SOC 2 · Learn
SOC 2, explained.
Guides to the report enterprise buyers open first, written for the people who have to run the programme.
Guides
SOC 2 · Choosing support
How to choose the right SOC 2 consultant
When help is genuinely needed, how the consultant role differs from the auditor's, what should be delivered, and how engagements are priced.
10 min readRead guide →
SOC 2 · Choosing supportWhat should you assess before hiring an SOC 2 consultant?
A scored procurement checklist: scope, evidence ownership, independence, timeline realism and pricing transparency.
11 min readRead guide →
SOC 2 · IntroductionSOC 2 Explained
What the report is, who asks for it, what the auditor checks, and what "we have SOC 2" really means.
8 min readRead guide →
SOC 2 · IntroductionWhat Is SOC 2 Compliance?
What compliance means, what obligations it creates, how long it lasts, and what it does not cover.
8 min readRead guide →
SOC 2 · OverviewSOC 2 compliance
The criteria, the two report types, cost, timelines, who does the work and what follows the report.
9 min readRead guide →
SOC 2 · SequenceHow best to proceed with SOC 2
The right order to run a programme, and the decision that belongs at each stage.
9 min readRead guide →
SOC 2 · DeliveryHow to manage SOC 2 without turning it into a full-time project
The process end to end: scope, report type, control owners, platform, evidence, examination and life after the report.
8 min readRead guide →
SOC 2 · CostThe budget-friendly ways to get SOC 2 compliance
Where the money goes, and the eight decisions that cut a first-year bill without weakening the report.
9 min readRead guide →
SOC 2 · Support modelsSOC 2 vCISO Services
What a retainer should include, what it costs, and when a vCISO beats a project consultant or a hire.
8 min readRead guide →
SOC 2 · United StatesUS SOC 2 consultants
What the US market offers, what fees cover, how sector changes the scope, and what to ask before signing.
8 min readRead guide →
SOC 2 · United KingdomUK SOC 2 consultants
Why a US standard matters here, who can issue the report, what it costs in sterling, and the ISO 27001 overlap.
8 min readRead guide →
SOC 2 · ReportsSOC 2 Type 1 versus Type 2
What each report covers, what they cost, how long each takes, and which one your buyer will accept.
7 min readRead guide →
SOC 2 · Choosing a firmHow to choose a SOC 2 compliance consultant
The nine questions to ask, what a good proposal contains, and how to compare firms fairly.
8 min readRead guide →
Free check
See where you stand on SOC 2, free.
Answer a short set of questions and see what SOC 2 expects of your AI systems and where you stand today. No sign-up to see your result.
Applicability
Whether SOC 2 applies to how you use AI, and to which systems.
What is expected
Risk classification, governance, documentation and human oversight.
Where you stand
A banded result, pointed at the gaps that matter most.
What you get
On screen in about five minutes, pre-scoped to SOC 2.
Or speak to us about your deadline. Book a meeting.