SOC 2
Type I to prove design, Type II to prove operation. We get you through both without stalling the roadmap.
- Typical duration
- 3–12 months
- Primary audience
- CISOs & Boards
- You leave with
- A clean report your prospects’ security teams accept without a follow-up call.
Three phases, start to finish.
- 01 Criteria scoping You pay for the Trust Services Criteria you need. Security is mandatory; the other four are a decision, not a default. Criteria chosen against what your customers are actually asking for System description and boundary agreed with the auditor early Type I or Type II path chosen against your sales timeline
- 02 Control design and evidence Controls designed to be operated rather than described, with evidence collection automated everywhere it can be. Control design mapped to each criterion in scope Evidence automation so the audit window collects itself Monitoring through the window, not a scramble at the end of it
- 03 Fieldwork and report A readiness assessment before the auditor arrives, then liaison through fieldwork to a report your prospects accept. Readiness assessment run as a dry fieldwork Auditor liaison, so requests do not land on your engineers Vendor security questionnaire playbook for your sales team
Scope the criteria, not the brochure
Security is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are not — and each one you add lengthens the audit and the evidence burden. We scope to what your customers are actually asking for in their security reviews, which is usually Security alone, sometimes Security plus Availability.
Type I to Type II
Type I proves your controls are designed correctly at a point in time. Type II proves they operated over a window, typically three to twelve months. Most companies should plan for a short Type I to unblock a specific deal, then run straight into a Type II window.
Evidence automation
Manual evidence collection is why SOC 2 feels expensive in year two. We wire evidence collection into the systems you already run — your identity provider, your ticketing system, your CI pipeline — so the audit window is a query rather than a fire drill.
SOC 2: the questions we get asked.
Should we start with Type I or Type II?
If a specific deal is blocked, a short Type I unblocks it and proves your controls are designed correctly at a point in time. Then run straight into a Type II window, which proves they operated over three to twelve months. Going directly to Type II is cheaper overall but slower to your first report.
Which Trust Services Criteria do we actually need?
Security is mandatory. Availability, Confidentiality, Processing Integrity and Privacy are each a decision that lengthens the audit and the evidence burden. Most software companies need Security alone, sometimes Security plus Availability. We scope against what your customers are asking for in their security reviews, not against the brochure.
Can a Canadian company get SOC 2?
Yes. SOC 2 is an AICPA attestation performed by a licensed CPA firm; the firm has to be qualified, not the client, and Canadian CPA firms perform SOC 2 engagements routinely. Most of our SOC 2 clients are Canadian companies selling into the United States.
SOC 2 or ISO 27001 — which should we do first?
Follow the demand. If the deals you are losing are with North American enterprise buyers, SOC 2 is what their vendor-risk teams ask for, and a Type I unblocks the nearest one fastest. If your buyers are European, or you are selling to enterprises that run a formal supplier standard, ISO 27001 carries more weight. Doing both is common and not twice the work — most of the control implementation is shared, and only the audit and evidence formats differ.
Do you perform the audit?
No — the audit must be performed by an independent CPA firm. We do readiness, control design, evidence automation and auditor liaison, and we run a dry fieldwork before the real one so nothing surfaces first in front of your auditor.
Other lines of work
All servicesTell us what triggered the search. We will scope to that.
We reply to every assessment request within one business day.
