Assessment & advisory
SOC 2 Readiness & Audit Support
SOC 2 readiness for SaaS, healthcare technology, and service providers: scope Trust Services Criteria, remediate gaps, and prepare Type 1 or Type 2 evidence.
Discuss your SOC 2 requirementsWhat we assess
We define the system boundary, relevant Trust Services Criteria, subservice organizations, and control owners. A Type 1 examination considers design at a point in time; Type 2 also examines operating effectiveness over a period. Choosing the report period before controls are operating can create avoidable evidence gaps.
Evidence to prepare
- System description, service commitments, and control-to-criteria mapping.
- Approved policies, access provisioning and review records, and change approvals.
- Risk assessments, incident records, vendor reviews, and security monitoring evidence across the examination period.
Keep design evidence separate from operating evidence. An approved procedure shows how a control is designed; dated records show whether it ran consistently over the review period. Evidence should identify its source, owner, scope, and collection date.
What you receive
- Readiness gap register with control owners and a prioritized remediation plan.
- Evidence index distinguishing control design from operating records.
- Auditor coordination and responses to evidence requests within the agreed engagement scope.
The assessment outcome
An organized control environment and evidence package for the independent CPA’s examination. The CPA issues the SOC report; readiness support does not guarantee an unqualified opinion.
Common questions
Is SOC 2 a certification?
SOC 2 is an independent CPA attestation report. Readiness work helps an organization prepare the system, controls, and evidence before that examination.
What determines the engagement timeline and cost?
The system boundary, number of entities and locations, existing control maturity, evidence availability, and assessment pathway determine the effort. Share your customer requirements and target milestone so we can define a realistic scope before proposing a schedule.
Framework reference: AICPA — SOC suite of services. Guidance reviewed October 4, 2026; confirm current requirements when scoping an engagement.
