01Program
SOC 2 compliance and readiness services for Type 1 and Type 2 reports
Readiness for a SOC 2 examination: choosing the Trust Services Criteria in scope, designing controls that map to them, collecting evidence across the observation period and working with the licensed CPA firm that issues the report. The report is theirs to issue; the readiness is our work.
- Name
- SOC 2 Readiness
- Line
- 01 · Cybersecurity
- Type
- Outcome program, combines several practices
01The problem
A SOC 2 report is sampled across the whole period, so one gap counts.
SOC 2 is usually triggered by a customer: a security questionnaire, a procurement deadline, a contract clause. The temptation is to treat it as paperwork and move fast. A Type 2 report then exposes the shortcut, because the auditor samples evidence across every month of the observation period, and a control that lapsed in month four is an exception in the report your customer reads.
Readiness done properly is quieter. The controls are the ones a well-run company would operate anyway, the evidence is produced by the systems that already run, and the report describes how the company actually works.
02Scope
What the SOC 2 program covers.
Scope and criteria selection
Which systems, which Trust Services Criteria (Security, plus Availability, Confidentiality, Processing Integrity or Privacy as needed) and which report type, decided against what your customers ask for.
Readiness assessment
Control-by-control review against the criteria, with gaps rated by effort and by how visible they would be in a report.
Control design and implementation
Controls sized to the company, implemented with the teams that will operate them, and written as the control descriptions the auditor will test.
Evidence program
A calendar and an owner for every piece of evidence, with collection automated from identity, cloud, ticketing and code platforms wherever possible.
Policies and system description
The policy set and the system description that the report is built around, written to describe how the company works today.
Type 1 and Type 2 examination support
Auditor selection, evidence requests, walkthroughs and exception handling during the examination, and the bridge letter after it.
Vendor and subservice organization management
Carve-out or inclusive treatment of cloud providers and critical vendors, with the complementary controls documented.
03Approach
How a SOC 2 engagement runs.
The AICPA Trust Services Criteria and the points of focus beneath them. Controls are mapped once across SOC 2, [ISO 27001](/services/cybersecurity/iso-27001) and other frameworks, so a company holding both does not run two programs. See [running ISO 27001 and SOC 2 from one control set](/resources/blog/iso-27001-and-soc-2-one-control-set).
Decide the report
Type 1 for a point-in-time description of design, Type 2 for operating effectiveness over a period. Most enterprise buyers want Type 2; a Type 1 first is a reasonable step when a deadline is close.
Assess and design
Measure existing controls against the criteria, then design the smallest control set that satisfies them and reduces real risk.
Implement and automate evidence
Put controls into operation and connect evidence collection to the systems of record, so the audit does not depend on screenshots.
Run the observation period
Monitor control operation through the period, catch lapses early, and record remediation so that exceptions are rare and explained.
Support the examination
Prepare the evidence population, host walkthroughs and manage the auditor’s requests to a schedule.
04Outcomes
What the SOC 2 program is built to achieve.
- A scoped Trust Services Criteria selection and report type that matches customer demand
- Controls implemented and described in the auditor’s own terms
- Evidence collected on a calendar from systems of record, with owners
- An observation period run without surprises
- A SOC 2 examination entered with the evidence population already assembled
When this work fits
- SaaS and service companies whose enterprise deals require a SOC 2 report
- Companies with a Type 1 report moving to Type 2
- Organizations holding ISO 27001 and adding SOC 2 for North American buyers
- Teams whose evidence is rebuilt by hand before each examination
05Questions
SOC 2: questions we are asked
A Type 1 report describes the system and evaluates whether controls are suitably designed at a point in time. A Type 2 report also tests whether those controls operated effectively over a period, commonly three to twelve months. Enterprise buyers usually ask for Type 2. A Type 1 can be a sensible first step when a contract deadline arrives before an observation period can be completed.
Security is required in every SOC 2 report. Availability, Confidentiality, Processing Integrity and Privacy are added when customers or the nature of the service call for them. Including a criterion adds controls and evidence, so the selection is made against what your buyers ask for and what the service actually promises.
A licensed CPA firm performs the examination and issues the report under the AICPA attestation standards. Onion Infosec prepares you: scoping, control design, evidence programs and support during the examination. We do not issue reports, and that separation is what gives the report its value.
It is recorded as an exception and described in the report, along with management’s response. Exceptions are not fatal, but they are read by your customers. The readiness program is built to catch lapses early, remediate them and document the fix, so that exceptions are rare and explained.
Not necessarily. Automation helps where evidence can be pulled from identity, cloud, ticketing and code platforms on a schedule, and we design the evidence program around whatever tooling you choose or already own. The platform does not replace the controls, the owners or the judgment of the auditor.
Often alongside
Related services, industries and guides
- ISO 27001 Consulting
- Compliance Readiness Program
- GRC & Compliance
- Third-Party Risk Management
- All cybersecurity services
Industries where this matters most
Guides and products
Working with us
What every engagement rests on.
- Non-disclosure agreements
- Every engagement is governed by an NDA. Details of your environment, findings and deliverables stay within the engagement.
- Least-privilege access
- The minimum access the work requires, tied to named individuals and removed when the work ends.
- Telemetry stays in your tenant
- In security operations, our analysts work inside your SIEM, EDR or cloud console in preference to exporting logs to systems we run.
- End of engagement
- Access is handed back, and your information is returned or deleted as agreed with you.
Onion Information Security Solutions Private Limited · CIN U62099MH2025PTC443498 · Registered office in Mumbai, India
