SOC 2 · HIPAA · ISO 27001
SOC 2 readiness for companies whose buyers have started asking for a report.
Your buyers are asking for a SOC 2 report and your engineers are asking who owns it. We take you from first gap assessment to auditor handoff with fixed pricing, operator-led delivery, and no platform to buy.
Before you buy anything
Compliance software, readiness consultants, and audit firms do different work. Buyers are routinely sold one as though it were the others, and that is where SOC 2 budgets get wasted.
Vanta, Drata, Secureframe and others connect to your systems and gather evidence automatically. That is real work and it saves real time. It is also the part most people think is the whole job.
Which controls actually fit your business, whether your evidence would survive a sampler pulling it, and what the auditor will ask that no dashboard ever will. A platform can tell you a control is failing. It cannot tell you whether it was the right control for your business in the first place. This is the job we do.
A licensed CPA firm performs the examination and issues the report. They cannot design what they attest to, which is why readiness and audit are separate purchases. We are not an audit firm and we never grade our own work.
You do not always need all three. You do need to know which one you are buying.
SOC 2 Readiness
Start where you are. Every engagement is remote, fixed-scope, and priced for teams without a compliance department.
Coach
4 to 8 weeks · your team drives
Office hours, document review, control guidance, and auditor liaison support while your team owns the work. Built for early-stage companies where the founders and engineers will carry the program themselves.
Most Popular
12 to 16 weeks · we drive end to end
Policies, control implementation, evidence collection, vendor reviews, pre-audit walkthrough, and a clean handoff to the audit firm. AI-drafted documentation, human-reviewed, audit-grade.
Retainer
Rolling · after your audit
A SOC 2 report ages the day it is issued. Evidence upkeep, control monitoring, vendor reviews, security questionnaire support, and Type II observation-window discipline, kept alive between audits.
We are not an audit firm and do not issue SOC 2 reports. Readiness and advisory only, by design: nobody should audit their own work. When you are ready, we refer you to a licensed CPA firm and support you through the audit.
Email us two paragraphs: what you sell, and what your buyer is asking for. We will tell you honestly whether you need coaching, full readiness, or nothing yet. No call required.
Get an honest readThe Client Portal
Every engagement runs through a live client portal: control-by-control readiness across your Trust Services Criteria, the phase timeline with real dates, and a running engagement log of everything that has happened. You watch your audit readiness move instead of waiting for a status meeting.
Regulated Buyers
SOC 2 is rarely the whole ask. Regulated buyers layer their own obligations on top: HIPAA for health data, FERPA for student records, ISO 27001 for international and enterprise deals. We map them into one control set so you build one program, not three.
Healthcare and healthtech buyers
Security Rule safeguards and business associate obligations built into the same control set your SOC 2 runs on. One engagement, no second firm.
University and K-12 procurement
Student-record obligations, data governance language for institutional contracts, and the security questionnaires university procurement sends before a pilot becomes an adoption.
What university procurement actually checks →Enterprise and international deals
When larger buyers ask for ISO certification alongside your SOC 2 report, we extend the program rather than starting over. Shared controls, one evidence pipeline.
Shipping AI features? Buyers are starting to add AI questions to the same security reviews. That work has its own inventory, controls and evidence, so we run it as a separate practice called Assay. See Assay →
Engagement Timeline
Four phases, explicit deliverables, an end-of-phase checkpoint every time. No floating timeline, no scope creep.
Weeks 1 to 3
Weeks 4 to 7
Weeks 8 to 12
Weeks 13 to 16
"Audit dates are deadlines, not aspirations. We treat them that way."
Why Control and Function
The practice was built on running compliance as the operator, not observing it as a consultant. We led a SOC 2 Type I program end to end as the sole IT operator, with no outside MSP and no compliance platform, and the auditor passed it clean on the first attempt. We answered buyer security questionnaires ourselves in that role. We know what an auditor will press on and where companies waste cycles.
In a company without a compliance function, security lands on the engineering lead's desk. The compliance platforms assume you have a dedicated compliance manager. You do not, and you should not need one. We deliver done-with-you readiness priced for your size.
Most readiness firms are pure GRC writers who cannot configure SSO or speak to engineers in their own language. We can. Faster engagements, fewer escalations, and a delivery cadence technical teams respect.
Policy sets and system descriptions eat consultant hours when drafted by hand, and firms bill accordingly. Our AI-assisted documentation pipeline compresses that work to days, with a human reviewing every artifact before it carries our name. Audit-grade output at a fraction of the market's hours.
We take no referral fees from Vanta, Drata, Secureframe, or anyone else. The neutrality comes from experience, not distance: we have hands-on Secureframe experience and speak the others fluently. If a platform genuinely fits your environment we will implement it with you. If it does not, we will say so and save you the subscription.
SOC 2 reports are issued by licensed CPA firms, and we are not one by design. We prepare you, point you to licensed audit firms, and hand off cleanly. We take no referral fee from any of them, so our recommendation has no revenue attached. We never audit our own work. That separation protects your report.
FAQ
Readiness coaching starts at $8,000 for teams that will drive the work themselves. Full readiness, where we drive the program end to end, starts at $15,000. Managed compliance retainers run $1,500 to $4,000 per month after your audit, and dual-framework engagements are scoped individually. Every engagement is fixed fee, invoiced by milestone, payable by ACH or card. No hourly meters.
No. SOC 2 audits are performed by licensed CPA firms. We provide readiness and advisory services only: we prepare you, refer you to audit firms (taking no referral fee), and support you through the audit window. We never audit our own work. That separation protects the integrity of your report.
A full readiness engagement typically runs 12 to 16 weeks from kickoff to auditor handoff. Coaching engagements run 4 to 8 weeks. One planning reality worth knowing early: audit firms book fieldwork 2 to 3 months out, and the fourth quarter is their busy season, so the audit date drives the schedule more than the readiness work does.
A Type I covers control design at a point in time; a Type II covers operation over a period, usually 3 to 12 months. When a deal or procurement gate needs paper soon, Type I first is the right call. When nothing is gating, many companies now go straight to a Type II over a short observation window and skip one audit fee. We will tell you honestly which fits your situation, including when the answer saves you money with someone else.
Not necessarily. Compliance platforms automate evidence collection well for some environments and poorly for others. We are platform-neutral and take no referral fees: if one fits your stack we will implement it with you, and if not, the program we ran ourselves used no platform at all and passed its audit clean on the first attempt.
Yes. Healthcare buyers bring HIPAA, education buyers bring FERPA and the HECVAT questionnaire, and international or enterprise deals often ask for ISO 27001. We run dual-framework engagements that map these into a single control set, so you build one program instead of three. Selling into universities? Read what university procurement actually checks.
Vendor reports: what Complementary User Entity Controls are, and why holding a vendor’s SOC 2 is not reviewing it.
Contact
A 30-minute readiness call costs nothing and tells you exactly where you stand, whether it is your first SOC 2 or a second framework on top of it. No sales pressure. If we are not the right fit, we will say so and point you to someone who is.