P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Compliance and audit

SOC 2 Readiness

Get to a clean SOC 2 report without buying a platform you do not need. Scope, control design, evidence, and the auditor conversation, run by someone who has been the auditee.

SOC 2 is where organisations discover that their security is fine and their evidence is not. The report is not a certificate you pass: it is an opinion an auditor writes about whether your controls operated across a period. Most of the work, therefore, is proving what you already do rather than building anything new.

5

Trust Services Criteria

Only Security is mandatory.

1

Criterion most buyers ask for

Security, in the large majority of contracts.

3–12

Month observation window

Type II. The window is where evidence discipline is tested.

0

Certificates issued

SOC 2 produces an auditor's opinion, not a certificate.

What it covers

Security

The only mandatory criterion. For many organisations it is also the only one customers are actually asking about, and adding the others because more sounds better is the most common way to double the cost of a first report.

Availability

Worth including when you sell an uptime commitment, because the auditor will test the monitoring and the incident process behind it.

Confidentiality

Frequently confused with privacy. This is about information you have agreed to protect, not about personal data.

Processing integrity and privacy

The two most often added without need. Privacy in particular overlaps UK GDPR work you may already have done, and duplicating it is expensive.

How the engagement runs

  1. 1

    Scope to the question being asked

    Read the customer contracts and security questionnaires that triggered this. They usually name the criteria, and they rarely ask for all five.

  2. 2

    Map controls to what you already do

    Most controls exist already under a different name. The exercise is describing them in the auditor's terms, not inventing a parallel control set.

  3. 3

    Build the evidence plan

    For every control, name the artefact that proves it and where the artefact comes from. This is the step that decides whether the observation window works.

  4. 4

    Close gaps before the clock starts

    A gap found in month one of a Type II window costs a remediation note. The same gap found in month five can cost the report.

  5. 5

    Select the auditor

    Firms differ in how they test and how much they push back. Choosing before you understand your own evidence is choosing blind.

  6. 6

    Run the window and hand over

    Evidence collected as the period runs rather than assembled at the end, which is the difference between a calm audit and a fortnight of archaeology.

What you walk away with

  • A scope recommendation with the reasoning, including which criteria to leave out and why
  • Control descriptions mapped to the Trust Services Criteria
  • An evidence plan naming the artefact and its source for every control
  • A gap assessment completed before the observation window opens
  • A Type I versus Type II recommendation based on what your customers will accept
  • Auditor selection support and preparation for the questions they ask

How this plays out

Example scenario

A UK SaaS company blocked on a US enterprise deal.

The work: Read the customer's actual security addendum before scoping anything.

The customer required Security only. The proposed five-criteria scope would have roughly doubled cost and timeline for criteria nobody had asked about.

Example scenario

An organisation five months into a twelve month Type II window.

The work: Evidence review against the control set.

Access reviews had been performed but never recorded, so five months of a control's operation was unprovable. The window effectively restarted, which is the expensive version of this lesson.

Example scenario

A company holding ISO 27001 and assuming SOC 2 would be automatic.

The work: Mapping exercise between the two.

Substantial overlap in controls and almost none in evidence expectations. ISO tests that a management system exists; SOC 2 tests that specific controls operated on specific dates.

Start the conversation

A short call to understand your situation; a clear scope if the engagement fits, and a straight answer if it does not.

Discuss SOC 2 readiness

Share this

Send it to whoever owns the budget or the risk.

← All services

The problem

SOC 2 is where UK companies selling into the United States discover that their security is fine and their evidence is not. The report is not a certificate you pass; it is an opinion an auditor writes about whether your controls operated over a period, which means the work is largely about proving what you already do.

Most readiness projects go wrong in the same two places. The scope is drawn too wide, usually by picking all five Trust Services Criteria because more sounds better, and the observation window starts before anyone has checked that the evidence will actually exist when the auditor asks for it.

What you get

  • A scope that covers what your customers are asking about and nothing else
  • Control design mapped to the Trust Services Criteria, in your language rather than the framework's
  • An evidence plan that names, for each control, what artefact proves it and where that artefact comes from
  • A gap assessment before the observation window opens, when fixing things is still cheap
  • Support through auditor selection and the questions they will ask
  • A view on Type I versus Type II that reflects what your customers will accept

Proof point

Delivered by someone who has sat on the other side of an audit as ISO 27001 and ISO 42001 Lead Auditor. The useful thing about that is knowing which answers get accepted, which get a follow-up question, and which quietly become a finding.