Security & Compliance
SOC 2 readiness
For material US enterprise deals. Roughly 70–80% of the controls overlap with ISO 27001.
Who it is for
SaaS companies with US enterprise deals.
Everything below is in the scope document, written and priced before anything starts. If something you need is not on this list, say so and it goes in the quote — or we tell you it does not belong in this engagement.
- Trust services criteria selected to your commitments rather than all five by default
- Control design and gap remediation
- Evidence automation, so the six-month observation window is not a manual burden
- Auditor selection and readiness assessment
- Type I then Type II sequencing
Worth saying up front
If you have not done ISO 27001 yet, doing it first is cheaper overall. We will say so.
Also in Security & Compliance
ISO 27001 implementationThe information-security certification European RFPs treat as table stakes.12–16 weeksDPDP Act complianceIndia's Digital Personal Data Protection Act, applied to systems you already run.3–8 weeksGDPR & data-protection advisoryFor EU customers and EU data, including the transfer mechanism question.3–8 weeksvCISO retainerPart-time security leadership for companies that need the function but not the salary.Monthly
Next step
Thirty minutes on whether this is the right engagement.
If a different service on this list fits better, or if you do not need us at all, that is what the call will conclude.