Free ISO 27001 Assessment

SOC 2

A US prospect wants SOC 2 by renewal. Here is how it gets there.

Trust Services Criteria mapped to your controls, policies written, evidence collected and gaps fixed, for teams of 10 to 300, in the platform that keeps collecting evidence through the observation period.

Trust Services CriteriaExample, Security and Availability

36 criteria, each with a control, an owner and evidence

CC1 to CC5
Control environment, communication, risk, monitoring, control activities
17 / 17
CC6 to CC9
Access, operations, change, risk mitigation
16 / 16
A1 Availability
Capacity, recovery, backups
3 / 3
Evidence collected automatically
From AWS, GitHub and the identity provider
68%
Ready for the CPA firm, week 10Export · CSV, PDF

Who this is for

Teams whose US customers ask for the report before they sign.

  • A fit

    • A SaaS company of 10 to 300 people whose US enterprise prospect requires a SOC 2 Type II report as a condition of the contract or the renewal.
    • A startup after a funding round whose investors or customers expect a SOC 2 report within the year.
    • A team on AWS, Google Cloud or Azure with GitHub and an identity provider, where most evidence can be collected automatically.
  • Also a fit

    • A company that already holds ISO 27001 and wants to reuse that work for US customers; readiness is then mostly mapping and the system description.
    • A company whose first attempt produced a policy folder and no evidence.
    • A team that wants SOC 2 and ISO 27001 from one control set.
  • Not a fit

    • Organisations that need the SOC 2 examination itself. We prepare you; a licensed CPA firm that you engage performs the examination and issues the report.
    • Companies with owned data centres. The physical and environmental criteria need an on-site partner, which we would name in the quote.
    • Teams that want the report without operating the controls. A Type II covers operation over months, and the CPA firm tests it.

What you walk away with

Controls the CPA firm can test, and your team can keep running.

Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.

SOC 2 readiness

11 deliverables, 8 to 10 weeks
  • Scope and system description

    Services, infrastructure, people, data, as the report requires

    • DOCX
    • PDF
  • Trust Services Criteria control matrix

    Criterion, control, owner, frequency, evidence

    • CSV
    • PDF
  • Policy set covering the Common Criteria

    Access, change, incident, vendor, acceptable use, business continuity, and the rest your categories need

    • DOCX
    • PDF
  • Risk assessment

    Risks, owners, treatment, residual rating

    • CSV
    • PDF
  • Vendor inventory with risk ratings

    Sub-processors, reports held, review date

    • CSV
  • Procedures for access reviews, change management, incident response and vendor review

    Written for how your team actually works

    • Procedure
  • Gap remediation log

    Each gap, the fix, the owner, the date closed

    • CSV
  • Evidence pack mapped to each criterion

    Collected from connected cloud, code and identity systems; uploaded where not

    • Platform
  • Observation period plan

    What is sampled, how often, by whom, for the Type II window

    • DOCX
  • CPA firm shortlist and examination plan

    Type I or Type II, categories, dates around your deadline

    • DOCX
  • Recorded hand-over and readiness sign-off

    With whoever owns the controls afterwards

    • Video
    • PDF

How it works

Ten weeks to hand-over. Then the observation period, then the report.

The examination is yours to contract with a licensed CPA firm; we book it around your date and join the calls.

  • GRCTrail
  • Hand-over
  • Without us
  1. Week 0

    Scoping call

    Type I or Type II, categories, cloud footprint, what exists. Written fixed price within 3 business days.

  2. Weeks 1 to 2

    Assessment

    Gap analysis against the criteria you need. Categories agreed. Implementation price confirmed.

  3. Weeks 3 to 9

    Implementation

    Control matrix, policies, risk assessment, vendor inventory, evidence collection, gap remediation. Two review sittings with your team.

  4. Week 10

    Hand-over

    Observation period plan, CPA firm booked, recorded hand-over, readiness sign-off.

  5. 3 to 12 months

    Observation period

    Controls operate and evidence collects. Type I can be issued at the start; Type II at the end. We join the CPA firm's calls and fix findings against our work.

  6. Every year

    Next report

    A new observation period, the same controls. Evidence keeps collecting in GRCTrail or in your export.

How we price

What moves the price

Three things we ask about on the call.

  • Which categories.

    Security alone is the base case; Availability, Confidentiality, Processing Integrity and Privacy each add criteria to evidence.

  • How much of the stack is cloud.

    Controls on AWS, GitHub and the identity provider are evidenced automatically; owned hardware is not.

  • What already exists.

    An ISO 27001 certificate or a working security programme shortens the work considerably.

Never in our price, named in the quote so you can budget

  • The SOC 2 examination itself, performed by a licensed CPA firm that you engage directly and that issues the report
  • Penetration testing
  • Formal legal opinions
  • Acting as your security officer during the observation period

Questions before the call

Who issues the SOC 2 report?

A licensed CPA firm, after its examination. We prepare your controls and evidence, help you choose a firm and book the dates around your deadline. We do not perform examinations or issue reports, and the firm must not have designed the controls it tests.

Type I or Type II: which one do we need?

Ask the customer. Most enterprise buyers want a Type II. A Type I is faster and is often accepted as a first step while the Type II observation period of 3 to 12 months runs.

Can we reuse ISO 27001 work for SOC 2?

Yes. Most ISO 27001 Annex A controls map to the Common Criteria. If you hold ISO 27001, readiness is mostly mapping, the system description and evidence formatting.

Does GRCTrail collect SOC 2 evidence automatically?

Where an integration exists, yes: cloud, code and identity systems. Evidence that lives elsewhere is uploaded and tracked in the same library, so the CPA firm sees one evidence set.

What if the CPA firm finds an exception?

If it is against work we delivered, we fix it at no extra charge; that is stated in the quote. If it concerns something outside the agreed scope, we tell you what it would take and you decide.

Tell us your date, which report you need and what exists today.

You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.