Control and Function

SOC 2 · HIPAA · ISO 27001

We don't sell platforms. We earn audits.

SOC 2 readiness for companies whose buyers have started asking for a report.

Your buyers are asking for a SOC 2 report and your engineers are asking who owns it. We take you from first gap assessment to auditor handoff with fixed pricing, operator-led delivery, and no platform to buy.

12 to 16 wks
From kickoff to auditor handoff, full readiness
Fixed price
Coaching from $8K, full readiness from $15K
First attempt
The program we ran ourselves passed its audit clean
Zero
Referral fees from compliance platforms. Advice stays neutral
Operator-led, not advisory-only · AI-accelerated documentation, human-reviewed · Fixed scope, fixed price · Platform-neutral, no referral fees · Advisory only, never the auditor

Before you buy anything

Three jobs, three parties

Compliance software, readiness consultants, and audit firms do different work. Buyers are routinely sold one as though it were the others, and that is where SOC 2 budgets get wasted.

The platform collects the proof

Vanta, Drata, Secureframe and others connect to your systems and gather evidence automatically. That is real work and it saves real time. It is also the part most people think is the whole job.

The consultant decides what is worth proving

Which controls actually fit your business, whether your evidence would survive a sampler pulling it, and what the auditor will ask that no dashboard ever will. A platform can tell you a control is failing. It cannot tell you whether it was the right control for your business in the first place. This is the job we do.

The auditor independently tests it

A licensed CPA firm performs the examination and issues the report. They cannot design what they attest to, which is why readiness and audit are separate purchases. We are not an audit firm and we never grade our own work.

You do not always need all three. You do need to know which one you are buying.

SOC 2 Readiness

The readiness ladder

Start where you are. Every engagement is remote, fixed-scope, and priced for teams without a compliance department.

Coach

SOC 2 Readiness Coaching

From $8K

4 to 8 weeks · your team drives

Office hours, document review, control guidance, and auditor liaison support while your team owns the work. Built for early-stage companies where the founders and engineers will carry the program themselves.

Most Popular

Full SOC 2 Readiness

From $15K

12 to 16 weeks · we drive end to end

Policies, control implementation, evidence collection, vendor reviews, pre-audit walkthrough, and a clean handoff to the audit firm. AI-drafted documentation, human-reviewed, audit-grade.

Retainer

Managed Compliance

$1.5 to $4K / mo

Rolling · after your audit

A SOC 2 report ages the day it is issued. Evidence upkeep, control monitoring, vendor reviews, security questionnaire support, and Type II observation-window discipline, kept alive between audits.

We are not an audit firm and do not issue SOC 2 reports. Readiness and advisory only, by design: nobody should audit their own work. When you are ready, we refer you to a licensed CPA firm and support you through the audit.

Not sure what you actually need?

Email us two paragraphs: what you sell, and what your buyer is asking for. We will tell you honestly whether you need coaching, full readiness, or nothing yet. No call required.

Get an honest read

The Client Portal

Your engagement, visible.

Every engagement runs through a live client portal: control-by-control readiness across your Trust Services Criteria, the phase timeline with real dates, and a running engagement log of everything that has happened. You watch your audit readiness move instead of waiting for a status meeting.

  • Live control statuses, from client-asserted to independently validated
  • Phase timeline that moves when the plan moves, with your audit date always in view
  • A dated engagement log, so the record of the work is never a mystery
  • Evidence pointers only, never your raw artifacts: sensitive material stays in your environment

Regulated Buyers

Selling into universities, health systems, or the enterprise?

SOC 2 is rarely the whole ask. Regulated buyers layer their own obligations on top: HIPAA for health data, FERPA for student records, ISO 27001 for international and enterprise deals. We map them into one control set so you build one program, not three.

SOC 2 + HIPAA

Scoped

Healthcare and healthtech buyers

Security Rule safeguards and business associate obligations built into the same control set your SOC 2 runs on. One engagement, no second firm.

Ed-tech + FERPA

Scoped

University and K-12 procurement

Student-record obligations, data governance language for institutional contracts, and the security questionnaires university procurement sends before a pilot becomes an adoption.

What university procurement actually checks →

SOC 2 + ISO 27001

Scoped

Enterprise and international deals

When larger buyers ask for ISO certification alongside your SOC 2 report, we extend the program rather than starting over. Shared controls, one evidence pipeline.

Shipping AI features? Buyers are starting to add AI questions to the same security reviews. That work has its own inventory, controls and evidence, so we run it as a separate practice called Assay. See Assay →

Engagement Timeline

What Full Readiness actually looks like.

Four phases, explicit deliverables, an end-of-phase checkpoint every time. No floating timeline, no scope creep.

01

Weeks 1 to 3

Scope and gap

  • · System description drafted
  • · Trust Services Criteria gap assessment
  • · Type I vs Type II sequencing plan
  • · Platform decision, if any
02

Weeks 4 to 7

Controls built

  • · Policy set drafted and adopted
  • · Access, logging, and change controls implemented
  • · Vendor management stood up
  • · Human review on every artifact
03

Weeks 8 to 12

Evidence collected

  • · Evidence mapped to every control
  • · Remediation support where gaps remain
  • · Vendor and subprocessor reviews
  • · Internal dry-run walkthrough
04

Weeks 13 to 16

Auditor handoff

  • · Audit firm referral and selection
  • · Pre-audit walkthrough
  • · Evidence package delivered
  • · Support through the audit window

"Audit dates are deadlines, not aspirations. We treat them that way."

Why Control and Function

Most readiness firms write policies. We get you through the audit.

01

Operational, not advisory

The practice was built on running compliance as the operator, not observing it as a consultant. We led a SOC 2 Type I program end to end as the sole IT operator, with no outside MSP and no compliance platform, and the auditor passed it clean on the first attempt. We answered buyer security questionnaires ourselves in that role. We know what an auditor will press on and where companies waste cycles.

02

Built for teams without a compliance department

In a company without a compliance function, security lands on the engineering lead's desk. The compliance platforms assume you have a dedicated compliance manager. You do not, and you should not need one. We deliver done-with-you readiness priced for your size.

03

IT, security, and compliance under one roof

Most readiness firms are pure GRC writers who cannot configure SSO or speak to engineers in their own language. We can. Faster engagements, fewer escalations, and a delivery cadence technical teams respect.

04

AI-accelerated, human-reviewed

Policy sets and system descriptions eat consultant hours when drafted by hand, and firms bill accordingly. Our AI-assisted documentation pipeline compresses that work to days, with a human reviewing every artifact before it carries our name. Audit-grade output at a fraction of the market's hours.

05

Platform-neutral, always

We take no referral fees from Vanta, Drata, Secureframe, or anyone else. The neutrality comes from experience, not distance: we have hands-on Secureframe experience and speak the others fluently. If a platform genuinely fits your environment we will implement it with you. If it does not, we will say so and save you the subscription.

06

Never the auditor

SOC 2 reports are issued by licensed CPA firms, and we are not one by design. We prepare you, point you to licensed audit firms, and hand off cleanly. We take no referral fee from any of them, so our recommendation has no revenue attached. We never audit our own work. That separation protects your report.

FAQ

The questions every buyer asks first.

What does SOC 2 readiness cost?+

Readiness coaching starts at $8,000 for teams that will drive the work themselves. Full readiness, where we drive the program end to end, starts at $15,000. Managed compliance retainers run $1,500 to $4,000 per month after your audit, and dual-framework engagements are scoped individually. Every engagement is fixed fee, invoiced by milestone, payable by ACH or card. No hourly meters.

Do you perform the SOC 2 audit itself?+

No. SOC 2 audits are performed by licensed CPA firms. We provide readiness and advisory services only: we prepare you, refer you to audit firms (taking no referral fee), and support you through the audit window. We never audit our own work. That separation protects the integrity of your report.

How long does it take?+

A full readiness engagement typically runs 12 to 16 weeks from kickoff to auditor handoff. Coaching engagements run 4 to 8 weeks. One planning reality worth knowing early: audit firms book fieldwork 2 to 3 months out, and the fourth quarter is their busy season, so the audit date drives the schedule more than the readiness work does.

Type I or Type II?+

A Type I covers control design at a point in time; a Type II covers operation over a period, usually 3 to 12 months. When a deal or procurement gate needs paper soon, Type I first is the right call. When nothing is gating, many companies now go straight to a Type II over a short observation window and skip one audit fee. We will tell you honestly which fits your situation, including when the answer saves you money with someone else.

Do we need Vanta, Drata, or Secureframe?+

Not necessarily. Compliance platforms automate evidence collection well for some environments and poorly for others. We are platform-neutral and take no referral fees: if one fits your stack we will implement it with you, and if not, the program we ran ourselves used no platform at all and passed its audit clean on the first attempt.

Can you handle HIPAA, FERPA, or ISO 27001 alongside SOC 2?+

Yes. Healthcare buyers bring HIPAA, education buyers bring FERPA and the HECVAT questionnaire, and international or enterprise deals often ask for ISO 27001. We run dual-framework engagements that map these into a single control set, so you build one program instead of three. Selling into universities? Read what university procurement actually checks.

Vendor reports: what Complementary User Entity Controls are, and why holding a vendor’s SOC 2 is not reviewing it.

Contact

Start the conversation.

A 30-minute readiness call costs nothing and tells you exactly where you stand, whether it is your first SOC 2 or a second framework on top of it. No sales pressure. If we are not the right fit, we will say so and point you to someone who is.

Denver, Colorado · Available for engagements across the United States