Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Prove Your Controls Work

SOC 2 Type 1 and Type 2 Readiness and Audit Support

SOC 2 is the attestation report customers ask for before they trust you with their data. We help you get ready for both Type 1 and Type 2, then support you through the audit.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

SOC 2 is an attestation, produced by a licensed auditor, that reports on how well your controls meet the Trust Services Criteria for security and, if you choose, availability, confidentiality, processing integrity, and privacy. A Type 1 report judges your controls at a single point in time. A Type 2 report tests that they operated effectively across a period, usually three to twelve months. It matters because buyers use it to vet vendors quickly. We help you design controls, pick the right criteria, and collect the evidence an auditor needs.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the SOC 2 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Criteria Selection. We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2. Activities: Select the Trust Services Criteria in scope; Decide the Type 1 or Type 2 path and timing; Define system boundaries for the report; Shortlist audit firms and align on timeline. Hands over Scope Memo and Audit Roadmap. Phase 2, Gap Assessment. We measure your controls against the criteria and give you a clear list of what to fix before the audit. Activities: Map existing controls to each criterion; Interview engineering, HR, and IT control owners; Test key controls for design and evidence; Rank gaps by audit impact and effort. Hands over Readiness Assessment Report. Phase 3, Control Design and Remediation. We help you design and implement the controls, from access reviews to change management and monitoring. Activities: Draft policies for access, change, and incidents; Implement quarterly access reviews; Stand up change management and monitoring controls; Assign owners for every control in the matrix. Hands over Control Matrix and Remediated Control Set. Phase 4, Evidence Automation. We connect a compliance platform so evidence collects itself, which is essential for the observation period of a Type 2. Activities: Connect cloud, HR, and code repositories to the platform; Map automated tests to each control; Set alerts for failing evidence checks; Close manual evidence gaps with owners. Hands over Automated Evidence Collection Setup. Phase 5, Observation Period Support. For Type 2, we help you run the controls consistently across the audit window and watch for drift. Activities: Monitor control performance across the window; Review platform alerts and fix drift early; Document exceptions and remediation; Run monthly check-ins with control owners. Hands over Clean Observation Period Evidence Trail. Phase 6, Audit Support. We work alongside your auditor through fieldwork so the report lands without surprises. Activities: Manage auditor evidence requests; Prepare control owners for walkthroughs; Respond to exceptions before they become findings; Review the draft report and management assertion. Hands over SOC 2 Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Criteria Selection

We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2.

What Happens In This Phase

  • Select the Trust Services Criteria in scope
  • Decide the Type 1 or Type 2 path and timing
  • Define system boundaries for the report
  • Shortlist audit firms and align on timeline

The Handover

Scope Memo and Audit Roadmap

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Criteria Selection

    We choose which Trust Services Criteria apply and decide whether to start with a Type 1 or go straight to Type 2.

    OutputScope Memo and Audit Roadmap

    Activities

    • Select the Trust Services Criteria in scope
    • Decide the Type 1 or Type 2 path and timing
    • Define system boundaries for the report
    • Shortlist audit firms and align on timeline
  2. 02

    Gap Assessment

    We measure your controls against the criteria and give you a clear list of what to fix before the audit.

    OutputReadiness Assessment Report

    Activities

    • Map existing controls to each criterion
    • Interview engineering, HR, and IT control owners
    • Test key controls for design and evidence
    • Rank gaps by audit impact and effort
  3. 03

    Control Design and Remediation

    We help you design and implement the controls, from access reviews to change management and monitoring.

    OutputControl Matrix and Remediated Control Set

    Activities

    • Draft policies for access, change, and incidents
    • Implement quarterly access reviews
    • Stand up change management and monitoring controls
    • Assign owners for every control in the matrix
  4. 04

    Evidence Automation

    We connect a compliance platform so evidence collects itself, which is essential for the observation period of a Type 2.

    OutputAutomated Evidence Collection Setup

    Activities

    • Connect cloud, HR, and code repositories to the platform
    • Map automated tests to each control
    • Set alerts for failing evidence checks
    • Close manual evidence gaps with owners
  5. 05

    Observation Period Support

    For Type 2, we help you run the controls consistently across the audit window and watch for drift.

    OutputClean Observation Period Evidence Trail

    Activities

    • Monitor control performance across the window
    • Review platform alerts and fix drift early
    • Document exceptions and remediation
    • Run monthly check-ins with control owners
  6. 06

    Audit Support

    We work alongside your auditor through fieldwork so the report lands without surprises.

    OutputSOC 2 Report

    Activities

    • Manage auditor evidence requests
    • Prepare control owners for walkthroughs
    • Respond to exceptions before they become findings
    • Review the draft report and management assertion

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the SOC 2 scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Vanta, Drata, Sprinto, Scrut, Secureframe, AWS Config, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: AICPA Trust Services Criteria, SOC 2 Type 1, SOC 2 Type 2, AICPA SSAE 18, COSO Framework.

What We Run

8 tools

  • Vanta
  • Drata
  • Sprinto
  • Scrut
  • Secureframe
  • AWS Config
  • Jira
  • Confluence

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • SOC2AICPATrust Services Criteria
  • SOC2AICPAType 1
  • SOC2AICPAType 2
  • AICPASSAE 18
  • COSOFramework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Readiness assessment report
  • Control matrix mapped to criteria
  • Remediation plan
  • Evidence collection setup
  • Audit support through fieldwork

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Should we start with SOC 2 Type 1 or Type 2?

Type 1 is faster and shows your controls are designed well, which helps when a deal is waiting. Type 2 carries more weight because it tests the controls over time. Many start with Type 1, then move to Type 2.

How long is the Type 2 observation period?

Usually three to twelve months. A first report often uses three to six months, then annual reports cover a full year. We help you pick a sensible window.

Which Trust Services Criteria do we need?

Security is always required. Availability, confidentiality, processing integrity, and privacy are optional and depend on what you promise customers. We help you choose.

Keep Moving Through Compliance

Service 8 of 13 in this practice area