
SOC 2 Readiness and Implementation
We take firms through SOC 2 Type 1 and Type 2, from scoping and criteria selection through policies, controls and evidence, to preparation for and support through the independent CPA examination. Delivered with Hael, and inside Vanta, Drata, Secureframe or your existing environment.
Connect with our SOC 2 experts for tailored support.
Speak with Our SOC 2 Experts
Complete the form, and our experts will contact you within 24 hours. Alternatively, call us directly at 0207 866 2512.
Built by compliance practitioners
Expert Guidance Through Every Stage of Your SOC 2 Programme

Regulatory depth
The criteria are built into how the programme is run: which criteria apply to which service, what constitutes sufficient evidence of operation, what an examiner tests and what a customer's security team reads. Specified by practitioners advising regulated firms since 2013.

One record, every output
Controls, evidence, approvals and sign-off are captured as they happen, so the audit pack, the customer questionnaire response and the next reporting period all draw from the same record rather than being assembled separately.

Independence preserved
The CPA firm performing the examination cannot design or implement the controls it tests. Readiness and audit are separately resourced, which is why the preparation is run by us and the opinion remains entirely theirs.
Leading security compliance since 2013

.png)

.png)

.png)

Why firms use us for SOC 2
A customer has set the deadline
SOC 2 programmes usually begin because a specific customer has asked for a report before contract. The date is theirs, not yours, and the programme is planned backwards from it.
The platform did not finish the work
A compliance platform lists the outstanding controls and monitors the ones it can reach. Writing the policies, implementing the controls, gathering the evidence and holding the schedule remain with the firm, and that is where first-time programmes stall.
Evidence that survives examination
A report obtained on limited evidence still fails the customer review it was bought for, because the reviewer asks what sits behind a control and finds little there. Evidence built as controls operate holds up; evidence reconstructed afterwards does not.
Continuity between periods
A Type 2 report covers a period, and the next period begins where the last ended. Where evidence accumulates continuously, each report is a continuation rather than a reconstruction.
One programme. Every output.
The controls you implement are the same controls the examiner tests, and the evidence you produce as they operate is the evidence that goes into the audit pack.
Scope and criteria
The services, systems, locations and Trust Services Criteria within the examination boundary, decided at the start with the reasoning recorded, because scope determines both cost and whether the report answers what your customer asked.
Control environment
Policies, procedures and controls covering access, change, development, vulnerability management, incident response, continuity, suppliers, training and monitoring, written for how the firm operates rather than adapted from a template library.
Evidence
What each control must produce, who owns it, how often, and where it is held. Records reviewed and gaps resolved before the examination opens rather than assembled in the weeks before it.
System description
The description of the service organisation's system required by the report, covering services, infrastructure, software, people, procedures, data and the boundary of the examination.
Audit pack
The evidence index, request tracker and interview plan the CPA firm works from, with control owners briefed on what they will be asked and how to answer it.
Our simple three-step SOC 2 process
We help SaaS, cloud, fintech and AI businesses reach SOC 2 Type 1 and Type 2.
Step 1:
Scope and Readiness
We review the services in scope, confirm which Trust Services Criteria apply, establish whether Type 1 or Type 2 is the right starting point, and assess your existing controls and evidence against them.
Step 2:
Implementation and Evidence
We prepare the policies, design and embed the controls, define what evidence each control must produce, and configure your compliance platform. We run the project to the deadline.
Step 3:
Audit and Report
We prepare the audit pack and the system description, brief the people who will be interviewed, coordinate with the independent CPA firm and manage responses through fieldwork to the issued report.
Our Soc 2 services
Full end-to-end support.
SOC 2 readiness
assessment
We assess your existing controls and evidence against the criteria in scope and set out what must be resolved before audit.
Implementation and remediation
We prepare the policies, design the controls and close the gaps identified, working to an agreed schedule rather than handing over a list.
Compliance platform support
We work inside Vanta, Drata, Secureframe or your existing environment, configure the controls properly and manage the manual evidence the platform does not capture.
Audit preparation and coordination
We prepare the evidence pack and system description, brief your people and manage communication with the CPA firm throughout fieldwork.
Continuous assurance
We maintain the control environment between reporting periods so each report begins from an operating baseline.
Customer security reviews
We answer CAIQ, SIG and bespoke customer questionnaires from the same approved control and evidence record.

Our People
Our security assurance team combines information security, governance and regulatory compliance experience. The same practitioners who advise firms through FCA authorisation and supervision specify how these programmes are scoped, evidenced and taken to audit.
When you work with us, you gain direct access to senior professionals rather than an account manager. The programme is run by people who understand what an examiner will test and what a customer's security team will read.
Key information and requirements for SOC 2
Key SOC 2 infomations
What SOC 2 requires
SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants. An independent licensed CPA firm examines a service organisation's controls against the Trust Services Criteria and issues a report containing its opinion. It is not a certification and there is no certificate. It is not required by statute in any jurisdiction: demand comes from enterprise procurement, customer contracts and investor diligence.
Trust Services Criteria. Five categories: security, availability, processing integrity, confidentiality and privacy. Security, known as the common criteria, is included in every report. The other four are selected where relevant to the service and to the assurances the customer requires.
Type 1. Examines whether controls were suitably designed and implemented at a specified date. A point-in-time report.
Type 2. Examines both design and whether controls operated effectively throughout a defined review period. The report most enterprise customers require.
Observation period. Agreed with the CPA firm, commonly between three and twelve months, with six months a frequent minimum. Shorter periods carry less weight with some customers.
System description. The report includes a description of the service organisation's system: services, infrastructure, software, people, procedures, data and the boundary of the examination.
Auditor independence. The CPA firm cannot have designed or implemented the controls it examines. Readiness and audit must be separately resourced.
Report sections. Five: the auditor's report and opinion; management's assertion; the system description; the description of criteria, controls, tests performed and results; and an optional section for other information.
Report currency. A report covers a stated date or period. Customers expect a report covering a recent period, so the programme continues after the first one is issued.
Other important information
SOC 1, SOC 2 and SOC 3. SOC 1 addresses controls relevant to customers' financial reporting and is common for payroll, payment processing and financial administration. SOC 2 addresses security, availability, processing integrity, confidentiality and privacy. SOC 3 covers the same criteria as SOC 2 but is written for general distribution and contains far less detail.
UK and international firms. SOC 2 originated in the United States, but there is no requirement for the organisation examined to be incorporated or located there. The examination must be performed by an appropriately qualified CPA firm.
Penetration testing. The criteria do not mandate a penetration test by name. Most CPA firms expect evidence of vulnerability management, and many customers ask for a recent independent test alongside the report as part of their own review.
SOC 2 and ISO/IEC 27001. The two overlap substantially. Where both are required, running them as a single programme means one body of evidence serves both, and the second costs a fraction of the first.
Platform and framework. A compliance platform automates evidence collection, monitors selected controls and organises the audit. Determining scope, designing controls that fit the business, operating manual controls and holding the accountability remain with the firm. We run the programme; the firm retains ownership of its controls.
Our services
Scoping. Services, systems, locations and criteria confirmed and recorded, with the report type chosen against what the customer has actually asked for and by when.
Readiness assessment. Current controls and evidence assessed against the criteria in scope, with findings separated into what must be resolved before examination and what can follow.
Policies and procedures. The documentation set the criteria require, written to describe how the organisation operates.
Control implementation. Controls designed and embedded across access, change, development, vulnerability management, incident response, continuity, suppliers, training and monitoring.
Evidence management. Evidence requirements defined per control with named owners and frequencies, records reviewed and gaps resolved before fieldwork.
Platform configuration. Vanta, Drata, Secureframe or your existing environment configured properly, with manual evidence managed alongside the automated collection.
System description. Prepared and reviewed against the boundary agreed at scoping.
Audit coordination. CPA firm selection supported, audit pack and evidence index prepared, control owners briefed, and responses managed through fieldwork to the issued report.
Continuous assurance. Control re-testing, evidence refresh, supplier review and preparation for the next reporting period.
What we provide
Scoping and readiness. Criteria selection, boundary definition, gap assessment against each applicable criterion, and a prioritised plan with owners and dates.
Implementation. Policies, procedures, control design and embedding across the agreed scope.
Evidence and platform. Evidence plan per control, platform configuration, manual evidence management and pre-audit review.
Audit support. System description, audit pack, control owner briefing and management of auditor requests through fieldwork.
Continuous assurance. Between-period maintenance, customer questionnaire responses drawn from the same record, and preparation for the next examination.
Key information and requirements
SOC 2 is an attestation, not a certification. An independent CPA firm issues a report containing an opinion. There is no certificate.
Security is always in scope. The other four criteria are selected according to the service and the customer's requirements.
The auditor cannot help you prepare. Independence rules prevent the examining firm from designing or implementing the controls it tests.
Type 2 requires an operating period. Commonly three to twelve months, agreed with the CPA firm, during which controls must operate and produce evidence.
The report ages. Customers expect a report covering a recent period, so evidence production continues after the first report is issued.
Our Security Assurance Publications
Frequently Asked Questions about Soc 2
What is SOC 2 and which businesses need it?
SOC 2 is an assurance framework developed by the American Institute of Certified Public Accountants. It examines controls at a service organisation relevant to security, availability, processing integrity, confidentiality and privacy. It is most commonly requested from SaaS providers, cloud businesses, AI companies, fintech firms and managed service providers, in other words any organisation that stores, processes or transmits data on behalf of its customers. SOC 2 is not a statutory requirement in any jurisdiction. Demand comes from enterprise procurement, customer contracts and investor diligence. Most firms begin the programme because a specific customer has asked for a report, not because a regulator has required one.
Is SOC 2 a certification?
Strictly, no. SOC 2 is an attestation. An independent licensed CPA firm examines your controls and issues a report containing its professional opinion. You do not receive a certificate in the way you would following an ISO/IEC 27001 certification audit. The phrase "SOC 2 certification" is used widely and informally, including by customers, but the deliverable is a report. This matters commercially, because the report is what your customer's security team will read, and its usefulness depends on the scope, the period covered and the quality of the evidence behind it rather than on the fact of having passed.
What is the difference between Type 1 and Type 2?
A Type 1 report examines whether controls were suitably designed and implemented at a specified date. A Type 2 report examines both the design and whether those controls operated effectively throughout a defined review period. Type 2 provides stronger evidence of sustained operation and is what most enterprise customers ask for. You do not have to complete Type 1 before Type 2. Where controls are already operating and sufficient evidence exists, a firm can proceed directly to Type 2. Type 1 is most useful as an interim milestone where controls have recently been implemented and a customer has confirmed it will satisfy their immediate requirement.
How long does SOC 2 take?
A first-time Type 1 programme commonly reaches audit readiness in two to four months where scope is controlled and the principal technical controls are already operating. A Type 2 report adds an observation period agreed with the CPA firm, commonly between three and twelve months, during which controls must operate and produce evidence. Fieldwork and report production follow. The main variables are the scope, the maturity of existing controls, the quality of available evidence, internal availability and the CPA firm's own timetable. Where the deadline is set by a customer, we work backwards from that date and confirm at the outset what can credibly be achieved.
How much does SOC 2 cost?
Cost has three components. First, readiness and implementation support, which is the largest element for most first-time programmes. Second, any compliance platform subscription and specialist security testing required. Third, the independent CPA examination, which is contracted separately and paid directly to the audit firm. Fees vary according to the report type, the criteria in scope, the complexity of the systems involved, the number of locations and how much implementation is required. We agree a defined advisory scope and fee before work begins, so the implementation and audit costs remain separate and transparent.
What are the Trust Services Criteria?
There are five: security, availability, processing integrity, confidentiality and privacy. Each contains criteria and points of focus describing the characteristics a control should have in order to satisfy it. Security, often called the common criteria, is included in every SOC 2 report. The remaining four are selected according to the service you provide and the assurances your customers require. Adding criteria increases the controls and evidence involved, so the selection should reflect genuine relevance and customer requirements rather than an attempt to make the report appear more comprehensive than it needs to be.
What is actually in a SOC 2 report?
Five sections. The auditor's report, containing the CPA firm's opinion. Management's assertion, your own statement about the system and its controls. The system description, setting out the services, infrastructure, software, people, procedures and data within the boundary. The description of criteria, controls and tests, which lists each applicable criterion, the control addressing it, the testing performed and the results. And an optional fifth section for other information. Most of a customer's security team's attention goes to the opinion and to the tests and results, which is why the quality of the evidence behind each control matters more than the fact of holding a report.
Will Vanta, Drata or Secureframe make us SOC 2 ready?
They will help. These platforms connect to your systems, monitor selected controls, manage policies and organise evidence, and they materially reduce administration when configured properly. What they do not do is determine the correct scope, design controls that fit how your organisation actually operates, implement technical and procedural changes, operate manual controls, or guarantee that an auditor will accept the evidence produced. Buying the platform is the straightforward part. Completing the work is where first-time programmes stall, usually because the outstanding task list competes directly with product delivery for the same people. We work inside whichever platform you have selected rather than requiring you to change it.
Who performs the SOC 2 audit?
An independent licensed CPA firm. It cannot have designed or implemented the controls it examines, because that would compromise the independence on which the report depends. This is why readiness and implementation are handled separately from the examination itself, and it is a point firms often discover late, having assumed the auditor would guide them through preparation. We help select an appropriate firm, prepare your evidence and people, and manage communication throughout fieldwork. The CPA firm remains solely responsible for its opinion and for the report it issues.
What is the difference between SOC 1 and SOC 2?
SOC 1 addresses controls at a service organisation relevant to its customers' financial reporting, and is commonly required of payroll providers, payment processors and financial administration services. SOC 2 addresses controls relevant to security, availability, processing integrity, confidentiality and privacy. The right report depends on what your customers need assurance over. Some organisations require both, because they address different risks and different audiences. A SOC 3 report also exists: it covers the same criteria as SOC 2 but is written for general distribution and contains far less detail.
Should we choose SOC 2 or ISO/IEC 27001?
It depends principally on what your customers ask for. SOC 2 produces an independent report against the Trust Services Criteria and is most commonly requested in US enterprise procurement. ISO/IEC 27001 is an international certifiable standard for an information security management system and is more widely recognised in Europe and internationally. The underlying control environments overlap substantially, so many organisations pursue both and reuse the same risk process, policies, controls and evidence across the two programmes. Where both are required, running them together is materially cheaper than running them in sequence.
Do we need a penetration test for SOC 2?
The criteria do not mandate a penetration test by name. In practice, most CPA firms expect to see evidence of vulnerability management, and many enterprise customers ask for a recent independent penetration test alongside the report as part of their own review. For that reason we treat testing as part of the programme even though it is not strictly a SOC 2 requirement. It is arranged with a specialist testing firm and coordinated as part of the engagement, so the timing fits the observation period rather than arriving after the report has been issued.
What happens after the first report?
A SOC 2 report covers a stated date or period, and customers generally expect a current report during later assurance reviews. The programme therefore continues. Controls must keep operating, evidence must keep being produced, and the next reporting period begins where the last one ended. Firms that stop maintaining evidence in the weeks after a report is issued spend the following year reassembling it. Our continuous assurance support covers evidence review, control owner coordination, policy maintenance, supplier reviews, risk assessment and preparation for the next period, and we answer customer security questionnaires from the same record.


