Skip to content

service // soc2

SOC 2

SOC 2 readiness, controls, and evidence for service providers

SOC 2 is the trust currency of the service industry. If your clients are asking for it — or will be — you need a path through Type I and Type II that doesn't consume your whole team. I help you get there with process refinement, documentation, and evidence workflows that auditors can actually follow.

What's included

Common questions

What is the difference between SOC 2 Type I and Type II?

A SOC 2 Type I report evaluates whether your controls are designed properly at a point in time. A Type II report evaluates whether those controls operated effectively over a period of time (typically 3-12 months). Most clients ultimately want Type II; Type I is often the practical first step.

Does my small business need SOC 2?

If you provide services to other businesses — especially SaaS, IT, or data-processing services — your clients may ask for a SOC 2 report. It is increasingly a condition of enterprise contracts. If you are not being asked, it may not be the right framework for you yet.

How long does a SOC 2 project take?

A Type I project typically takes 3-9 months depending on your starting point. Type II adds an observation period of 3-12 months on top of that. Much depends on how much evidence and documentation already exists.

What does a SOC 2 engagement cost?

Costs vary widely by scope and firm. Independent consultants can often deliver a large share of the readiness work for a fraction of what a Big 4 firm charges, and you keep a direct relationship with the person doing the work.

Talk it through

A free 30-minute call to see whether SOC 2 applies to you and what the first step looks like.

book the call