AICPA Trust Services Criteria

SOC 2 readiness for SaaS and service organisations selling into regulated buyers

Pick the right Trust Services Criteria scope, build the controls, and get audit-ready Type I or Type II without overengineering — defensibly, on a fixed timeline.

Book a 30-min call
ISO 27001:2022 certified
Swiss-precision methodology
EU + Switzerland advisory experience

What you get in 90 days

Concrete deliverables, on a fixed timeline, with named outcomes per phase.

30 days

TSC scoping, gap assessment, auditor selection

Trust Services Criteria scope memo, control gap assessment, and a shortlisted CPA firm with engagement letter ready for signature.

60 days

Control implementation and evidence baseline

Documented control library aligned to selected TSC, ownership matrix, and an evidence-collection process running ahead of the audit period.

90 days

Type I attestation prep or Type II observation start

For Type I — readiness review and pre-audit walk-through. For Type II — confirmed observation period start with monitoring cadence in place.

Implementation Approach

Our SOC 2 Implementation Method

We use a proven methodology that integrates SOC 2 controls into your existing operations while preparing you for successful audit outcomes.

1

Readiness Assessment

2-3 weeks

Comprehensive evaluation of current security posture against SOC 2 Trust Services Criteria to identify gaps and prioritize implementation efforts.

Timeline: Weeks 1-3
2

Control Implementation

8-12 weeks

Design and implementation of SOC 2 controls across security, availability, processing integrity, confidentiality, and privacy criteria.

Timeline: Weeks 4-16
3

Evidence Collection

6-9 months

Systematic collection and documentation of evidence demonstrating control effectiveness over the required observation period.

Timeline: Months 4-12
4

Audit Readiness

4-6 weeks

Final preparation for SOC 2 audit including evidence review, audit support, and remediation of any identified issues.

Timeline: Months 12-13

Integrated Control Design

Our approach embeds SOC 2 controls into your existing processes, ensuring compliance becomes part of your operational excellence rather than an additional burden.

Frequently asked questions

The questions compliance leads ask us most about SOC 2.

Type I attests to the design of your controls at a point in time. Type II attests that the controls operated effectively over a period — typically 6 to 12 months. Most enterprise buyers require Type II eventually, but starting with Type I to validate the design before opening a Type II observation window is often the lower-risk path.

Ready to start? Book a 30-min scoping call.

We diagnose where you stand against the standard, scope the right engagement, and send a written brief within 48 hours.

Diagnose your gap against the standard in 30 minLive walkthrough on your call
Receive a written engagement brief in 48 hoursScope, timeline, fixed deliverables
Decide on terms before any work startsNo commitment until you sign