Attestation report

SOC 2 Readiness

Getting the evidence running before the audit window opens, which is most of what determines whether a Type 2 goes well.

Who this applies to. SaaS and service organizations answering customer due diligence, usually because a deal is blocked on it.

What SOC 2 actually asks of you

SOC 2 is an attestation performed by a CPA firm against the Trust Services Criteria. Security is always in scope. Availability, confidentiality, processing integrity, and privacy are added when they are relevant to what you sell, and each one added is more work, so the selection is worth deliberating rather than defaulting.

The Type 1 and Type 2 distinction matters more than it first appears. Type 1 tests whether controls are designed appropriately at a point in time. Type 2 tests whether they operated effectively across a period, typically three to twelve months. That period is the constraint: if your evidence collection is not already running, the clock has not started.

Organizations that come to us with a signed audit engagement and a deal closing in ninety days are usually looking at a Type 1 now and a Type 2 later. That is often the right answer, and it is better to say so early than to discover it during fieldwork.

The engagement

What readiness covers

Criteria selection

Deciding which Trust Services Criteria belong in scope based on what you actually contract to deliver, rather than including all five because the list exists.

Readiness assessment

Measuring the current environment against the criteria and producing a gap register tied to specific points of focus, so remediation is a work list rather than a research project.

Evidence pipeline

Establishing how each control produces evidence automatically and where it lands. This is the difference between a Type 2 that is administratively routine and one that consumes a quarter of someone’s year.

Observation window planning

Choosing when the period starts and how long it runs, working backwards from the date a customer needs the report in hand.

Auditor coordination

Preparing for fieldwork and sample requests, so the auditor gets what they ask for first time. You engage the CPA firm directly, and their independence is what makes the report mean something.

What you are left holding

Deliverables

  • Scoped criteria with rationale for inclusions and exclusions
  • Gap register mapped to Trust Services Criteria points of focus
  • Control descriptions in the form the auditor will request them
  • Evidence collection running, with owners and cadence
  • System description draft
  • Observation window plan tied to your commercial deadline

FAQ

SOC 2 questions we get asked

Type 1 or Type 2?

Type 2 is what customers generally want, because it says the controls worked over time rather than existed on one day. Type 1 is a reasonable staging post when a deal needs something now and the observation period has not run.

If you have the runway, going straight to Type 2 avoids paying for two engagements.

Do you perform the audit?

No. A SOC 2 examination is performed by a licensed CPA firm. We prepare you for it. Preparing an organization and then attesting to it would be the conflict the report exists to avoid.

We already have ISO 27001. Does that help?

Considerably. The control work overlaps heavily and a functioning ISMS produces much of the evidence a SOC 2 auditor will ask for. The mapping is not one to one, and the reporting formats differ, but you are starting from a much better position than an organization with neither.

Start with scope, not with a proposal

The first conversation is about what is actually in scope, because that governs the cost of everything after it.

Talk to an expert