~/services/soc-2-type-1Service
SOC 2 Type 1 readiness
An internal readiness assessment for a SOC 2 Type 1 examination, which reports on whether your controls are suitably designed as of one date rather than on how they ran over time. We assess control design against the Trust Services Criteria, run a gap assessment and prepare the evidence the CPA firm will ask for. The report is issued by a licensed CPA firm, not by us.
What this covers
- Control design against every Trust Services Criterion in scope, assessed the way the CPA firm will assess it
- Which criteria you should be in scope for at all, based on what your customers and contracts actually require
- Whether a control that reads well on paper would hold if it were tested, which is what a Type 2 examination will later do
- The system description, and whether you meet the commitments you make in it
- Complementary user entity controls and subservice organisations
- Evidence that the control existed on the date the report speaks to
- Every criterion in scope is assessed, not a sample
What you receive
- TSC gap assessment
- Control design review
- Evidence readiness review
- Remediation roadmap
- Readiness sign-off before the CPA
Scope your SOC 2 Type 1 readiness engagement.
A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.