SOC 2
A US prospect wants SOC 2 by renewal. Here is how it gets there.
Trust Services Criteria mapped to your controls, policies written, evidence collected and gaps fixed, for teams of 10 to 300, in the platform that keeps collecting evidence through the observation period.
36 criteria, each with a control, an owner and evidence
- CC1 to CC5
- Control environment, communication, risk, monitoring, control activities
- 17 / 17
- CC6 to CC9
- Access, operations, change, risk mitigation
- 16 / 16
- A1 Availability
- Capacity, recovery, backups
- 3 / 3
- Evidence collected automatically
- From AWS, GitHub and the identity provider
- 68%
Who this is for
Teams whose US customers ask for the report before they sign.
A fit
- A SaaS company of 10 to 300 people whose US enterprise prospect requires a SOC 2 Type II report as a condition of the contract or the renewal.
- A startup after a funding round whose investors or customers expect a SOC 2 report within the year.
- A team on AWS, Google Cloud or Azure with GitHub and an identity provider, where most evidence can be collected automatically.
Also a fit
- A company that already holds ISO 27001 and wants to reuse that work for US customers; readiness is then mostly mapping and the system description.
- A company whose first attempt produced a policy folder and no evidence.
- A team that wants SOC 2 and ISO 27001 from one control set.
Not a fit
- Organisations that need the SOC 2 examination itself. We prepare you; a licensed CPA firm that you engage performs the examination and issues the report.
- Companies with owned data centres. The physical and environmental criteria need an on-site partner, which we would name in the quote.
- Teams that want the report without operating the controls. A Type II covers operation over months, and the CPA firm tests it.
What you walk away with
Controls the CPA firm can test, and your team can keep running.
Every deliverable is editable and yours, inside the platform or exported as DOCX, CSV and PDF.
SOC 2 readiness
11 deliverables, 8 to 10 weeksScope and system description
Services, infrastructure, people, data, as the report requires
- DOCX
Trust Services Criteria control matrix
Criterion, control, owner, frequency, evidence
- CSV
Policy set covering the Common Criteria
Access, change, incident, vendor, acceptable use, business continuity, and the rest your categories need
- DOCX
Risk assessment
Risks, owners, treatment, residual rating
- CSV
Vendor inventory with risk ratings
Sub-processors, reports held, review date
- CSV
Procedures for access reviews, change management, incident response and vendor review
Written for how your team actually works
- Procedure
Gap remediation log
Each gap, the fix, the owner, the date closed
- CSV
Evidence pack mapped to each criterion
Collected from connected cloud, code and identity systems; uploaded where not
- Platform
Observation period plan
What is sampled, how often, by whom, for the Type II window
- DOCX
CPA firm shortlist and examination plan
Type I or Type II, categories, dates around your deadline
- DOCX
Recorded hand-over and readiness sign-off
With whoever owns the controls afterwards
- Video
How it works
Ten weeks to hand-over. Then the observation period, then the report.
The examination is yours to contract with a licensed CPA firm; we book it around your date and join the calls.
- GRCTrail
- Hand-over
- Without us
Week 0
Scoping call
Type I or Type II, categories, cloud footprint, what exists. Written fixed price within 3 business days.
Weeks 1 to 2
Assessment
Gap analysis against the criteria you need. Categories agreed. Implementation price confirmed.
Weeks 3 to 9
Implementation
Control matrix, policies, risk assessment, vendor inventory, evidence collection, gap remediation. Two review sittings with your team.
Week 10
Hand-over
Observation period plan, CPA firm booked, recorded hand-over, readiness sign-off.
3 to 12 months
Observation period
Controls operate and evidence collects. Type I can be issued at the start; Type II at the end. We join the CPA firm's calls and fix findings against our work.
Every year
Next report
A new observation period, the same controls. Evidence keeps collecting in GRCTrail or in your export.
How we price
What moves the price
Three things we ask about on the call.
Which categories.
Security alone is the base case; Availability, Confidentiality, Processing Integrity and Privacy each add criteria to evidence.
How much of the stack is cloud.
Controls on AWS, GitHub and the identity provider are evidenced automatically; owned hardware is not.
What already exists.
An ISO 27001 certificate or a working security programme shortens the work considerably.
Never in our price, named in the quote so you can budget
- The SOC 2 examination itself, performed by a licensed CPA firm that you engage directly and that issues the report
- Penetration testing
- Formal legal opinions
- Acting as your security officer during the observation period
Questions before the call
Who issues the SOC 2 report?
A licensed CPA firm, after its examination. We prepare your controls and evidence, help you choose a firm and book the dates around your deadline. We do not perform examinations or issue reports, and the firm must not have designed the controls it tests.
Type I or Type II: which one do we need?
Ask the customer. Most enterprise buyers want a Type II. A Type I is faster and is often accepted as a first step while the Type II observation period of 3 to 12 months runs.
Can we reuse ISO 27001 work for SOC 2?
Yes. Most ISO 27001 Annex A controls map to the Common Criteria. If you hold ISO 27001, readiness is mostly mapping, the system description and evidence formatting.
Does GRCTrail collect SOC 2 evidence automatically?
Where an integration exists, yes: cloud, code and identity systems. Evidence that lives elsewhere is uploaded and tracked in the same library, so the CPA firm sees one evidence set.
What if the CPA firm finds an exception?
If it is against work we delivered, we fix it at no extra charge; that is stated in the quote. If it concerns something outside the agreed scope, we tell you what it would take and you decide.
Related
Last reviewed: October 2026
Tell us your date, which report you need and what exists today.
You leave the call with a scope and an indicative range. The written fixed price follows within 3 business days.