Skip to content

02 · Compliance

SOC 2 Readiness

Get through your first SOC 2 without derailing the roadmap.

We design your Trust Services Criteria controls, put the evidence collection on rails, run a readiness assessment against the criteria your auditor will use, and coordinate with the CPA firm through Type I and the Type II observation window.

The context

Why this matters

SOC 2 is where most North American SaaS deals get unblocked, and where most first-time teams lose a quarter. The failure pattern is predictable: controls are written to sound impressive, then nobody operates them, and the Type II observation window closes with gaps the auditor has to qualify.

We design controls you can actually run every month, wire them to evidence that generates itself where possible, and pressure-test the whole set in a readiness assessment before your auditor ever looks at it.

If you are pursuing ISO 27001 as well, we map the two frameworks against each other from the start. The overlap is substantial, running them as one programme rather than two saves months.

What is covered

Scope of the engagement

  1. 01

    Trust Services Criteria selection

    Decide which categories you are reporting on, Security is mandatory, and Availability, Confidentiality, Processing Integrity and Privacy are chosen based on what your customers actually contract for.

  2. 02

    Control design & narrative

    A control set mapped to the TSC points of focus, written as operable procedures with named owners, frequencies and evidence sources.

  3. 03

    Readiness assessment

    A dry-run audit against your control set, identifying design gaps and evidence gaps before the CPA firm does.

  4. 04

    Evidence pipeline

    Setting up the recurring collection, access reviews, change management, vendor reviews, security training, incident records, so the observation window does not become a scramble.

  5. 05

    Auditor selection & coordination

    Help choosing a CPA firm, scoping the engagement, and managing the request list through fieldwork.

  6. 06

    ISO 27001 crosswalk

    A mapping between your SOC 2 controls and ISO 27001 Annex A so one body of evidence serves both frameworks.

What you receive

Deliverables

Everything below is included in the fixed price. Nothing here is an upsell discovered halfway through.

  • Trust Services Criteria scoping decision and rationale
  • Full control matrix with owners, frequencies and evidence sources
  • Readiness assessment report with remediation backlog
  • System description draft for the audit report
  • Evidence collection calendar and templates
  • SOC 2 ↔ ISO 27001 control crosswalk

Questions

SOC 2 Readiness FAQ

Type I is a point-in-time opinion on whether your controls are suitably designed. Type II covers a window, usually three to twelve months, and tests whether those controls actually operated. Most enterprise buyers want Type II eventually; Type I is a reasonable first milestone that unblocks deals while the observation window runs.

No. A SOC 2 report is issued by a licensed CPA firm and independence rules prevent the same party from both building and attesting the controls. We prepare you and manage the process; the CPA firm issues the opinion.

It depends on who is asking. US enterprise buyers typically ask for SOC 2; European, UK, Middle Eastern and APAC buyers usually ask for ISO 27001. If both are on your roadmap, run them together, the control overlap is roughly 80%, and doing them sequentially means paying for the same evidence work twice.

Know exactly what an auditor, and an attacker, would find.

Tell us what you need certified or tested. We will scope it properly, quote a fixed price, and tell you honestly if the timeline you have in mind is realistic.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.