Prove Your Controls Work
SOC 2 Type 1 and Type 2 Readiness and Audit Support
SOC 2 is the attestation report customers ask for before they trust you with their data. We help you get ready for both Type 1 and Type 2, then support you through the audit.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
SOC 2 is an attestation, produced by a licensed auditor, that reports on how well your controls meet the Trust Services Criteria for security and, if you choose, availability, confidentiality, processing integrity, and privacy. A Type 1 report judges your controls at a single point in time. A Type 2 report tests that they operated effectively across a period, usually three to twelve months. It matters because buyers use it to vet vendors quickly. We help you design controls, pick the right criteria, and collect the evidence an auditor needs.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the SOC 2 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Criteria Selection. We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2. Activities: Select the Trust Services Criteria in scope; Decide the Type 1 or Type 2 path and timing; Define system boundaries for the report; Shortlist audit firms and align on timeline. Hands over Scope Memo and Audit Roadmap. Phase 2, Gap Assessment. We measure your controls against the criteria and give you a clear list of what to fix before the audit. Activities: Map existing controls to each criterion; Interview engineering, HR, and IT control owners; Test key controls for design and evidence; Rank gaps by audit impact and effort. Hands over Readiness Assessment Report. Phase 3, Control Design and Remediation. We help you design and implement the controls, from access reviews to change management and monitoring. Activities: Draft policies for access, change, and incidents; Implement quarterly access reviews; Stand up change management and monitoring controls; Assign owners for every control in the matrix. Hands over Control Matrix and Remediated Control Set. Phase 4, Evidence Automation. We connect a compliance platform so evidence collects itself, which is essential for the observation period of a Type 2. Activities: Connect cloud, HR, and code repositories to the platform; Map automated tests to each control; Set alerts for failing evidence checks; Close manual evidence gaps with owners. Hands over Automated Evidence Collection Setup. Phase 5, Observation Period Support. For Type 2, we help you run the controls consistently across the audit window and watch for drift. Activities: Monitor control performance across the window; Review platform alerts and fix drift early; Document exceptions and remediation; Run monthly check-ins with control owners. Hands over Clean Observation Period Evidence Trail. Phase 6, Audit Support. We work alongside your auditor through fieldwork so the report lands without surprises. Activities: Manage auditor evidence requests; Prepare control owners for walkthroughs; Respond to exceptions before they become findings; Review the draft report and management assertion. Hands over SOC 2 Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Criteria Selection
We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2.
What Happens In This Phase
- Select the Trust Services Criteria in scope
- Decide the Type 1 or Type 2 path and timing
- Define system boundaries for the report
- Shortlist audit firms and align on timeline
The Handover
Scope Memo and Audit Roadmap
The next phase starts from this.
Phase 01 Scoping and Criteria Selection
We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2.
What Happens In This Phase
- Select the Trust Services Criteria in scope
- Decide the Type 1 or Type 2 path and timing
- Define system boundaries for the report
- Shortlist audit firms and align on timeline
The Handover
Scope Memo and Audit Roadmap
The next phase starts from this.
- 01
Scoping and Criteria Selection
We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2.
OutputScope Memo and Audit RoadmapActivities
- Select the Trust Services Criteria in scope
- Decide the Type 1 or Type 2 path and timing
- Define system boundaries for the report
- Shortlist audit firms and align on timeline
- 02
Gap Assessment
We measure your controls against the criteria and give you a clear list of what to fix before the audit.
OutputReadiness Assessment ReportActivities
- Map existing controls to each criterion
- Interview engineering, HR, and IT control owners
- Test key controls for design and evidence
- Rank gaps by audit impact and effort
- 03
Control Design and Remediation
We help you design and implement the controls, from access reviews to change management and monitoring.
OutputControl Matrix and Remediated Control SetActivities
- Draft policies for access, change, and incidents
- Implement quarterly access reviews
- Stand up change management and monitoring controls
- Assign owners for every control in the matrix
- 04
Evidence Automation
We connect a compliance platform so evidence collects itself, which is essential for the observation period of a Type 2.
OutputAutomated Evidence Collection SetupActivities
- Connect cloud, HR, and code repositories to the platform
- Map automated tests to each control
- Set alerts for failing evidence checks
- Close manual evidence gaps with owners
- 05
Observation Period Support
For Type 2, we help you run the controls consistently across the audit window and watch for drift.
OutputClean Observation Period Evidence TrailActivities
- Monitor control performance across the window
- Review platform alerts and fix drift early
- Document exceptions and remediation
- Run monthly check-ins with control owners
- 06
Audit Support
We work alongside your auditor through fieldwork so the report lands without surprises.
OutputSOC 2 ReportActivities
- Manage auditor evidence requests
- Prepare control owners for walkthroughs
- Respond to exceptions before they become findings
- Review the draft report and management assertion
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
What Is Examined, and What it Is Measured Against
Map
Map of the SOC 2 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Sprinto, Scrut, Secureframe, AWS Config, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: AICPA Trust Services Criteria, SOC 2 Type 1, SOC 2 Type 2, AICPA SSAE 18, COSO Framework.
What We Run
8 tools
- Drata
- Sprinto
- AWS Config
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- AICPA
- AICPAType 1
- AICPAType 2
- AICPA
- COSO
Deliverables
What You Receive
- Readiness assessment report
- Control matrix mapped to criteria
- Remediation plan
- Evidence collection setup
- Audit support through fieldwork
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Should we start with SOC 2 Type 1 or Type 2?
Type 1 is faster and shows your controls are designed well, which helps when a deal is waiting. Type 2 carries more weight because it tests the controls over time. Many start with Type 1, then move to Type 2.
How long is the Type 2 observation period?
Usually three to twelve months. A first report often uses three to six months, then annual reports cover a full year. We help you pick a sensible window.
Which Trust Services Criteria do we need?
Security is always required. Availability, confidentiality, processing integrity, and privacy are optional and depend on what you promise customers. We help you choose.
Keep Moving Through Compliance
Service 8 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.