~/services/soc-2-type-1Service

SOC 2 Type 1 readiness

An internal readiness assessment for a SOC 2 Type 1 examination, which reports on whether your controls are suitably designed as of one date rather than on how they ran over time. We assess control design against the Trust Services Criteria, run a gap assessment and prepare the evidence the CPA firm will ask for. The report is issued by a licensed CPA firm, not by us.

EngagementReadiness

What this covers

  • Control design against every Trust Services Criterion in scope, assessed the way the CPA firm will assess it
  • Which criteria you should be in scope for at all, based on what your customers and contracts actually require
  • Whether a control that reads well on paper would hold if it were tested, which is what a Type 2 examination will later do
  • The system description, and whether you meet the commitments you make in it
  • Complementary user entity controls and subservice organisations
  • Evidence that the control existed on the date the report speaks to
  • Every criterion in scope is assessed, not a sample

What you receive

  • TSC gap assessment
  • Control design review
  • Evidence readiness review
  • Remediation roadmap
  • Readiness sign-off before the CPA

Scope your SOC 2 Type 1 readiness engagement.

A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.

Contact
contact.log

No form, no sales desk. The person who answers is the person who would run your engagement.

Profiles
XLinkedIn
Book a scoping call

30 minutes, fixed price after. No questionnaire.