Hael
Book a meeting
SOC 2 · Sequence

How best to proceed with SOC 2

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 9 min read
Key takeaways
  • Start with the buyer conversation, not with the framework. What they will accept decides your scope, your report type and your budget.
  • Decide scope and criteria before speaking to auditors, because both are priced from them.
  • Run the gap assessment before booking the audit window, so remediation happens on your schedule rather than the auditor's.
  • The observation period cannot be shortened once started, so it belongs early in the plan, not late.
  • Plan the year after the report at the same time as the report itself.

Proceed in this order

Proceed in this order: find out exactly what your buyer will accept, set the scope from that, assess the gap, fix it, then start the observation period and support the examination. The most common mistake is starting with the framework rather than the buyer, which produces a report that is larger, later and more expensive than the one that would have closed the deal.

Each stage below carries one or two decisions that are hard to reverse afterwards. Those are the ones worth slowing down for.

Stage 1: The buyer conversation

Before anything else, get the requirement in writing. Ask three questions.

Which report do you need, Type 1 or Type 2? These carry very different timelines and costs, and buyers often say "SOC 2" without having decided.

Which systems and services does it need to cover? This defines your scope, and getting it from the buyer rather than guessing prevents both directions of error.

What is the actual deadline, and what happens if we miss it? Sometimes the date is contractual. Often it is aspirational, and knowing which changes your whole plan.

If they will accept an ISO 27001 certificate instead, that is worth knowing too, particularly for a European company. Our ISO 27001 service page sets out how the two compare.

Decision at this stage: whether you need SOC 2 at all, and which report.

Stage 2: Scope and criteria

Scope is the single most consequential decision in the programme. It sets the auditor's fee, the volume of evidence, the internal hours and whether the finished report answers the buyer's question.

Define the system boundary: which product, which environment, which infrastructure, which data. Name what is excluded as well as what is included.

Then select criteria. Security is mandatory. Add Availability, Processing Integrity, Confidentiality or Privacy only where a customer has asked or your contracts commit you.

Decision at this stage: the system boundary and the criteria. Both are difficult to change once the examination is agreed.

Stage 3: Ownership

Name the person who owns the programme and protect their hours. This is the point at which you also decide whether you need external help, and the honest test is whether that person has both the experience and the available time.

If you are bringing in a firm, this is when to do it, not after the gap assessment. A consultant who joins after the scope is set inherits decisions they would have advised against.

Decision at this stage: internal, external, or a combination, and who specifically.

Stage 4: Gap assessment

A structured comparison of your current position against each criterion in scope, stating what is met, what is not, and what closes each gap.

Do this before booking an audit window. A gap found here is fixed on your timetable. The same gap found during fieldwork is fixed under pressure, is billed for by the auditor, and can require re-testing that extends the period.

Our readiness and gap assessment delivers this as a fixed fee with a delivery call, so the remediation plan is agreed before any implementation work begins.

Decision at this stage: the remediation plan and who does each item.

Stage 5: Build and remediate

Write the policies so they describe your actual company. Configure the controls: access management, change approval, logging, monitoring, vulnerability management, vendor oversight, incident response. Establish who collects what evidence and on what schedule.

Design each control so operating it leaves a dated record automatically, rather than requiring someone to gather proof later. This is the difference between a comfortable observation period and an uncomfortable one.

Commission the penetration test here rather than at the end. Buyers expect recent results, and finding something significant late is expensive.

Decision at this stage: which processes genuinely change, versus which documents change.

Stage 6: Select the auditor and set the window

Speak to two or three CPA firms. Compare on sector experience, availability against your target date, and how they handle evidence exchange, not on fee alone.

Agree the observation period length. Three months is the shortest most firms accept and gets a report out soonest. Six months is more common for a first report and tests quarterly controls more fairly.

Decision at this stage: the firm and the window. The window cannot be shortened once it starts.

Stage 7: Run the observation period

This is where programmes drift. Nothing is due, everyone returns to normal work, and the controls have to keep operating anyway.

Put every recurring control in a calendar with a named owner. Check the record monthly rather than annually. A missed access review found in week six is a five-minute fix. The same gap found by the auditor in month eleven is an exception in the report.

Decision at this stage: none, if the earlier stages were done properly. That is the point of them.

Stage 8: Examination and report

The auditor requests evidence, tests samples across the period, and interviews the people who operate the controls. Brief those people beforehand, so they can describe the process in their own words and it matches the documentation.

Findings are handled during fieldwork where possible. The opinion and the report come from the CPA firm alone.

Stage 9: The year after

The day the report is issued, the next period has already begun. Controls that stop in month two will appear in next year's examination.

Plan the second year at the same time as the first: who keeps the cadence running, who answers buyer questionnaires from the report, who watches for changes in your systems that take a control out of scope. Second-year cost typically falls by around a third, but only for companies whose controls kept running. That is the work our continuous governance and assurance service covers.

The order in one table

StageOutputDecision that is hard to reverse
1. Buyer conversationWritten requirementWhether you need SOC 2, and which report
2. Scope and criteriaSystem boundary and criteria listBoth, once the examination is agreed
3. OwnershipA named owner with protected hoursInternal, external or both
4. Gap assessmentRequirement-by-requirement findingsThe remediation plan
5. Build and remediatePolicies, controls, evidence frameworkWhich processes actually change
6. Auditor and windowEngagement letter, period start dateThe window length
7. Observation periodAccumulated evidenceNone, if stages 1 to 6 were done
8. ExaminationThe reportNone
9. The year afterA running programmeWho keeps it running

What to do next

If you have not yet had stage 1 in writing, do that before anything else. It is free and it changes more of the plan than any other single action.

Our free readiness diagnostic gives a first view of where you stand, and the SOC 2 service page sets out how we run the stages above end to end.

References

FAQ

What is the first step in a SOC 2 programme?

Getting your buyer's requirement in writing: which report type, which systems, and the real deadline. That answer sets the scope and the budget.

Should we do the gap assessment before choosing an auditor?

Yes. Remediation is cheaper and calmer on your own timetable than during fieldwork, and knowing your gaps makes the auditor conversation more accurate.

How long does the whole process take?

Six to ten weeks to be ready for a Type 1. Nine to twelve months for a first Type 2, because the observation period runs forward and cannot be compressed.

When should we bring in outside help?

Before scope is set, if you are going to at all. A firm that joins later inherits decisions it would have advised against.

What happens after the report is issued?

The next observation period has already started. Controls have to keep operating, and buyers will ask questions from the report, so someone needs to own both.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through SOC 2, ISO 27001, ISO/IEC 42001 and the EU AI Act, from first assessment to report, and maintain the position afterwards. We do the work rather than only advising on it, and every engagement has a named practitioner and an agreed scope, timetable and fee. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on SOC 2, free.

Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether SOC 2 applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to SOC 2.

Or speak to us about your deadline. Book a meeting.