From failing controls to a clean report
SOC 2 and ISO 27001 usually show up the same way: a big customer asks for one and gives you a deadline. We run the whole thing: gap assessment, policy writing, control implementation, evidence collection, auditor coordination. And we fix the failing controls ourselves instead of handing you a list.
Somebody asked for your SOC 2 report and you don't have one. Now there's a deal on the line and a deadline that arrived faster than anyone expected. This is how most companies get here, not because they planned a compliance initiative, but because a customer's procurement team made it non-negotiable.
We run the gap assessment against the Trust Services Criteria or ISO 27001 Annex A, tell you exactly what's missing, and then build it: the policies, the access controls, the vendor management process. When a control fails during evidence collection, we don't log it and move on. We fix it. A config change, a policy rewrite, a conversation with your engineering team about why MFA isn't enforced on that one legacy service.
We stay through the audit: picking the right firm, managing fieldwork, keeping evidence requests from piling up in someone's inbox. And once the report is signed, we keep the program running so next year is a renewal, not a repeat of this year's scramble.
What's included
Gap assessment
An honest read of where you stand against Trust Services Criteria or ISO 27001 Annex A, ranked by risk and effort to close.
Control design & implementation
Controls sized to your actual stack, not policy templates pulled off the internet and renamed.
Policy library
A full set of information security policies your engineers will actually read, because they're written for your environment.
Evidence collection & remediation
We gather the evidence and fix what's failing: access reviews, encryption gaps, vendor contracts, whatever's blocking a clean report.
Auditor selection & liaison
We help pick the audit firm and run point on the relationship through fieldwork and report delivery.
Post-certification maintenance
Controls stay monitored and evidence stays current, so Type II and next year's renewal aren't a fire drill.
Frequently asked questions
How long does this actually take?
Most companies reach SOC 2 Type I or ISO 27001 audit readiness in six to twelve weeks, depending on how much of your access control and vendor management is already in shape. Type II is different. It needs an observation period, usually three to six months, where the auditor confirms controls worked over time, not just that they existed on the day of the assessment.
Can we go after SOC 2 and ISO 27001 at the same time?
Usually, yes. Access control, vendor management, and incident response overlap heavily between the two, and we design the program to satisfy both without duplicating the work. If your timeline or customer base points toward doing them in sequence instead, we'll say so. Sequencing isn't a failure, it's sometimes just the faster path.
Do you actually fix control failures, or just report them?
We fix them. A failing control in your GRC platform isn't a line item we hand back to you. It's a policy update, a configuration change, or a conversation with your engineering team about the underlying issue, and we drive it to closed.
Do you push us toward a specific platform?
We'll tell you what fits. See our GRC Platform Management service for that conversation. This service covers the certification lifecycle end to end, platform included.
Ideal for
- SaaS companies hit with a SOC 2 or ISO 27001 requirement from an enterprise customer
- Startups pursuing certification ahead of a sales cycle or a renewal deadline
- Teams that started the process, stalled at evidence collection, and need it finished
- Companies pursuing both frameworks who don't want to build two separate programs
Related services
Ready to talk through SOC 2 & ISO 27001?
The audit's in six weeks. The questionnaire's due Friday. Let's talk Tuesday. Book a free consultation and we'll tell you straight what it takes to get your program built, certified, and operating.