Security & Compliance

SOC 2 readiness

For material US enterprise deals. Roughly 70–80% of the controls overlap with ISO 27001.

Typical duration
9–14 months including observation
Scope
Fixed and written before you sign
Team
Principal plus 1–2 specialists

Who it is for

SaaS companies with US enterprise deals.

Everything below is in the scope document, written and priced before anything starts. If something you need is not on this list, say so and it goes in the quote — or we tell you it does not belong in this engagement.

  • Trust services criteria selected to your commitments rather than all five by default
  • Control design and gap remediation
  • Evidence automation, so the six-month observation window is not a manual burden
  • Auditor selection and readiness assessment
  • Type I then Type II sequencing
Worth saying up front

If you have not done ISO 27001 yet, doing it first is cheaper overall. We will say so.

How every Security & Compliance engagement runs →

Next step

Thirty minutes on whether this is the right engagement.

If a different service on this list fits better, or if you do not need us at all, that is what the call will conclude.