Audit readiness
SaaS audit readiness
Audit-ready is a specific state, not a feeling. It means every control you claim has an owner, a frequency, and a record you can produce in the room without going to look for it.
The context
Why this is different
The word ready does a lot of hiding. Teams describe themselves as nearly ready when they have policies written, and then fail Stage 1 because nobody has run an internal audit. Others have excellent operational security and no records, which is invisible to an auditor because an auditor can only assess what you can evidence.
The useful definition is narrow. You are audit-ready when three things are true: the mandatory documents exist and agree with each other, every control you claimed has been operating long enough to have produced records, and each named control owner can describe their own control in a fifteen minute conversation.
That last one gets overlooked and causes more findings than any technical gap. Your access control policy can be excellent, but if the engineer who runs the quarterly review cannot describe how they do it, the auditor records a finding against the control rather than against the document.
What we look for
The failure classes that actually show up.
The internal audit was never run
Mandatory under ISO 27001 Clause 9.2 and the most common reason a Stage 1 gets delayed. It is a two-week fix that surfaces at the worst possible moment, and it usually pushes Stage 2 by a month because of scheduling.
No management review record
Clause 9.3 requires top management to review the ISMS, with specific inputs listed in 9.3.2. Minutes written against those headings take an hour to produce and are checked off item by item.
Policies describing a company you intend to become
The access control policy says quarterly reviews; you have run one. You have written your own nonconformity. Document what you actually do, then improve the practice, rather than the other way round.
A risk register with one date on it
Populated in a single sitting the week before. Real risk management leaves history: entries added over time, dated acceptance decisions with named approvers, and at least one reassessment triggered by a change.
Scope that contradicts another document
The scope statement says three environments, the asset inventory lists four. Cheap to fix, expensive to discover in the room, and it prompts the auditor to start checking other documents against each other.
Controls operating without records
Access reviews performed in a meeting with no output, offboarding done carefully but never logged, vendor checks that happened in someone's head. The control works; the evidence does not exist.
Security testing booked too late
Annex A 8.8 and 8.29 are hard to evidence without independent testing, and turning up with open criticals is worse than turning up with nothing. Testing needs enough runway to remediate and retest.
Control owners who have not read their control
Auditors interview owners directly. Fifteen minutes of preparation per person removes an entire category of finding, and almost nobody does it.
How we test it
The engagement.
- 01
Establish which framework, and why
US enterprise buyers usually ask for SOC 2; European, UK, Middle Eastern and APAC buyers usually ask for ISO 27001. If both are on the roadmap inside a year, run them as one programme. The control overlap is roughly 80% and doing them sequentially pays for the same evidence work twice.
- 02
Scope, inventory, gap analysis
Scope statement, asset and environment inventory, then a control-by-control assessment producing a prioritised backlog with owners and effort estimates. Everything downstream depends on these being right.
- 03
Start the risk register early
In week two, not week ten, so that it has genuine review history by the time an auditor looks at it. This is the one item where starting late cannot be recovered by working harder.
- 04
Build controls and evidence together
Every control gets an owner, a frequency and a defined evidence artefact at the point it is implemented, rather than reconstructing evidence later. The evidence pack should build continuously.
- 05
Test, remediate, retest
Independent security testing scheduled early enough that findings are closed and verified before the audit. The retest report is the evidence, not the original findings.
- 06
Internal audit, management review, owner briefings
Run the internal audit properly so it finds what the external auditor would. Hold the management review against the required inputs. Brief every control owner on their own control.
What you get
Deliverables
- From
- $9,500
- Typical duration
- 12 to 20 weeks
- Gap analysis with a prioritised, owned remediation backlog
- Scope statement and Statement of Applicability, or SOC 2 control matrix
- Risk methodology, register and treatment plan
- Complete policy set written to match how your team actually works
- Evidence pack mapped control by control
- Internal audit report and management review minutes
- Control owner briefing pack, one page per owner
- Stage 1 and Stage 2 support, or CPA firm coordination for SOC 2
Questions
The ones engineers ask.
Three tests. Can you produce every mandatory document without searching for it? Has every control you claimed produced at least one record? Can each named owner describe their control unprompted? If all three are yes, you are ready. If any is no, you are not, regardless of how complete the documentation looks.
For a 10 to 100 person SaaS company with MFA enforced and infrastructure as code, 12 to 20 weeks to audit-ready. Add the certification body or CPA firm's own scheduling on top, which is frequently the longest pole in the project.
Partly. Platforms handle evidence collection and drift monitoring genuinely well. They do not scope your ISMS, run a defensible risk assessment, write policies matched to your business, conduct your internal audit, or defend a control decision to an auditor. Use both; we work alongside whichever platform you have.
Tell us on the scoping call and we will work backwards from it. Sometimes the honest answer is to move the date. A failed audit costs more than a rescheduled one, and it is visible to the certification body for a long time afterwards.
There is no minimum in either framework. The question is commercial: if nobody is asking, the money usually does more good spent on the underlying security work. Once a deal is blocked on it, the calculation changes immediately.
Know exactly what an auditor, and an attacker, would find.
Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.
No sales sequence. A scoping call and a written proposal cost nothing.