SOC 2 readiness that gets you through the observation period clean.
There is no such thing as SOC 2 certification. What exists is an attestation report, written by a licensed CPA firm about your controls, and the Type II version covers a stretch of months rather than a single day. Our job is getting you ready for that: scoping against what your buyers are genuinely asking for, having the controls actually running before the clock starts, and building evidence that piles up from ordinary work rather than being manufactured in a panic the fortnight before fieldwork.

- Type I or IIPoint in time, or a period
- 5 categoriesSecurity is the usual scope
- A CPA firm issues itWe do readiness, not the report
- 6-12 monthsTypical Type II observation period
Eight things to settle before an auditor starts work.
Confirming SOC 2 is what your buyers actually want
The honest first question. SOC 2 is what American enterprise buyers ask for, and for most US companies selling B2B software or services it is the right answer. But if your pipeline includes European or Asian enterprise buyers, ISO 27001 may be requested alongside or instead, and the underlying evidence overlaps heavily. Establish who is actually asking before committing.
Type I against Type II, and why buyers almost always mean the second
Type I speaks to whether your controls were well designed on one specific day. Type II speaks to design and operation across a period, normally six to twelve months. Buyers want the second one overwhelmingly, because knowing a control looked correct on a Tuesday in March tells them nothing about whether it runs. Type I has a genuine use as a stepping stone when a customer needs something immediately, but it is rarely where you stop.
Choosing which Trust Services categories to include
Five exist: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security, the common criteria, appears in essentially every engagement. The rest get added where they reflect a promise you genuinely make to customers. Taking all five because a longer list looks more impressive is a common and expensive mistake, since every category you include is more surface an auditor will test you against.
Writing system descriptions and commitments you can meet
The report contains a description of your system and the commitments you have made to customers, and the auditor tests you against those commitments rather than against some universal standard. There is a quiet trap in that. An ambitious uptime figure or response promise that marketing wrote in 2023 becomes a criterion you are formally measured against. We read those before they harden into something you have to evidence every year.
Evidence that accumulates automatically
A Type II observation period means somebody samples across months, so evidence has to exist for the whole window rather than be assembled the week before fieldwork. Access reviews, change approvals, vulnerability remediation, joiner and leaver records, incident tickets, monitoring alerts. The companies that sail through are the ones where all of that falls out of normal work rather than being manufactured for the auditor.
The controls buyers and auditors both focus on
Logical access and provisioning, change management, risk assessment, vendor management, incident response, and monitoring. The three that most often need genuine work are access reviews that actually happen on a schedule, change management that describes how code truly reaches production, and offboarding that is both fast and documented.
Your cloud platform, and the half of it nobody else is covering
Your cloud provider publishes its own reports and you rely on them, which is entirely legitimate and expected. What they cannot possibly cover is your configuration, your access model, and how you deploy. Auditors have grown precise about exactly where that line falls, so any readiness engagement worth paying for includes reviewing how you have genuinely configured the platform rather than assuming the provider report reaches down to you.
Appointing a CPA firm, which is not us
These reports are issued by licensed CPA firms. We are not one, we cannot issue one, and you should treat anyone offering to handle both the preparation and the attestation with real suspicion. Our part is getting you ready: assessing you against the criteria, closing the gaps, and standing beside you through fieldwork with whichever firm you appoint.
This is not a certification, and getting that wrong costs you credibility.
These distinctions read as pedantry and are anything but. The people asking you for a report handle dozens of them a year, and using the wrong word in a security review costs you credibility at precisely the moment you can least afford it.
- Nobody is certified to SOC 2, and no certificate exists to hang on a wall. A licensed CPA firm issues an attestation report carrying their opinion on your controls. You share that report, normally under an agreement, rather than displaying a badge. A vendor advertising itself as certified is quietly telling every knowledgeable buyer that it never really understood what it purchased.
- A Type II report covers a defined window, and in practical terms it goes stale. Buyers expect a report covering a recent period, which makes this an annual cycle rather than a project. Budget for a recurring cost and a recurring evidence discipline, not something with a completion date.
- The criteria are the AICPA Trust Services Criteria, the 2017 set with revised points of focus published in 2022. There is no numbered control list to tick off the way Annex A works in ISO 27001. These are principles-based, meaning your auditor exercises real judgment, which makes the quality of your preparation matter far more than it would in a checklist framework.
- Scope only what you can defend under questioning. Security on its own is a complete, credible, and extremely common scope. Adding Availability commits you to producing uptime evidence. Adding Confidentiality and Privacy commits you to data handling criteria. Every addition should be there because a customer asked for it or because you genuinely make that promise, never because the list looked a bit thin.
Four positions we take on readiness engagements.
We scope from buyer demand, not ambition
Before anything else we ask which customers are requesting SOC 2, in what form, and with which categories named. Getting the scope wrong is the most expensive mistake available in this area, because every unnecessary category is auditor testing you pay for and evidence you maintain forever. If your buyers also need ISO 27001, we sequence the two so the work is done once.
We do readiness, a CPA firm does the report
That separation is mandatory and worth understanding properly. We assess you against the criteria, close the gaps, build the evidence discipline, and stand beside you through fieldwork. The attestation itself comes from the licensed firm you appoint. We will help you pick one and tell you exactly what to ask them, starting with their experience of companies your size in your sector.
We start the evidence clock before the observation period
Type II samples across months, which means a control that started the same week the window opened produces almost nothing for the auditor to look at early on. We get the controls running properly first and open the observation period only once they genuinely operate. That single sequencing decision is the difference between a clean report and one carrying exceptions you will explain to every prospect who reads it for the next year.
We are still there in year two, which is the year everyone drops it
The first report gets attention, budget, and a project manager. The second gets forgotten until a customer asks for something current and there is a visible gap between observation periods. We keep the controls and the evidence running all year so each cycle repeats rather than rebuilds. Managed clients keep the standard response commitments alongside it: five minutes on critical, ten on high, thirty on the rest.
Six situations where the report genuinely pays for itself.
A SaaS company selling to enterprise buyers
The clearest case of all. Enterprise buyers routinely require a Type II report before they will sign, and not having one does not lose the deal outright. It stalls it in security review for months, which is considerably worse, because you keep forecasting it. For a company with genuine enterprise pipeline, the report repays itself on shortened sales cycles before you count anything else.
A company whose deals keep stalling in security review
A pattern most sales leaders will recognize: the commercial conversation goes beautifully, a security questionnaire arrives, and the deal then sits untouched for two months. Where that keeps happening with the same profile of buyer, a report addresses the cause rather than the symptom. Before committing, count how many deals it genuinely affects, because the honest answer is sometimes fewer than it feels like at the time.
A fintech or payments business
Financial services buyers apply harder third-party scrutiny than any other sector, and a Type II report covering Security, usually with Availability alongside it, has become close to a baseline expectation. This sector also frequently needs PCI DSS, and the evidence overlaps enough that running both programs together costs meaningfully less than running them one after the other.
A data processing or analytics provider
Holding or processing customer data at any scale usually means Confidentiality gets added alongside Security, and your privacy commitments will be read closely. This is also where customer commitments bite hardest, because whatever your contracts and your website say about how you handle data becomes the standard the auditor measures you against.
A startup approaching a funding round or acquisition
Diligence for a later funding round or an acquisition now routinely covers security posture, and a clean Type II report answers a large share of it in one document. Timing is everything here. Readiness plus an observation period cannot be compressed into the weeks before a data room opens, so this has to start well ahead of any transaction anyone is discussing.
A managed service or outsourcing provider
Operate systems on behalf of clients and their auditors will come asking about you specifically. A report answers that once, rather than through dozens of individually completed questionnaires. For anyone serving regulated clients it has become close to a requirement, and the categories you scope should mirror what you genuinely undertake to deliver.
Ready, rushing, or waiting for a customer to ask.
| Feature | Genuinely ready | Rushing the observation period | Not started |
|---|---|---|---|
Scope and categories chosen from buyer demand | Guessed | ||
Access reviews running on a cadence | Started recently | ||
Change management covers production honestly | Partially | ||
Evidence accumulates from normal work | |||
Customer commitments reviewed before publication | Not applicable | ||
Vendor management documented | Thin | ||
Readiness assessment completed before fieldwork | Skipped | ||
Exceptions expected in the report | Few or none | Several | Not applicable |
Second-year cycle is routine | Another scramble | Not applicable | |
Sales cycle actually shortens | Eventually | No |
Two frameworks, and how to work out which one is actually being asked for.
What it is
- SOC 2
- An attestation report
- ISO 27001
- A certification of a management system
Who issues it
- SOC 2
- A licensed CPA firm
- ISO 27001
- An accredited certification body
Who usually asks for it
- SOC 2
- US enterprise buyers
- ISO 27001
- International and global buyers
What you receive
- SOC 2
- A detailed report you share privately
- ISO 27001
- A certificate you can display
Criteria structure
- SOC 2
- Principles-based criteria and points of focus
- ISO 27001
- 93 Annex A controls plus clauses 4 to 10
Scope decision
- SOC 2
- Which of five categories
- ISO 27001
- Which parts of the organization
Covers a period
- SOC 2
- Type II does, typically 6 to 12 months
- ISO 27001
- Certificate valid three years with surveillance
Recurring commitment
- SOC 2
- Annual report cycle
- ISO 27001
- Annual surveillance, three-year recertification
Emphasis on management system
- SOC 2
- Lighter
- ISO 27001
- Heavy, clauses 4 to 10
Evidence reusable for the other
- SOC 2
- Substantially
- ISO 27001
- Substantially
Five stages, with the observation period living inside the final one.
- 1
Confirm the demand, and fix the scope
Who is actually asking, whether they mean Type I or Type II, which Trust Services categories apply, and precisely which system falls in scope. We also read your published customer commitments at this stage, because those become criteria you get tested against, and they are enormously easier to adjust now than during fieldwork.
- 2
Readiness assessment against the criteria
A gap assessment against the criteria in your chosen categories, with an effort estimate on every finding. This deliberately happens before you appoint anyone, so that fieldwork starts from a known position rather than you discovering the gaps at your own expense partway through the observation window.
- 3
Remediate, and get controls genuinely operating
Access reviews on a real schedule, change management describing what genuinely happens, offboarding that is quick and documented, vendor management, risk assessment, incident handling, and monitoring. The goal is never documentation. It is controls that run as part of ordinary work and leave a trail without anybody being asked to produce one.
- 4
Open the observation period once controls are running
Six to twelve months for a Type II. We deliberately open it after the controls are genuinely operating rather than on the day they were switched on, because an auditor sampling the first month of a control that began that same month finds very little and writes that down.
- 5
Support fieldwork, then run the annual cycle
We assemble the evidence, answer the auditor requests, and run the process through to an issued report. Then comes the part that matters commercially: keeping the controls and the evidence running so the next period follows on continuously. Buyers ask for current reports, and a visible gap between observation periods is a question you would much rather not be answering.
What US companies ask about SOC 2.
Fifteen checks before you appoint an auditor.
Decide the shape
- Which named customers or prospects have actually asked for this?Get it in writing from their security or procurement team.
- Do they want Type I or Type II?Almost always Type II. Ask rather than assume.
- Which Trust Services categories have they named?Security alone is a complete and common scope.
- What system and services are in scope?The product they buy, and the infrastructure behind it.
- Have you appointed a licensed CPA firm?Separate from whoever does your readiness work.
The controls that carry weight
- Do access reviews genuinely happen on a schedule, with evidence left behind?Sampled more often than anything else, and missing more often than anything else.
- Does change management cover production deployments honestly?Including emergency changes, which auditors always ask about.
- Is offboarding fast and evidenced?Auditors sample leavers. Slow removal is visible immediately.
- Do you run a documented risk assessment?A criterion in its own right, not just good practice.
- Do you assess and monitor your own vendors?Including your cloud provider and any subprocessors.
Evidence through the observation period
- Does the evidence pile up on its own, or does somebody go and make it?The single best predictor of a smooth Type II.
- Are alerts and incidents ticketed, with resolution recorded?A sampled incident with no trail is a finding.
- Are vulnerabilities tracked to remediation with dates?Scanning without remediation evidence proves nothing.
- Has anybody read your customer commitments to see what they actually promise?You will be tested against your own wording.
- Is somebody accountable for keeping this true year-round?The report is annual. The controls are continuous.
The pages around this one.
Compliance services
The wider compliance practice: HIPAA, CMMC, state privacy laws, and how the frameworks overlap.
Access rights review
The most frequently sampled SOC 2 control, designed so it actually removes access.
Vulnerability assessment
The identification and remediation-tracking evidence your auditor samples.
Find out what your buyers are actually asking for.
That answer decides Type I or Type II, which categories to scope, and whether ISO 27001 belongs in the plan. We will help you ask the question properly, then run a readiness assessment against the criteria so fieldwork starts from a known position rather than an expensive surprise.
Related Services
Explore more solutions that work great with this service
Access Rights Review and Certification
Recurring access certification your auditors accept
Learn moreVulnerability Assessment
Vulnerability assessment for US businesses across external attack
Learn morePenetration Testing
Penetration testing for US businesses across external, internal, web
Learn moreIT Compliance
HIPAA, SOC 2, NIST, CMMC, CCPA readiness
Learn moreMicrosoft Purview
Data governance and compliance solutions
Learn more