SYS// BRSTD-2026
UPLINK // AUTH_OK
LAT 24.86°N
LNG 67.00°E
ATELIER // v3.04
SIG ▮▮▮▮▮
PWR 98.4%
TEMP 36.6°C
FREQ 2400.0 MHz
PING 012 ms
PKTS 000000
RNG 000.0m
VEC 0.000,0.000
ID 0x000000
brainiac/studio

Digital Studio

brainiac/studiobrainiac/studio
Security
07 · security / soc 2 readiness

Ready before the auditor arrives.

SOC 2 is mostly about evidence: doing sensible things and being able to prove you did them consistently. We get both in place before the audit starts.

scroll
In short

We prepare you for a SOC 2 audit — implementing the controls, setting up the evidence collection, and closing the gaps. Usually two to four months before you are audit-ready. We are not auditors, which is why we can do this.

Updated August 2026

Most of SOC 2 is proving what you already do.

Where the gaps usually are, and how much work each is.

GAPS BY HOW OFTEN THEY ARE MISSING ENTIRELYAccess reviewsnever done · low effort to fixChange recordsalready in pull requests · needs recordingOff-boarding evidencea checklist and proofVendor registermoderate — a process to buildIncident planwriting, plus one rehearsalEvidence that needs a human every quarter stops happening by the third.
what this actually means

Most of SOC 2 is proving what you already do.

Companies usually have reasonable practices already. What they do not have is evidence — a record that access was reviewed every quarter, that changes were approved, that backups were tested. The audit asks for proof, not intentions.

So readiness is largely about making evidence collect itself. If proving a control requires someone to assemble screenshots each quarter, it will stop happening by the third one and the audit will find that.

Type I says the controls exist on a date. Type II says they operated over months. Most customers asking for SOC 2 want Type II, which means the evidence period starts before the audit — planning ahead saves real time.

2–4 moTo audit-ready
AutomatedEvidence, not quarterly screenshots
IndependentAuditor — we prepare, they assess
what we build

What we do.

01

Gap assessment first

What is already in place, what is missing, and how much work each gap is.

02

Evidence that collects itself

The single most important thing. Manual evidence gathering stops by the third quarter.

03

Policies people will follow

Written for your actual company. Generic templates get ignored and auditors notice.

04

Access review process

Quarterly, recorded, and as automated as your tooling allows.

05

Change management

Usually you already have this in pull requests. It needs recording, not rebuilding.

06

Incident response plan

Written, and rehearsed at least once — auditors ask whether it has been tested.

07

Vendor register

Who processes your data, what was assessed, and when it was last reviewed.

08

Auditor liaison

We help you choose one and prepare, though we cannot audit you ourselves.

Where the gaps usually are.

In rough order of how often we find each one missing entirely.

Control areaCommon gapEffort to close
Access reviewsNever done, or done onceLow — quarterly, and automatable
Change managementDeploys with no approval recordLow, if you already use pull requests
Onboarding and offboardingNo record of access removedLow — a checklist and evidence
Vendor reviewNobody assesses suppliersModerate — a register and a process
Incident responseNo written planModerate — writing and one rehearsal
Risk assessmentNever formally doneModerate — annual, documented
Encryption and loggingUsually fineLow — mostly proving it

How we approach it.

By design

We prepare you; an independent firm audits. The same party cannot do both credibly.

Not auditors
Evidence

The single biggest predictor of whether readiness survives to the audit.

Automated
Typical

Plus the Type II evidence period, which is why starting early matters.

2–4 months
use cases

When to start.

01

An enterprise customer asked

The usual trigger. Starting when the deal is already waiting is stressful and expensive.

02

You are selling upmarket

Above a certain deal size it becomes a standard question. Better to have started early.

03

You handle customer data

If you process anything sensitive on their behalf, this is coming eventually.

04

Not for a very small team with no ask

If nobody has requested it and you have five people, the money is better spent elsewhere for now.

approach

How we work.

01

We assess the gaps

Against the trust criteria you actually need, which is usually not all of them.

02

We prioritise by effort

The quick, automatable controls first, so progress is real early.

03

We automate the evidence

Before anything else. Evidence that needs a human every quarter will not survive.

04

We write the policies

For your company as it works, not a template with your name replaced.

05

We run the evidence period

For Type II the controls must operate over months. We check they are holding.

06

We prepare you for the auditor

Walkthrough, evidence organised, and the questions they will ask.

faq

Frequently asked.

5 questions answered. Still have one? Reach out.

No, and nobody credible would offer both. SOC 2 audits must be performed by an independent CPA firm, and preparing a company then assessing it would defeat the purpose. We get you ready and help you choose an auditor; they do the audit.

5 questions
Ask another →