~/services/soc-2-type-2Service
SOC 2 Type 2 readiness
An internal readiness assessment for a SOC 2 Type 2 examination, which reports on whether your controls actually operated effectively across a review period, not just on one date. We map controls to the Trust Services Criteria, test how they are running in practice, and close the gaps before the observation window opens. The report is issued by a licensed CPA firm, not by us.
What this covers
- Full coverage of the Trust Services Criteria in scope: the common criteria for Security, plus Availability, Processing Integrity, Confidentiality and Privacy wherever you commit to them
- Operating effectiveness across the review period, which is the whole difference between this and a Type 1
- Whether a control ran every time it was supposed to, and what the exceptions were when it did not
- The system description, and whether you meet the commitments you make in it
- Complementary user entity controls and subservice organisations
- Evidence and populations, sampled the way the auditor will sample them
- Gaps closed before the observation window opens rather than during it, because a control fixed mid-period still shows exceptions in the report
What you receive
- TSC gap assessment
- Control design review
- Evidence readiness review
- Remediation roadmap
- Readiness sign-off before the CPA
Scope your SOC 2 Type 2 readiness engagement.
A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.