SOC 2 readiness and gap assessment
A tested view of where the control environment stands against the criteria you intend to report against, what is missing, what is weak in operation and what has no evidence behind it. You receive a prioritised remediation plan with owners, effort and a realistic report date.
SOC 2 scope and Trust Services Criteria
We define the systems, services, locations and sub-service organisations in scope, and which of security, availability, confidentiality, processing integrity and privacy you should report against. Scope decided badly is the most expensive mistake in a SOC 2 programme.
Control implementation and remediation
We implement the controls themselves: access administration, authentication, change management, logging and monitoring, vulnerability management, incident response, backup and recovery, vendor oversight and risk assessment. Designed around how your teams actually work.
Policy development
The policy set an examiner will read, written for your organisation rather than lifted from a template library, with named owners, review cycles and approval records that match what the controls do in practice.
Evidence collection and preparation
We establish what evidence each control produces, where it lives, who produces it and on what cadence, then assemble the population and samples the examiner will request so requests do not become a scramble.
Vanta, Drata and Secureframe implementation and support
We work inside the compliance platform you already pay for. Vanta, Drata, Secureframe and comparable tools show which controls are failing; we configure them properly, connect the integrations and do the work the platform cannot do for you.
SOC 2 project management
One plan, one owner list, one timetable and one weekly cadence. We chase internal workstreams, manage the audit firm's requests, track remediation to closure and give leadership a straight answer on whether the report date still holds.
Type I preparation
A Type I reports on the suitability of design at a point in time. We prepare the control descriptions, evidence and system description so the examination can be performed cleanly, and so the same work carries directly into Type II.
Type II preparation and observation-period support
A Type II tests operating effectiveness across a period, commonly three to twelve months. We make sure the controls operate and produce evidence for every day of that window, and we monitor them through it rather than discovering gaps at the end.
CPA audit coordination
We help you select an appropriately licensed independent CPA firm, agree the examination plan and timetable, coordinate every evidence request, brief the people who will be interviewed and manage the flow of questions during fieldwork.
Remediation of audit findings
Where the examiner identifies exceptions or deficiencies, we work through the response: corrective action, control redesign where needed, management responses and the changes required before the next period.
Ongoing SOC 2 compliance
A SOC 2 report covers a period that ends. We keep controls operating, evidence current, exceptions handled and scope changes governed, so the next period is a continuation rather than a rebuild.
SOC 2 with ISO 27001
Run together, one control set and one evidence base serves both, and the marginal cost of the second is a fraction of the first. We map the overlap honestly and identify what genuinely has to be built twice.
SOC 2 for companies selling to enterprise customers
Where the report exists to unblock revenue, the programme is designed around procurement reality: what the buyer asked for, what will satisfy their security review, and how to hold the line credibly until the report is issued.