01Program

SOC 2 compliance and readiness services for Type 1 and Type 2 reports

Readiness for a SOC 2 examination: choosing the Trust Services Criteria in scope, designing controls that map to them, collecting evidence across the observation period and working with the licensed CPA firm that issues the report. The report is theirs to issue; the readiness is our work.

Name
SOC 2 Readiness
Line
01 · Cybersecurity
Type
Outcome program, combines several practices

01The problem

A SOC 2 report is sampled across the whole period, so one gap counts.

SOC 2 is usually triggered by a customer: a security questionnaire, a procurement deadline, a contract clause. The temptation is to treat it as paperwork and move fast. A Type 2 report then exposes the shortcut, because the auditor samples evidence across every month of the observation period, and a control that lapsed in month four is an exception in the report your customer reads.

Readiness done properly is quieter. The controls are the ones a well-run company would operate anyway, the evidence is produced by the systems that already run, and the report describes how the company actually works.

02Scope

What the SOC 2 program covers.

  • Scope and criteria selection

    Which systems, which Trust Services Criteria (Security, plus Availability, Confidentiality, Processing Integrity or Privacy as needed) and which report type, decided against what your customers ask for.

  • Readiness assessment

    Control-by-control review against the criteria, with gaps rated by effort and by how visible they would be in a report.

  • Control design and implementation

    Controls sized to the company, implemented with the teams that will operate them, and written as the control descriptions the auditor will test.

  • Evidence program

    A calendar and an owner for every piece of evidence, with collection automated from identity, cloud, ticketing and code platforms wherever possible.

  • Policies and system description

    The policy set and the system description that the report is built around, written to describe how the company works today.

  • Type 1 and Type 2 examination support

    Auditor selection, evidence requests, walkthroughs and exception handling during the examination, and the bridge letter after it.

  • Vendor and subservice organization management

    Carve-out or inclusive treatment of cloud providers and critical vendors, with the complementary controls documented.

03Approach

How a SOC 2 engagement runs.

The AICPA Trust Services Criteria and the points of focus beneath them. Controls are mapped once across SOC 2, [ISO 27001](/services/cybersecurity/iso-27001) and other frameworks, so a company holding both does not run two programs. See [running ISO 27001 and SOC 2 from one control set](/resources/blog/iso-27001-and-soc-2-one-control-set).

  1. Decide the report

    Type 1 for a point-in-time description of design, Type 2 for operating effectiveness over a period. Most enterprise buyers want Type 2; a Type 1 first is a reasonable step when a deadline is close.

  2. Assess and design

    Measure existing controls against the criteria, then design the smallest control set that satisfies them and reduces real risk.

  3. Implement and automate evidence

    Put controls into operation and connect evidence collection to the systems of record, so the audit does not depend on screenshots.

  4. Run the observation period

    Monitor control operation through the period, catch lapses early, and record remediation so that exceptions are rare and explained.

  5. Support the examination

    Prepare the evidence population, host walkthroughs and manage the auditor’s requests to a schedule.

04Outcomes

What the SOC 2 program is built to achieve.

  • A scoped Trust Services Criteria selection and report type that matches customer demand
  • Controls implemented and described in the auditor’s own terms
  • Evidence collected on a calendar from systems of record, with owners
  • An observation period run without surprises
  • A SOC 2 examination entered with the evidence population already assembled

When this work fits

  • SaaS and service companies whose enterprise deals require a SOC 2 report
  • Companies with a Type 1 report moving to Type 2
  • Organizations holding ISO 27001 and adding SOC 2 for North American buyers
  • Teams whose evidence is rebuilt by hand before each examination

05Questions

SOC 2: questions we are asked

A Type 1 report describes the system and evaluates whether controls are suitably designed at a point in time. A Type 2 report also tests whether those controls operated effectively over a period, commonly three to twelve months. Enterprise buyers usually ask for Type 2. A Type 1 can be a sensible first step when a contract deadline arrives before an observation period can be completed.

Security is required in every SOC 2 report. Availability, Confidentiality, Processing Integrity and Privacy are added when customers or the nature of the service call for them. Including a criterion adds controls and evidence, so the selection is made against what your buyers ask for and what the service actually promises.

A licensed CPA firm performs the examination and issues the report under the AICPA attestation standards. Onion Infosec prepares you: scoping, control design, evidence programs and support during the examination. We do not issue reports, and that separation is what gives the report its value.

It is recorded as an exception and described in the report, along with management’s response. Exceptions are not fatal, but they are read by your customers. The readiness program is built to catch lapses early, remediate them and document the fix, so that exceptions are rare and explained.

Not necessarily. Automation helps where evidence can be pulled from identity, cloud, ticketing and code platforms on a schedule, and we design the evidence program around whatever tooling you choose or already own. The platform does not replace the controls, the owners or the judgment of the auditor.

Working with us

What every engagement rests on.

Non-disclosure agreements
Every engagement is governed by an NDA. Details of your environment, findings and deliverables stay within the engagement.
Least-privilege access
The minimum access the work requires, tied to named individuals and removed when the work ends.
Telemetry stays in your tenant
In security operations, our analysts work inside your SIEM, EDR or cloud console in preference to exporting logs to systems we run.
End of engagement
Access is handed back, and your information is returned or deleted as agreed with you.

Onion Information Security Solutions Private Limited · CIN U62099MH2025PTC443498 · Registered office in Mumbai, India