Commercial & Industry / FOCUSED SERVICE

SOC 2 Type II Readiness

Control design, a draft system description, and an evidence index for a SOC 2 Type II examination, built before the observation period starts.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for a company that must hand a customer a SOC 2 Type II report and has no controls running on a documented schedule. We scope the system and decide which trust categories to include: Security always, and Availability, Confidentiality, Processing Integrity, or Privacy when your contracts call for them. We run a gap assessment against the Trust Services Criteria, walking each one with its control owner and inspecting live settings in your identity provider, source control, and cloud accounts rather than a spreadsheet. We build the control matrix, the policy set, a draft system description, and an evidence index, then rehearse a full evidence request across a trial period. The examination itself belongs to the licensed service auditor you engage; we never audit our own work.

WHEN THIS IS THE RIGHT FIT

Founders and security leads at SaaS and managed service companies whose enterprise customers or procurement teams have made a SOC 2 Type II report a condition of the contract, usually with a renewal or close date already set.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Scope the system and choose the categories

We read the customer contracts and questionnaires that created the demand, agree the system boundary and product lines, decide which trust services categories to include, and settle whether outside providers such as a cloud host or a payroll service are carved out or inclusive. The result is a scoping memo and a target observation period.

Map every criterion to a control that runs

For each criterion in the framework and any added category, we record the control, its owner, its frequency, and the artifact that proves it ran: an access review export, a code change approval, a resolved change ticket. Missing controls are designed with the owner who will run them, not handed down as a checklist.

Rehearse the evidence request before the auditor sends one

We issue a mock evidence request against the index, sampled across the trial period the way a service auditor samples, and score what came back complete, late, or missing. You receive the scored results, the remediation list, and a readiness memo you can share with the firm you select.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • SaaS and managed service providers whose enterprise customers require a SOC 2 report
  • Companies with no controls yet running on a documented, repeatable schedule
  • Security leads who own vendor questionnaires but lack a control matrix
  • Product teams selling into regulated buyers who expect Type II operating evidence
WHEN IT’S TIME TO ENGAGE
  • A prospect or renewal makes a SOC 2 report a signed contract condition
  • An automation platform produced a boilerplate report a customer rejected
  • You must choose an observation period before the next audit window opens
  • A funding round or enterprise deal added security diligence to the timeline
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • System boundary, product lines, and trust services categories fixed against the contracts that drive the request

  • Gap walkthrough of every Trust Services Criterion with its control owner, including the categories your contracts require

  • Configuration review of identity provider, source control, cloud consoles, ticketing, and endpoint management for control evidence

  • Control matrix with owner, frequency, evidence source, and sampling population for every control

  • Draft system description covering boundaries, commitments, and the controls your customers must run themselves

  • Mock evidence request across a trial period, scored for completeness and timeliness

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$7,500–$13,500

Under 50 employees, one cloud product, Security criteria only

About 50–90 hours
Mid-size
$13,500–$24,000

50–250 employees, two or three SOC 2 criteria, several cloud environments

About 90–160 hours
Large
$24,000–$42,000

250+ employees, multiple products or business units, most or all SOC 2 criteria

About 160–280 hours
WHAT MOVES THE PRICE
  • Number of SOC 2 criteria in scope beyond Security
  • Number of products, environments, and outside vendors
  • Existing written policies and control owners
  • Whether a compliance automation platform is already in use
TYPICAL TIMELINE

4–10 weeks before the observation period starts, which then typically runs 3–12 months

The Type II examination is performed and billed by a licensed CPA firm, typically $7,000–$100,000+ depending on size and auditor.

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Gap report by criterion with the control that closes each gap and who owns it
  • Control matrix, policy set, and risk register ready for the observation period
  • Draft system description and management assertion outline for the service auditor
  • Evidence index with the scored results of the mock evidence request and a readiness memo

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

Should we get a Type I report first or go straight to Type II?

It depends on the customer deadline and how long your controls have operated. A Type I covers control design at a point in time and can be issued soon after readiness finishes. A Type II covers operating effectiveness over an observation period; there is no mandated minimum, six months is a common first-report choice, and twelve is what large customers expect. If a customer needs something within a quarter, a Type I followed by a Type II is the usual path. The service auditor settles the period length with you.

Can you perform the SOC 2 examination as well?

No. A SOC 2 report is an attestation issued by a licensed accounting firm, and the firm that designs your controls cannot examine them. We prepare you, then help you select and brief a service auditor. Be careful with automation platforms that promise a fast, cheap report; the profession has raised concerns that they produce boilerplate examinations. Between reports, a bridge letter signed by your management, not the auditor, covers the gap for customers and is not itself an attestation.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security