The problem
SOC 2 is where UK companies selling into the United States discover that their security is fine and their evidence is not. The report is not a certificate you pass; it is an opinion an auditor writes about whether your controls operated over a period, which means the work is largely about proving what you already do.
Most readiness projects go wrong in the same two places. The scope is drawn too wide, usually by picking all five Trust Services Criteria because more sounds better, and the observation window starts before anyone has checked that the evidence will actually exist when the auditor asks for it.
What you get
- A scope that covers what your customers are asking about and nothing else
- Control design mapped to the Trust Services Criteria, in your language rather than the framework's
- An evidence plan that names, for each control, what artefact proves it and where that artefact comes from
- A gap assessment before the observation window opens, when fixing things is still cheap
- Support through auditor selection and the questions they will ask
- A view on Type I versus Type II that reflects what your customers will accept
Proof point
Delivered by someone who has sat on the other side of an audit as ISO 27001 and ISO 42001 Lead Auditor. The useful thing about that is knowing which answers get accepted, which get a follow-up question, and which quietly become a finding.