01Program
ISO 27001 and SOC 2 audit readiness, built on controls that operate every day
ISO 27001, SOC 2, PCI DSS, GDPR, DPDP Act and SEBI CSCRF readiness built on controls that reduce real risk, with evidence generated by normal operations, not audit-week heroics.
- Name
- ISO 27001 & SOC 2 Readiness
- Line
- 01 · Cybersecurity
- Type
- Outcome program, combines several practices
01The problem
Documentation sprints do not survive renewal.
Compliance programs built as documentation sprints collapse at renewal: evidence is stale, controls exist on paper only, and every audit is a scramble. Customers and regulators are getting better at telling the difference.
02Scope
What the audit readiness program covers.
- Multi-framework gap assessment
- ISMS and policy framework development
- Control implementation support
- Evidence collection program design
- Internal audit and readiness review
- Certification audit support
03Approach
How an audit readiness engagement runs.
Cross-framework control mapping: implement a control once and map it to each framework that requires it. The same method informs the design of [GRC](/products/grc), which is in development. Frameworks are listed under [compliance frameworks](/services/cybersecurity/compliance-frameworks).
Gap assessment
Honest current-state measurement against the target framework, with a sequenced, realistic roadmap.
Implement controls that operate
Control sets sized to your organization, deployed with your teams, generating evidence as a by-product of working.
Verify before the auditor does
Internal audit and readiness review so the external audit holds no surprises.
04Outcomes
What the audit readiness program is built to achieve.
- Gap-to-certification roadmap with realistic timelines
- Controls implemented and operating, as well as documented
- Evidence collection embedded into existing workflows
- An external audit entered with gaps already known and addressed
When this work fits
- Companies asked for an ISO 27001 certificate or SOC 2 report during procurement
- Organizations facing a first external audit without a dedicated compliance team
- Teams holding one framework and adding a second without duplicating controls
- Security leaders whose evidence is rebuilt by hand before every audit cycle
05Questions
Audit readiness: questions we are asked
Duration is driven by four things: the scope of the ISMS, how many controls already operate, how much time control owners can give, and how quickly risk treatment decisions are made. A narrow scope with mature IT operations moves fastest. Auditors also expect the management system to be running before Stage 2, including an internal audit and a management review, so some operating history is unavoidable. The gap assessment produces a dated plan for your situation.
Start with the one your buyers or regulators ask for. ISO 27001 leads to a certificate for an information security management system and is recognized internationally. SOC 2 is an attestation report on controls against the AICPA Trust Services Criteria, requested most often in North American procurement. The control work overlaps heavily, so the second framework takes far less effort when both are planned together. See one control set for ISO 27001 and SOC 2.
A readiness assessment is advisory work. It measures your controls against the framework, lists the gaps and helps you close them. The certification audit is an independent examination. For ISO 27001, an accredited certification body performs the Stage 1 and Stage 2 audits and issues the certificate. For SOC 2, a licensed CPA firm issues the report. Onion Infosec provides readiness and audit support and does not issue certificates or reports. That separation keeps the audit independent.
Largely, yes. Access control, change management, logging, supplier management and incident handling appear in ISO 27001 Annex A, the SOC 2 Trust Services Criteria, PCI DSS and most sector rules under different wording. Each control is implemented once and mapped to every requirement it satisfies, so one piece of evidence serves several audits. Framework-specific items remain, such as the ISO 27001 Statement of Applicability or PCI DSS scoping. The frameworks we align to are listed under compliance frameworks.
Auditors look for proof that a control operated, as well as a policy saying it should. Typical samples include access reviews with sign-off, joiner and leaver tickets, change approvals, backup restore tests, vulnerability remediation records, incident logs, supplier reviews and training records. ISO 27001 also requires the risk assessment, the Statement of Applicability, internal audit reports and management review minutes. A SOC 2 Type 2 report samples evidence across the whole review period, so a gap in the middle still counts.
Often alongside
