Control design documentation, a precise system description, and a dry-run readiness assessment, built so your independent CPA firm's Type I examination comes back clean the first time.
Companies selling into the United States market where a customer or prospect has asked for a SOC 2 report, and who need something credible in hand reasonably quickly. Type I is frequently the right first step because it assesses control design at a point in time rather than operation over a period, which means you are not waiting months before you have anything to show. If your customer has specifically asked for Type II, read our Type II page instead, because a Type I will not satisfy that request.
Controls mapped to the criteria relevant to your business: typically Security, and Availability and/or Confidentiality where applicable.
A precise, auditor-ready system description covering your infrastructure, software, people, procedures and data, the document your CPA firm's report is built around.
An assessment of whether your policies and control narratives hold up as evidence of design effectiveness at a single point in time, which is Type I's specific focus.
A dry-run assessment identifying any control that wouldn't hold up under CPA firm scrutiny, before you pay for the real examination.
Every artefact your CPA firm will request, organised and indexed so the actual examination moves fast.
We help you select and brief an independent, licensed CPA firm to perform the examination itself.
SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants. Unlike ISO 27001, it is not a certification and there is no certificate. What you receive is a report written and signed by an independent CPA firm expressing an opinion on your controls. That difference in form matters when customers ask for evidence, because you are handing over a detailed report rather than a one page certificate.
SOC 2 reports are built around the Trust Services Criteria. Security, sometimes called the common criteria, is mandatory in every SOC 2 report. Availability, Confidentiality, Processing Integrity and Privacy are optional and included only where relevant to the service you provide. Each additional criterion adds scope, cost and audit effort, so choosing them carelessly is an expensive habit.
Because the report is an opinion from a licensed CPA firm, independence rules apply strictly. The firm that helped design and implement your controls cannot be the firm that examines them. This is the same principle that keeps us out of the examination itself, and it is worth understanding early so the engagement is structured correctly from the start.
A Type I report assesses whether your controls are suitably designed as at a specified date. The auditor examines the design of each control and your system description, and forms an opinion on whether the controls, if operating as described, would meet the criteria. It is a snapshot.
A Type II report assesses whether those controls operated effectively across a period, commonly three, six or twelve months. The auditor samples evidence from across the window and reports exceptions where controls did not operate as described. It is substantially more demanding and substantially more valuable to the customer reading it.
The usual path is Type I first, then Type II covering a period beginning shortly after. That gives you something to show quickly while the observation window for Type II accumulates. Some companies with mature controls skip straight to Type II, and if your customer has explicitly asked for Type II there is limited value in producing a Type I first.
The system description is the section of a SOC 2 report where you describe your service, your infrastructure, your people, your procedures and your data. It is written by you rather than the auditor, and the auditor opines on whether it is fairly presented. It is also the part most companies underestimate.
A weak system description creates problems in both directions. Describe your environment vaguely and the report becomes hard for a customer to rely on, which defeats the purpose of producing it. Describe controls you do not actually operate and you have created an inaccuracy the auditor is obliged to address. We review your description against what your environment genuinely does, and flag anything that claims more than the evidence supports.
We confirm which Trust Services Criteria apply to your business and agree the boundary of your system description.
Current controls are assessed against the criteria, with gaps prioritised by how likely they are to surface an exception.
We review your policies and control narratives against the Trust Services Criteria, and check the tooling (access management, logging, change management) your controls depend on is actually enforcing them.
A full dry-run against Type I expectations, so nothing about your control design surprises the CPA firm.
You get one round to address the control design gaps we identified. We re-review those items and issue the final readiness report.
We brief your chosen independent CPA firm and support you through the examination, but they perform and sign the actual Type I report.
After the readiness assessment, you get one round to address the control design gaps we identified. We then re-review those specific items and issue the final readiness report, so your CPA firm begins its examination against your corrected control design rather than the state we first assessed.
Processing Integrity in particular is often included reflexively by companies that do not process transactions. Each criterion added expands scope permanently, since dropping one later looks like a step backwards to customers.
It is an audited document. Anything it claims must be evidenced, and overstatement creates exceptions rather than impressions.
Firms book up, and their availability often sets your real timeline. Identify and engage yours early rather than after preparation is complete.
If a customer contract specifies Type II, a Type I report does not meet it. Clarify exactly what has been asked for before choosing a path.
Most first time clients reach Type I readiness in six to ten weeks, depending on how much control tooling already exists. The CPA firm's examination itself typically takes a further two to four weeks from fieldwork to issued report. If you are moving toward Type II afterwards, the observation window begins after Type I and runs for the period you and your customers agree, so factor that into any commitment you make to a prospect.
We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.
Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →
Type I assesses whether your controls are designed appropriately at a single point in time. Type II assesses whether those same controls operated effectively over a period, typically 3 to 12 months. Most companies start with Type I and move to Type II once controls have been running long enough to evidence.
No. AICPA independence rules require the CPA firm issuing your SOC 2 report to be independent of anyone who designed or implemented your controls. We prepare you; an independent, licensed CPA firm performs the examination. Full detail in our independence statement.
Most first-time clients are examination-ready in 6 to 10 weeks, depending on how mature your existing controls and tooling are.
Yes. This is one of the first things we scope. Adding criteria you don't need (like Processing Integrity when you don't process financial transactions) adds cost and audit burden for no customer benefit.
The Type I report itself, once issued by your CPA firm, is what satisfies most questionnaires. Our job is making sure that report comes back clean.
No. It is an attestation report issued by a licensed CPA firm expressing an opinion on your controls. There is no certificate and no certifying body, which is why you share the report itself rather than a badge.
Security is mandatory. Add Availability if you commit to uptime obligations, Confidentiality if you handle customer data under confidentiality terms, Processing Integrity if you process transactions where accuracy is central, and Privacy if you handle personal information in ways that warrant it. We scope this with you before anything else.
Yes. SOC 2 is a US originated framework but is used internationally and is commonly requested of non US suppliers selling into the US market. The examining firm must be a licensed CPA firm.
Only if your customers ask for both, which does happen when you sell across regions. The underlying control work overlaps substantially, so running them together is considerably more efficient than sequentially.
SOC 2 reports are restricted use documents, normally shared with customers and prospects under NDA rather than published. That is one practical difference from an ISO 27001 certificate, which can be displayed openly.
One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.
Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.
Book a discovery call