday in March tells them nothing about whether it runs. Type I has a genuine use as a stepping stone when a customer needs something immediately, but it is rarely where you stop.

Choosing which Trust Services categories to include

Five exist: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security, the common criteria, appears in essentially every engagement. The rest get added where they reflect a promise you genuinely make to customers. Taking all five because a longer list looks more impressive is a common and expensive mistake, since every category you include is more surface an auditor will test you against.

Writing system descriptions and commitments you can meet

The report contains a description of your system and the commitments you have made to customers, and the auditor tests you against those commitments rather than against some universal standard. There is a quiet trap in that. An ambitious uptime figure or response promise that marketing wrote in 2023 becomes a criterion you are formally measured against. We read those before they harden into something you have to evidence every year.

Evidence that accumulates automatically

A Type II observation period means somebody samples across months, so evidence has to exist for the whole window rather than be assembled the week before fieldwork. Access reviews, change approvals, vulnerability remediation, joiner and leaver records, incident tickets, monitoring alerts. The companies that sail through are the ones where all of that falls out of normal work rather than being manufactured for the auditor.

The controls buyers and auditors both focus on

Logical access and provisioning, change management, risk assessment, vendor management, incident response, and monitoring. The three that most often need genuine work are access reviews that actually happen on a schedule, change management that describes how code truly reaches production, and offboarding that is both fast and documented.

Your cloud platform, and the half of it nobody else is covering

Your cloud provider publishes its own reports and you rely on them, which is entirely legitimate and expected. What they cannot possibly cover is your configuration, your access model, and how you deploy. Auditors have grown precise about exactly where that line falls, so any readiness engagement worth paying for includes reviewing how you have genuinely configured the platform rather than assuming the provider report reaches down to you.

Appointing a CPA firm, which is not us

These reports are issued by licensed CPA firms. We are not one, we cannot issue one, and you should treat anyone offering to handle both the preparation and the attestation with real suspicion. Our part is getting you ready: assessing you against the criteria, closing the gaps, and standing beside you through fieldwork with whichever firm you appoint.

The vocabulary that tells a buyer whether you understand what you bought

This is not a certification, and getting that wrong costs you credibility.

These distinctions read as pedantry and are anything but. The people asking you for a report handle dozens of them a year, and using the wrong word in a security review costs you credibility at precisely the moment you can least afford it.

  • Nobody is certified to SOC 2, and no certificate exists to hang on a wall. A licensed CPA firm issues an attestation report carrying their opinion on your controls. You share that report, normally under an agreement, rather than displaying a badge. A vendor advertising itself as certified is quietly telling every knowledgeable buyer that it never really understood what it purchased.
  • A Type II report covers a defined window, and in practical terms it goes stale. Buyers expect a report covering a recent period, which makes this an annual cycle rather than a project. Budget for a recurring cost and a recurring evidence discipline, not something with a completion date.
  • The criteria are the AICPA Trust Services Criteria, the 2017 set with revised points of focus published in 2022. There is no numbered control list to tick off the way Annex A works in ISO 27001. These are principles-based, meaning your auditor exercises real judgment, which makes the quality of your preparation matter far more than it would in a checklist framework.
  • Scope only what you can defend under questioning. Security on its own is a complete, credible, and extremely common scope. Adding Availability commits you to producing uptime evidence. Adding Confidentiality and Privacy commits you to data handling criteria. Every addition should be there because a customer asked for it or because you genuinely make that promise, never because the list looked a bit thin.
Ask us which scope your buyers actually need
How we work on SOC 2

Four positions we take on readiness engagements.

Readiness is a market with a lot of tooling and not much judgment. Software can collect evidence. It cannot tell you whether your scope is right, whether your commitments are ones you can meet, or whether a control actually operates.

We scope from buyer demand, not ambition

Before anything else we ask which customers are requesting SOC 2, in what form, and with which categories named. Getting the scope wrong is the most expensive mistake available in this area, because every unnecessary category is auditor testing you pay for and evidence you maintain forever. If your buyers also need ISO 27001, we sequence the two so the work is done once.

We do readiness, a CPA firm does the report

That separation is mandatory and worth understanding properly. We assess you against the criteria, close the gaps, build the evidence discipline, and stand beside you through fieldwork. The attestation itself comes from the licensed firm you appoint. We will help you pick one and tell you exactly what to ask them, starting with their experience of companies your size in your sector.

We start the evidence clock before the observation period

Type II samples across months, which means a control that started the same week the window opened produces almost nothing for the auditor to look at early on. We get the controls running properly first and open the observation period only once they genuinely operate. That single sequencing decision is the difference between a clean report and one carrying exceptions you will explain to every prospect who reads it for the next year.

We are still there in year two, which is the year everyone drops it

The first report gets attention, budget, and a project manager. The second gets forgotten until a customer asks for something current and there is a visible gap between observation periods. We keep the controls and the evidence running all year so each cycle repeats rather than rebuilds. Managed clients keep the standard response commitments alongside it: five minutes on critical, ten on high, thirty on the rest.

Who needs this

Six situations where the report genuinely pays for itself.

SOC 2 is worth doing when it removes a specific commercial obstacle. That obstacle is nearly always an enterprise buyer with a procurement process and a security review stage.

A SaaS company selling to enterprise buyers

The clearest case of all. Enterprise buyers routinely require a Type II report before they will sign, and not having one does not lose the deal outright. It stalls it in security review for months, which is considerably worse, because you keep forecasting it. For a company with genuine enterprise pipeline, the report repays itself on shortened sales cycles before you count anything else.

A company whose deals keep stalling in security review

A pattern most sales leaders will recognize: the commercial conversation goes beautifully, a security questionnaire arrives, and the deal then sits untouched for two months. Where that keeps happening with the same profile of buyer, a report addresses the cause rather than the symptom. Before committing, count how many deals it genuinely affects, because the honest answer is sometimes fewer than it feels like at the time.

A fintech or payments business

Financial services buyers apply harder third-party scrutiny than any other sector, and a Type II report covering Security, usually with Availability alongside it, has become close to a baseline expectation. This sector also frequently needs PCI DSS, and the evidence overlaps enough that running both programs together costs meaningfully less than running them one after the other.

A data processing or analytics provider

Holding or processing customer data at any scale usually means Confidentiality gets added alongside Security, and your privacy commitments will be read closely. This is also where customer commitments bite hardest, because whatever your contracts and your website say about how you handle data becomes the standard the auditor measures you against.

A startup approaching a funding round or acquisition

Diligence for a later funding round or an acquisition now routinely covers security posture, and a clean Type II report answers a large share of it in one document. Timing is everything here. Readiness plus an observation period cannot be compressed into the weeks before a data room opens, so this has to start well ahead of any transaction anyone is discussing.

A managed service or outsourcing provider

Operate systems on behalf of clients and their auditors will come asking about you specifically. A report answers that once, rather than through dozens of individually completed questionnaires. For anyone serving regulated clients it has become close to a requirement, and the categories you scope should mirror what you genuinely undertake to deliver.

Three positions

Ready, rushing, or waiting for a customer to ask.

Most first attempts sit squarely in the middle column, and that is where the observation period turns painful, because somebody is sampling months during which the controls were not yet running properly.
Scope and categories chosen from buyer demand
Genuinely ready
Rushing the observation periodGuessed
Not started
Access reviews running on a cadence
Genuinely ready
Rushing the observation periodStarted recently
Not started
Change management covers production honestly
Genuinely ready
Rushing the observation periodPartially
Not started
Evidence accumulates from normal work
Genuinely ready
Rushing the observation period
Not started
Customer commitments reviewed before publication
Genuinely ready
Rushing the observation period
Not startedNot applicable
Vendor management documented
Genuinely ready
Rushing the observation periodThin
Not started
Readiness assessment completed before fieldwork
Genuinely ready
Rushing the observation periodSkipped
Not started
Exceptions expected in the report
Genuinely readyFew or none
Rushing the observation periodSeveral
Not startedNot applicable
Second-year cycle is routine
Genuinely ready
Rushing the observation periodAnother scramble
Not startedNot applicable
Sales cycle actually shortens
Genuinely ready
Rushing the observation periodEventually
Not startedNo
Feature
Genuinely ready
Rushing the observation period
Not started
Scope and categories chosen from buyer demand
Guessed
Access reviews running on a cadence
Started recently
Change management covers production honestly
Partially
Evidence accumulates from normal work
Customer commitments reviewed before publication
Not applicable
Vendor management documented
Thin
Readiness assessment completed before fieldwork
Skipped
Exceptions expected in the report
Few or noneSeveralNot applicable
Second-year cycle is routine
Another scrambleNot applicable
Sales cycle actually shortens
EventuallyNo
SOC 2 against ISO 27001

Two frameworks, and how to work out which one is actually being asked for.

An American company selling to American enterprises will be asked for SOC 2 nearly every time. ISO 27001 appears once your pipeline includes international buyers or global procurement frameworks. The underlying security work overlaps enormously, so a company that eventually needs both does not do the whole thing twice.

What it is

SOC 2
An attestation report
ISO 27001
A certification of a management system

Who issues it

SOC 2
A licensed CPA firm
ISO 27001
An accredited certification body

Who usually asks for it

SOC 2
US enterprise buyers
ISO 27001
International and global buyers

What you receive

SOC 2
A detailed report you share privately
ISO 27001
A certificate you can display

Criteria structure

SOC 2
Principles-based criteria and points of focus
ISO 27001
93 Annex A controls plus clauses 4 to 10

Scope decision

SOC 2
Which of five categories
ISO 27001
Which parts of the organization

Covers a period

SOC 2
Type II does, typically 6 to 12 months
ISO 27001
Certificate valid three years with surveillance

Recurring commitment

SOC 2
Annual report cycle
ISO 27001
Annual surveillance, three-year recertification

Emphasis on management system

SOC 2
Lighter
ISO 27001
Heavy, clauses 4 to 10

Evidence reusable for the other

SOC 2
Substantially
ISO 27001
Substantially
SOC 2ISO 27001
What it isAn attestation reportA certification of a management system
Who issues itA licensed CPA firmAn accredited certification body
Who usually asks for itUS enterprise buyersInternational and global buyers
What you receiveA detailed report you share privatelyA certificate you can display
Criteria structurePrinciples-based criteria and points of focus93 Annex A controls plus clauses 4 to 10
Scope decisionWhich of five categoriesWhich parts of the organization
Covers a periodType II does, typically 6 to 12 monthsCertificate valid three years with surveillance
Recurring commitmentAnnual report cycleAnnual surveillance, three-year recertification
Emphasis on management systemLighterHeavy, clauses 4 to 10
Evidence reusable for the otherSubstantiallySubstantially
How a readiness engagement runs

Five stages, with the observation period living inside the final one.

Nine to fifteen months to a first Type II report, and most of that is the observation window rather than work. What determines whether that window produces a clean report is everything done before it opens.
  1. 1

    Confirm the demand, and fix the scope

    Who is actually asking, whether they mean Type I or Type II, which Trust Services categories apply, and precisely which system falls in scope. We also read your published customer commitments at this stage, because those become criteria you get tested against, and they are enormously easier to adjust now than during fieldwork.

  2. 2

    Readiness assessment against the criteria

    A gap assessment against the criteria in your chosen categories, with an effort estimate on every finding. This deliberately happens before you appoint anyone, so that fieldwork starts from a known position rather than you discovering the gaps at your own expense partway through the observation window.

  3. 3

    Remediate, and get controls genuinely operating

    Access reviews on a real schedule, change management describing what genuinely happens, offboarding that is quick and documented, vendor management, risk assessment, incident handling, and monitoring. The goal is never documentation. It is controls that run as part of ordinary work and leave a trail without anybody being asked to produce one.

  4. 4

    Open the observation period once controls are running

    Six to twelve months for a Type II. We deliberately open it after the controls are genuinely operating rather than on the day they were switched on, because an auditor sampling the first month of a control that began that same month finds very little and writes that down.

  5. 5

    Support fieldwork, then run the annual cycle

    We assemble the evidence, answer the auditor requests, and run the process through to an issued report. Then comes the part that matters commercially: keeping the controls and the evidence running so the next period follows on continuously. Buyers ask for current reports, and a visible gap between observation periods is a question you would much rather not be answering.

Straight answers

What US companies ask about SOC 2.

No, and the distinction has commercial consequences. This is an attestation: a licensed CPA firm examines your controls and issues a report carrying their opinion. No certificate exists and no certification body is involved. You share the report with buyers, normally under a confidentiality agreement, rather than displaying a badge on your website. Describing yourself as certified signals to any knowledgeable buyer that you never fully understood what you bought, which is not the impression you want to leave halfway through a security review.

Type I speaks only to whether your controls were suitably designed on a specific date. Type II speaks to design and operating effectiveness across a period, normally six to twelve months, with evidence sampled throughout that window. Buyers almost invariably mean Type II, because knowing a control was well designed on one particular Tuesday says nothing about whether anyone runs it. Type I has a legitimate use when a customer needs something immediately, but treat it as a stepping stone rather than a destination.

Five exist: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security, the common criteria, appears in essentially every report and stands as a complete and credible scope entirely on its own. Add the others only where they mirror a promise you genuinely make, so Availability if you commit to uptime figures, Confidentiality if you undertake specific handling of customer data. Each extra category is more ground for an auditor to test, so scope from what buyers are asking rather than from ambition.

Only where your buyers are asking for it, which for an American company generally means international enterprise customers or a global procurement framework. The underlying control work overlaps heavily, so adding the second framework later costs far less than doubling. What genuinely differs is the wrapper around it. ISO 27001 wants the management system clauses, an internal audit, and a management review. This wants the system description, the commitments, and the observation period. Ask your five most important prospects what they actually require before spending anything.

Nine to fifteen months end to end for a first Type II, and the majority of that is waiting rather than working. The assessment and remediation take roughly two to four months at a company with a reasonable engineering culture. The observation window then runs six to twelve months. Fieldwork and issuing the report take a few weeks after that. Anyone promising you a Type II inside three months is describing either an observation period so short your buyers may refuse it, or a Type I.

No. These reports come from licensed CPA firms, and there is a deliberate independence line between whoever prepares you and whoever attests. We handle readiness: the gap assessment against the criteria, the remediation, the evidence discipline, and support through fieldwork. You appoint the firm, and we help you choose, including what to ask about their experience with companies your size in your sector, which varies far more than most people expect.

It helps considerably with gathering evidence and it is nowhere near sufficient alone. Tooling is excellent at collecting artifacts and rendering a dashboard. It cannot tell you whether your scope is right, whether the commitments in your contracts are ones you can actually meet, or whether a control showing green genuinely operates the way the criteria intend. The failure we see most often is a fully green dashboard sitting alongside access reviews that were scheduled and never once performed. The tool records that as configured. The auditor records it as an exception.

Logical access, every single time. Who holds access, how they got it, whether anyone reviewed it, and how fast it disappeared when they resigned. Leavers get sampled specifically, and slow or undocumented offboarding shows up immediately. After that comes change management, particularly whether the documented process describes how code genuinely reaches production including the emergency route, then vendor management, incident handling, and risk assessment. Fix access and change management properly and you have removed most of your exception risk.

An exception gets noted in the report alongside your management response, and the report still gets issued. They are not fatal, and one well-explained exception with a clear remediation attached is not a disaster. What they cost is time in every future sales conversation, because prospects read the report properly and ask about each one. That is exactly why we insist on readiness before fieldwork, and on opening the observation period only once the controls genuinely run.

It covers them and not you. Relying on your provider report for the infrastructure they operate is entirely legitimate and expected, and you should hold a copy and review it as part of vendor management. What it never covers is how you configured that platform, your access model, how you deploy, or your application. Auditors are precise about exactly where that boundary falls, and misunderstanding it is one of the most common first-time errors, especially among engineering teams who quite reasonably assume the provider attestation extends downward to them.

They are separate obligations that happen to overlap. SOC 2 is a contractual and commercial instrument driven by your customers, while HIPAA, the state privacy laws, and PCI DSS apply as legal or contractual obligations regardless of whether anybody asks for a report. Much of the control work serves all of them: access governance, change management, vendor oversight, incident response, and logging. What SOC 2 will not do is discharge those obligations, and we map the overlap so you are not surprised by a requirement no customer ever mentioned, with your counsel or assessor owning the interpretation.

Ask your five most important customers or prospects what they genuinely require, in exactly those words, and get the answer in writing from somebody in their security or procurement function rather than from an account manager. That one exercise settles Type I against Type II, tells you which categories to scope, and decides whether ISO 27001 belongs anywhere in the plan. It costs nothing, takes a week, and it is the step companies skip most often before spending a great deal of money. The CPA firm bills separately for the examination itself. Our readiness work is scoped against how far your current controls sit from the criteria, and we will tell you at the outset what drives both numbers.
SOC 2 readiness

Fifteen checks before you appoint an auditor.

The first set decides whether to do this at all and in what shape. The second covers the controls carrying the most audit weight. The third is the evidence discipline that makes a Type II observation period survivable rather than miserable.

Decide the shape

  • Which named customers or prospects have actually asked for this?
    Get it in writing from their security or procurement team.
  • Do they want Type I or Type II?
    Almost always Type II. Ask rather than assume.
  • Which Trust Services categories have they named?
    Security alone is a complete and common scope.
  • What system and services are in scope?
    The product they buy, and the infrastructure behind it.
  • Have you appointed a licensed CPA firm?
    Separate from whoever does your readiness work.

The controls that carry weight

  • Do access reviews genuinely happen on a schedule, with evidence left behind?
    Sampled more often than anything else, and missing more often than anything else.
  • Does change management cover production deployments honestly?
    Including emergency changes, which auditors always ask about.
  • Is offboarding fast and evidenced?
    Auditors sample leavers. Slow removal is visible immediately.
  • Do you run a documented risk assessment?
    A criterion in its own right, not just good practice.
  • Do you assess and monitor your own vendors?
    Including your cloud provider and any subprocessors.

Evidence through the observation period

  • Does the evidence pile up on its own, or does somebody go and make it?
    The single best predictor of a smooth Type II.
  • Are alerts and incidents ticketed, with resolution recorded?
    A sampled incident with no trail is a finding.
  • Are vulnerabilities tracked to remediation with dates?
    Scanning without remediation evidence proves nothing.
  • Has anybody read your customer commitments to see what they actually promise?
    You will be tested against your own wording.
  • Is somebody accountable for keeping this true year-round?
    The report is annual. The controls are continuous.
Related reading

The pages around this one.

Compliance services

The wider compliance practice: HIPAA, CMMC, state privacy laws, and how the frameworks overlap.

Learn more

Access rights review

The most frequently sampled SOC 2 control, designed so it actually removes access.

Learn more

Vulnerability assessment

The identification and remediation-tracking evidence your auditor samples.

Learn more
Next step

Find out what your buyers are actually asking for.

That answer decides Type I or Type II, which categories to scope, and whether ISO 27001 belongs in the plan. We will help you ask the question properly, then run a readiness assessment against the criteria so fieldwork starts from a known position rather than an expensive surprise.

Book a SOC 2 readiness assessmentSee compliance services

Related Services

Explore more solutions that work great with this service

Access Rights Review and Certification

Recurring access certification your auditors accept

Learn more

Vulnerability Assessment

Vulnerability assessment for US businesses across external attack

Learn more

Penetration Testing

Penetration testing for US businesses across external, internal, web

Learn more

IT Compliance

HIPAA, SOC 2, NIST, CMMC, CCPA readiness

Learn more

Microsoft Purview

Data governance and compliance solutions

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA