Compliance (ISO / SOC 2)
Getting you to the point where a certification or attestation audit is a formality. We assess against the standard, build the control set and documentation you are missing, help you operate the controls long enough to generate evidence, and prepare you for the audit itself. We are not the certification body, which is precisely why we can help you prepare.
Timeline
Three to nine months, dominated by the observation period rather than by our work. SOC 2 Type I and ISO 27001 Stage 1 come sooner; a Type II needs a genuine observation window — commonly three to twelve months — and no amount of preparation shortens it.
You get
- Gap analysis against every applicable control, with effort estimates
- A written policy and procedure set fitted to how your team works
- A control set with named owners and a documented operating cadence
If any of these is your week, this is the service.
A deal is blocked on a certificate you do not have
An enterprise customer has made SOC 2 or ISO 27001 a condition of signing, with a date attached.
What we do
A gap assessment first, so you know honestly whether the date is achievable before you commit to it.
You do not know which standard you need
SOC 2 and ISO 27001 overlap heavily but answer to different audiences, and picking wrong costs a year.
What we do
A short scoping conversation against who is actually asking — often the answer is one now and the other later, reusing most of the work.
You have policies nobody follows
A template policy set was bought and filed, and an auditor will ask for evidence the controls operated, not that they were written.
What we do
Controls designed to match how your team actually works, so the evidence is a by-product instead of a scramble.
You failed or stalled a previous attempt
An audit surfaced findings you were not prepared for, or the project stalled once it became clear how much was missing.
What we do
A remediation-first engagement that starts from the findings you already have rather than from the beginning.
Every step, and what leaves our hands at the end of it.
- 01
Scope & standard
Decide which standard, which entities and systems are in scope, and — for SOC 2 — which trust services criteria apply.
→ Scope & applicability statement
- 02
Gap assessment
Assess current state against every applicable control, and say plainly how far away you are and what it will take.
→ Gap analysis & effort estimate
- 03
Build
Write the policies, procedures and the control set — designed around how your team actually works, so they get followed.
→ Policy & control set
- 04
Operate & evidence
Run the controls for the observation period, collecting evidence as you go. This is the part that cannot be compressed.
→ Evidence pack
- 05
Audit readiness
A dry run against the auditor's own checklist, so anything they would raise is found by us first.
→ Readiness review
- 06
Audit support
We sit alongside you through fieldwork, answer the auditor's technical questions and help close any finding raised.
Deliverables.
- Gap analysis against every applicable control, with effort estimates
- A written policy and procedure set fitted to how your team works
- A control set with named owners and a documented operating cadence
- An evidence pack assembled the way the auditor will ask for it
- A readiness review run against the auditor's checklist
- Support through fieldwork and remediation of anything raised
Before we can quote.
- 01Which standard, and who is asking for it
- 02The entities, systems and locations that need to be in scope
- 03Any existing policies, evidence or prior audit findings
- 04An internal owner with the authority to make process changes stick
- 05Your target date, and what depends on it
Do not worry about having all of it. Send what you have and we will work out the rest on the scoping call.
Compliance (ISO / SOC 2), answered.
Can you certify us?
No, and nobody who prepares you should. Certification and attestation must come from an independent body — we prepare you, and we can introduce you to auditors we have worked with.
SOC 2 or ISO 27001?
SOC 2 is what North American enterprise buyers usually ask for; ISO 27001 is the international certification, and is more commonly asked for in Europe and Asia. The underlying control work overlaps heavily, so doing one makes the other substantially cheaper.
How fast can we get there?
The honest answer is that the observation period sets the floor. We can compress preparation considerably; we cannot compress the months a Type II auditor needs to see controls operating.
Do we need a pentest for this?
Usually yes — both standards expect independent technical testing, and auditors routinely ask for a current report. Pair this with VAPT or a pentest, which is why they are on the same platform.
Scope a Compliance (ISO / SOC 2).
Compliance (ISO / SOC 2) is already selected below. Tell us what you are trying to protect and what is driving the timing — if a different service fits better, we will say so rather than sell you this one.