SOC 2 Compliance Readiness
Scope the right Trust Services Criteria, close the gaps, and arrive at your CPA firm's examination with documentation and evidence already in order. We prepare you for a successful SOC 2; the licensed CPA firm issues the opinion.
Overview
SOC 2 readiness is the preparation work that determines whether your CPA firm's examination goes smoothly or surfaces costly surprises. SOC 2 compliance covers controls relevant to the Trust Services Criteria (TSC): Security is always in scope, and Availability, Processing Integrity, Confidentiality, and Privacy are added where they apply to your service. System and organization controls are the subject of the examination, and the readiness assessment is how you find out what still needs work before the auditor arrives.
We scope the criteria with you, run a gap analysis to identify gaps in your current control environment, design and document what needs to change, and build the evidence framework your auditor will rely on. Preparing for a SOC 2 involves remediating security controls, authoring policies and procedures, and structuring evidence collection so the audit process is predictable rather than stressful. We streamline that process by coordinating directly with your CPA firm throughout the engagement.
The audit opinion itself is issued by a licensed CPA firm that performs the examination. Our role is to get you ready for the actual SOC 2 examination and to make sure the evidence is there when the auditor asks for it. Risk management and vendor management arrangements are reviewed as part of the readiness process, since auditors will examine both.
What’s included
- Trust Services Criteria scoping (Security plus applicable categories)
- Gap analysis against the selected criteria
- Control design and remediation guidance to remediate identified gaps
- Policies and procedures documentation
- Evidence collection framework for Type I or Type II
- Audit preparation and CPA-firm coordination
- SOC 2 assessment readiness confirmation before examination
- Risk assessment aligned to SOC 2 criteria
How we work
-
01
Scope
We confirm which Trust Services Criteria apply to your service and define the system boundary. Scoping decisions made here affect everything downstream in the SOC 2 compliance journey.
-
02
Gap analysis
We assess your current security controls against each criterion and identify what needs to be designed, improved, or documented before the SOC 2 examination. This is the end of the readiness assessment phase where surprises should appear, not during the actual SOC audit.
-
03
Build and document
We help design the controls, author the policies and procedures, and set up the evidence collection process, so nothing is reconstructed after the fact. Controls supporting the TSC criteria are documented in a format auditors expect.
-
04
Internal audit and risk assessment
We run an internal audit against the selected Trust Services Criteria and a risk assessment to confirm the controls are operating as intended and to surface any gaps before your CPA firm's examination.
-
05
Audit preparation
We prepare you for the examination, run readiness checks, and coordinate with your CPA firm so the audit window is productive. Audit readiness is confirmed before the examination begins.
What you get
- SOC 2 scope and Trust Services Criteria selection
- Gap analysis and remediation plan
- Policy and control documentation
- Evidence framework and audit-readiness confirmation
- Risk assessment report
- Internal audit report
The opinion comes from a licensed CPA firm
A SOC 2 report is an opinion issued by a licensed CPA firm that conducts the examination under AICPA standards. Onyx Security Labs prepares you, authors the documentation, and coordinates the engagement. We do not issue the SOC 2 opinion ourselves.
Frequently asked questions
What is the difference between SOC 2 Type I and Type II?
A Type 1 report assesses whether your controls are suitably designed at a specific point in time. A Type 2 report assesses whether those controls operated effectively over a defined period, typically between three and twelve months. Most enterprise customers and procurement teams require a Type 2 report. SOC 2 Type 2 reports are also what most compliance frameworks and buyer questionnaires reference. We prepare you for either.
How long does SOC 2 readiness take?
It depends on your starting maturity and the criteria in scope. We give a realistic timeline after the gap analysis. For companies starting from low maturity, the readiness phase is often three to six months before a Type 1 examination, followed by an observation period for Type 2 reports. The SOC 2 project timeline is heavily influenced by how quickly your team can remediate and collect evidence.
Do we need a SOC 2 if we are not a US company?
SOC 2 is a US-origin framework under AICPA standards, but many enterprise buyers globally, particularly in technology and financial services, now require it regardless of where the vendor is headquartered. If your sales process is being blocked by it, the answer is usually yes. The SOC 2 compliance process and the SOC 2 examination work the same way regardless of your jurisdiction.
Credentials held by our team










How ready is your security and compliance?
Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.
Ready to simplify security and compliance?
Pick a service, book a scope call, or ask a question. Whatever order works.