Ready before the auditor arrives.
SOC 2 is mostly about evidence: doing sensible things and being able to prove you did them consistently. We get both in place before the audit starts.
We prepare you for a SOC 2 audit — implementing the controls, setting up the evidence collection, and closing the gaps. Usually two to four months before you are audit-ready. We are not auditors, which is why we can do this.
Updated August 2026
Most of SOC 2 is proving what you already do.
Where the gaps usually are, and how much work each is.
Most of SOC 2 is proving what you already do.
Companies usually have reasonable practices already. What they do not have is evidence — a record that access was reviewed every quarter, that changes were approved, that backups were tested. The audit asks for proof, not intentions.
So readiness is largely about making evidence collect itself. If proving a control requires someone to assemble screenshots each quarter, it will stop happening by the third one and the audit will find that.
Type I says the controls exist on a date. Type II says they operated over months. Most customers asking for SOC 2 want Type II, which means the evidence period starts before the audit — planning ahead saves real time.
What we do.
Gap assessment first
What is already in place, what is missing, and how much work each gap is.
Evidence that collects itself
The single most important thing. Manual evidence gathering stops by the third quarter.
Policies people will follow
Written for your actual company. Generic templates get ignored and auditors notice.
Access review process
Quarterly, recorded, and as automated as your tooling allows.
Change management
Usually you already have this in pull requests. It needs recording, not rebuilding.
Incident response plan
Written, and rehearsed at least once — auditors ask whether it has been tested.
Vendor register
Who processes your data, what was assessed, and when it was last reviewed.
Auditor liaison
We help you choose one and prepare, though we cannot audit you ourselves.
Where the gaps usually are.
In rough order of how often we find each one missing entirely.
| Control area | Common gap | Effort to close |
|---|---|---|
| Access reviews | Never done, or done once | Low — quarterly, and automatable |
| Change management | Deploys with no approval record | Low, if you already use pull requests |
| Onboarding and offboarding | No record of access removed | Low — a checklist and evidence |
| Vendor review | Nobody assesses suppliers | Moderate — a register and a process |
| Incident response | No written plan | Moderate — writing and one rehearsal |
| Risk assessment | Never formally done | Moderate — annual, documented |
| Encryption and logging | Usually fine | Low — mostly proving it |
How we approach it.
We prepare you; an independent firm audits. The same party cannot do both credibly.
The single biggest predictor of whether readiness survives to the audit.
Plus the Type II evidence period, which is why starting early matters.
When to start.
An enterprise customer asked
The usual trigger. Starting when the deal is already waiting is stressful and expensive.
You are selling upmarket
Above a certain deal size it becomes a standard question. Better to have started early.
You handle customer data
If you process anything sensitive on their behalf, this is coming eventually.
Not for a very small team with no ask
If nobody has requested it and you have five people, the money is better spent elsewhere for now.
How we work.
We assess the gaps
Against the trust criteria you actually need, which is usually not all of them.
We prioritise by effort
The quick, automatable controls first, so progress is real early.
We automate the evidence
Before anything else. Evidence that needs a human every quarter will not survive.
We write the policies
For your company as it works, not a template with your name replaced.
We run the evidence period
For Type II the controls must operate over months. We check they are holding.
We prepare you for the auditor
Walkthrough, evidence organised, and the questions they will ask.
Frequently asked.
5 questions answered. Still have one? Reach out.
No, and nobody credible would offer both. SOC 2 audits must be performed by an independent CPA firm, and preparing a company then assessing it would defeat the purpose. We get you ready and help you choose an auditor; they do the audit.