SOC 2 Compliance

SOC 2 consulting services, from readiness to report

Enterprise buyers want a SOC 2 report. Our consultants get you there.

Ali Aleali

Ali Aleali, CISSP, CCSP

Co-Founder & Principal Consultant

Former security architect for Bank of Canada and Payments Canada. CISSP, CCSP. Leads every engagement.

Connect on LinkedIn

What a SOC 2 consulting engagement includes

A senior consultant leads the engagement from the gap assessment to the auditor's report, then keeps the program audit-ready between cycles.

icon-8

A senior SOC 2 consultant on every engagement

The consultant who scopes your SOC 2 leads the work through the audit. Our team has built security programs for national financial systems.

icon-7

Scope and the System Description

Systems, people, data and vendors in scope, and the System Description (Section 3 of the SOC 2 report) written with your team to AICPA requirements.

icon-9

Policies and controls built for your stack

20+ policies and 100+ controls tailored to the Trust Services Criteria in scope and to the systems you operate.

icon-6

Your GRC platform, operated

We set up and operate Vanta, Drata, Secureframe, Scrut, Sprinto and others. The platform stays yours.

icon-5

Any environment, audit-ready

Cloud, hybrid, on-prem or bare-metal SOC 2. We build evidence trails that cover the infrastructure you operate, including physical access and on-prem logs.

icon-4

Auditor management through fieldwork

We coordinate with your independent CPA firm, organize evidence requests and defend your scope. You choose the audit firm, and it stays independent.

How a SOC 2 engagement works: Assess, Build, Operate

Three phases, each at a fixed price. Every engagement starts with a free readiness assessment.

01

Assess

A free readiness assessment: a strategy session, a high-level gap analysis against the Trust Services Criteria in scope, and a roadmap. Output: scope, gaps and next steps.

02

Build

Policies, controls mapped to every criterion in scope, GRC platform configuration, evidence collection, internal audit and penetration test management. Output: the Security Program Manual and a Type I report.

03

Operate

Continuous control monitoring and evidence collection, quarterly access reviews, vendor risk assessments, the annual internal audit and penetration test, and audit management through each Type II.

What you hold at the end of a SOC 2 Build

Built from your systems and documented, so the program survives staff turnover and a buyer's security review.

  • Security Program Manual

  • SOC 2 System Description

  • Gap assessment and roadmap

  • Customized policy set (20+)

  • Controls mapped to the Trust Services Criteria

  • Evidence collection in your GRC platform

  • Risk and vendor risk assessments

  • Internal audit report

  • Penetration test report

  • SOC 2 Type I report

What changes in the first 90 days of a SOC 2 engagement

SOC 2 gets an owner and a plan. Your engineers go back to the roadmap.

When a SOC 2 consultant is the right call, and when it is not

If we are not a fit, we say so on the scoping call.

SOC 2 consultant frequently asked questions

Plan for three cost buckets. Implementation consulting: our SOC 2 Build engagements typically cost USD $20,000 to $50,000 depending on scope, with a fixed price quoted after the scoping call. A GRC platform typically costs $5,000 to $25,000 per year. The audit from an independent CPA firm is paid separately: a Type I audit starts at around $5,000 and a Type II audit at around $7,500, more for multi-category or multi-system scopes. The readiness assessment that starts every engagement is free.

A well-run engagement typically gets you audit-ready in 8 to 12 weeks. A Type I audit then takes roughly 2 to 4 weeks to complete and report. A Type II requires an observation window, usually 3 to 12 months, during which your controls operate and produce evidence, and many enterprise buyers expect at least six months. The auditor then needs about 2 to 4 weeks to issue the report. We can compress the readiness timeline when a customer deadline is fixed.

A Type I report attests that your security controls are designed properly at a single point in time. A Type II report, which many enterprise customers ask for, attests that your controls operated effectively over a period of time, typically 3, 6 or 12 months.

The SOC 2 framework does not explicitly mandate a penetration test. It is a common way to produce evidence for criteria on monitoring and vulnerability detection, such as CC4.1 and CC7.1, and many auditors and enterprise buyers expect one. We manage the penetration test as part of Build and repeat it annually in Operate.

Ask who does the work: a senior consultant with production experience, or a junior associate with a checklist. Ask whether the controls are designed for your stack or dropped in from a template, and whether they cover the environment you operate, including on-prem and hybrid. Ask whether the price is fixed or hourly, and whether the consultant manages the auditor relationship. Our guide on how to choose a SOC 2 consultant lists the questions to ask on a first call.

Yes. Teams with on-prem servers, co-location racks or a hybrid mix often have the hardest time tying physical access, on-prem logs and cloud admin records into one evidence trail. We scope controls to the systems you operate and build that evidence trail with tooling that reaches on-prem. See our SOC 2 for bare-metal and on-prem infrastructure service for detail.

Yes. We act as the main point of contact between you and the auditor: we organize and submit evidence, defend your scope when it is challenged, push back on overreaching requests and walk the auditor through your control narrative. The audit firm stays independent by design. We can introduce reputable firms; you pick the firm, and we manage the engagement.

Yes. The System Description, Section 3 of the SOC 2 report, is a standard part of our service. We work with your team to document the scope, boundaries, services, controls and applicable Trust Services Criteria, so it meets AICPA requirements and is ready for the auditor.

Yes. We provide readiness assessments and internal audits before your SOC 2. We are not a CPA firm and do not issue the report, so we can act as your independent security and compliance consultant, find gaps and confirm your controls are effective before the external audit.

Yes. US and international SaaS companies are the core of our SOC 2 work, delivered remotely, with pricing in USD and reports for US enterprise buyers. Canadian companies can see our page for SOC 2 consultants in Canada, or compare the top SOC 2 consultants in Canada.

Get SOC 2 audit-ready with a fixed-price engagement

Book a 30-minute scoping call. We cover your environment, the deal behind the report request and whether a SOC 2 consultant fits.

From the blog: SOC 2 compliance and audits

SOC 2 CC7.5: Recovering From Identified Security Incidents

SOC 2 CC7.5 requires a company to identify, develop, and implement the activities that recover the environment after a security incident, and to ...

SOC 2 CC7.4: Responding to Security Incidents

SOC 2 CC7.4 requires a company to respond to security incidents through a defined incident-response program that understands, contains, remediates, ...

SOC 2 CC7.3: Evaluating Security Events to Identify Incidents

SOC 2 CC7.3 requires a company to evaluate detected security events, decide which of them are incidents, and act on the ones that are. It sits in the ...