Home All services
Start a project → Call Now

SOC 2 compliance readiness

Get the SOC 2 report your customer asked for — with an honest date.

We prepare the scope, fixes, system description and evidence for your SOC 2 examination, which an independent CPA firm carries out. Before the engagement starts, we tell you which report your date allows, because nobody can shorten the period the auditor must observe.

  • Type 1 or Type 2, chosen by your date
  • An independent CPA firm signs, not us
  • We reply within one working day.
  • TSP section 100
  • DC section 200
  • AT-C 105 and 205
  • 33 common criteria
Illustration: an hourglass with blue sand half run, five floor tiles with one lit and a report folder on a stand, joined by a line of light, standing for an observation period that ends in a report

In brief

What it is
SOC 2 readiness: we prepare your controls, description and evidence for an independent auditor's Type 1 or Type 2 examination.
Why it matters
Buyers ask for SOC 2 in contracts and security questionnaires. A Type 1 covers one date; a Type 2 covers a period your controls already ran, the observation window. So your start date sets your report date.
What you get
An honest date, ranked gaps with owners, the documents the auditor reads, an evidence plan and help through the audit.

What you get

The documents an auditor reads, and whose name goes on each.

The finished report comes in numbered sections. Only a licensed CPA firm may issue the auditor's opinion, usually Section I. SecWiz doesn't sign it and can't.

Control matrix. We produce it.

Every control mapped to its criteria: the auditor's starting point, and later the spine of Section IV, the test results.

System description. We draft it, you own it.

Section III of the report, and the part clients underestimate most. Written like marketing copy, it can get the opinion qualified, meaning it carries a formal reservation, for reasons unrelated to your security.

Customer and provider schedules. We produce them.

What your customers must do for your controls to work (CUECs), and what you rely on a subservice organization, such as your cloud provider, to do (CSOCs).

Evidence collection plan. We produce it.

For each control: which records get sampled and how, which system holds them, who owns them and where they are kept. Built before the window opens.

Management's written assertion. You sign it.

Usually Section II. We review your draft; we don't write it, and neither does the auditor.

Bridge letter template. You sign it.

Your statement covering the gap between period end and a buyer's request date. No auditor opinion, no testing, about three months of credibility. A stopgap, not coverage.

The description criteria, DC1 to DC9

The description is written to DC1 through DC9 (DC section 200). DC4 wants identified system incidents that resulted from control failures; DC8, the applicable criteria that aren't relevant, and why; DC9, the significant changes during the period.

The CUEC schedule (complementary user entity controls) answers DC6; the CSOC schedule (complementary subservice organization controls) answers DC7. Carving out your cloud provider excludes their controls from the opinion. It does not move CC9.2 off you.

Time, not rigor

The observation window is the product, and nobody can shorten it.

A Type 1 is an opinion as of one date. A Type 2 adds what buyers actually want: whether your controls operated throughout a stated period, the observation window.

We won't quote a Type 2 in six weeks: that means a Type 1, or a window so short your buyer will ask for a longer one.

Why a six-week Type 2 isn't real

  • Evidence can't be backdated. The auditor samples from system-generated records with timestamps. An access review nobody performed in March is still unperformed in September.
  • A new tool can't repair the past. No compliance platform onboarded in month five fixes months one to four.

The decision in front of you

Type 1 or Type 2: what the extra months buy.

Same controls, same criteria (TSP section 100), and the longer report isn't stricter. What changes is time. A buyer who writes "Type II" means the Type 2.

What differsType 1Type 2
Subject matterThe description, and suitability of designThe description, suitability of design, and whether controls operated effectively
CoverageAs of a single dateThroughout a stated period
Section IVAbsent. No tests, no resultsEvery test the auditor ran and every exception found
What shortens itRemediation speed, and nothing elseNothing. The period runs in real time
Typical elapsed time from a standing startThree to four monthsEight to nine months for a three-month window, sixteen to seventeen for twelve
What a US enterprise buyer does with itSometimes accepts it as an interim, with a date for the Type 2Reads Section IV
Which trust services categories to elect

Security is in every report and carries 33 common criteria. Availability adds three, Confidentiality two, Processing Integrity five and Privacy eighteen. Most first reports are Security only, or Security with Availability and Confidentiality.

Electing Privacy because it sounds responsible drags in consent, access-request and disposal work that is a project of its own. Our relevance memo says why each declined category was declined, because DC8 will ask.

Where remediation effort lands: CC6 and CC8.1

CC6 is where gap work concentrates: eight criteria covering identity and credentials, provisioning and deprovisioning, physical access, disposal, encryption in transmission, external access points and malicious software.

Two things set remediation length: whether single sign-on (SSO) with enforced multi-factor authentication (MFA) and central logging already exist, and whether every production change moves through an approved, ticketed pull request reviewed by someone other than its author. Retrofitting CC8.1 evidence into a team that pushes to main is the most reliable schedule killer we see.

A calendar, not a methodology

Where the months go when you start from scratch.

  1. Weeks 1 to 3: scope

    Security is always in. We help you choose among Availability, Confidentiality, Processing Integrity and Privacy, and record why you declined the rest.

  2. Weeks 3 to 6: gap work

    Each gap is rated and given an owner. We check gaps in your settings through a cloud and identity posture assessment.

  3. Months 1 to 3: remediation

    Most of the time goes on access, logging and change control.

  4. Month 4, day one: the window opens

    Controls must be running before the period starts, not settling in during it. No fee negotiation moves this.

  5. Months 4 to 7, or 4 to 15: the period runs

    Access reviews happen on their cadence and change tickets accumulate. Over twelve months, quarterly tasks happen four times.

  6. Four to eight weeks after the period ends: fieldwork and the report

    Walkthroughs, sampling, exceptions discussed, report dated.

  7. About eleven months after the period ends: the next window should be open

    The report doesn't formally expire, but a period end older than about twelve months reads as stale. Year two costs less, because the evidence machinery already runs (see compliance as a service).

Independence and limits

We do the readiness work, then we get out of the way.

The service auditor must be independent of the controls it examines, so a firm that designed and implemented them can't give the opinion.

Providers advertising "SOC 2 certification in India" mostly run readiness in-house and subcontract the examination to a US CPA firm, which is legitimate when stated openly.

What a SOC 2 doesn't reach

No US statute or regulator requires one; buyers do. In India it has no legal force. It doesn't satisfy the Digital Personal Data Protection Act 2023 or the DPDP Rules, whose duties start on their own calendar. Nor does it answer CERT-In's six-hour incident reporting direction. It isn't PCI DSS or FedRAMP, and doesn't create GDPR compliance. It is a commercial credential bought to win contracts.

What we won't do

  • Sell you a SOC 2 certificate. No such document exists.
  • Build one control per point of focus. TSP section 100 doesn't require assessing whether each one is addressed, and a checklist only inflates our fee and your audit work.
  • Elect categories for show, such as Processing Integrity for a product that doesn't process transactions, or Privacy in year one.
  • Take the readiness work and the audit on one engagement.
  • Tell you to start at all if no customer has asked and none is likely to.

What SecWiz is not. We are not a CPA firm, and we carry no ISO 27001 certificate of our own.

FAQ

Questions to settle before you commit to a date.

For other frameworks, see GRC and compliance.

Only if the observation window has already closed. A Type 2 opinion covers whether controls operated throughout a stated period, so the period has to have happened first. Starting today with nothing running, the honest answers are a Type 1 in roughly three to four months, or a Type 2 over a three-month window in about eight to nine.

No, and the phrasing matters more than people expect. There's no SOC 2 certificate, no accreditation body and no register. A licensed CPA firm performs an attestation examination under AT-C sections 105 and 205, management provides a written assertion, and the firm issues an opinion that may be unmodified, qualified, adverse or a disclaimer. Say that you have a SOC 2 Type 2 report covering a period. A vendor-risk analyst who sees "SOC 2 certified" on a website usually concludes the company has never been through one, then reads everything else on the page more skeptically.

Usually not. A Type 1 is as of a single date, it doesn't start the Type 2 clock, and it doesn't count as coverage, so running one first tends to lengthen the total timeline and leave a visible gap between the two report dates. It earns its cost in one situation: a buyer has said in writing that they'll accept it as an interim while the Type 2 window runs. If nobody has said that, put the money into remediation and open the window sooner.

Three months is the convention for a first report, twelve is what a mature vendor-risk team prefers, and the standards themselves set no minimum at all, which surprises most people. Your buyer decides this, not the AICPA. If the contract clause says "current SOC 2 Type 2", ask their vendor-risk function what they actually accept before you commit, because a three-month first report followed by a twelve-month second is a normal path and cheaper than guessing wrong once.

Yes, materially, and almost entirely in remediation. The risk assessment, policy suite and management review evidence largely transfer, so that phase often runs at about half length. What doesn't transfer is the shape of the deliverable. ISO 27001 gives a buyer a certificate from an accredited certification body plus a Statement of Applicability against the 93 Annex A controls. SOC 2 gives them a restricted-use report whose Section IV lists every test the auditor ran and every exception found. For clients selling into India, the EU or the Gulf, building the ISMS first and running SOC 2 on top of it is often the cheaper order.

An independent licensed CPA firm signs it. SecWiz cannot and does not. We're a security and compliance consultancy based in India, we're not a CPA firm, and we're not ISO 27001 certified ourselves either. There's a second reason beyond the license: the service auditor must be independent of the controls being examined, which disqualifies any firm that designed and implemented them. We do readiness, remediation, evidence operations and audit management, and we help you select and manage the firm that does the rest, including checking it's enrolled in AICPA peer review.

The criteria aren't. Those in TSP section 100 were issued in 2017 and haven't been altered; the 2022 update revised only the points of focus, saying in bold that it doesn't alter the criteria. What's moving is the plumbing underneath. The Auditing Standards Board issued an exposure draft on 26 February 2026 proposing revisions to AT-C 105, 205 and 210. Comments closed on 30 June 2026 with 23 letters received, and the proposed effective date is 15 June 2029. Nothing is final, and nothing in it changes what you have to build this year.

No. A SOC 2 report is restricted to management, user entities and specified parties who understand the system, which is why it goes out under NDA. What you can publish is a SOC 3: the same examination reissued as a general-use summary, without the Section III description detail and without the Section IV test results. It's still a report and still not a certificate. Most companies also want a trust page explaining how a buyer requests the SOC 2 itself, which we draft as part of the customer-facing pack.

Let's talk

Tell us the date your buyer gave you.

Send the clause or questionnaire that started this, and the date a report must exist by. We'll tell you which report is reachable, which categories to elect and what must run before the window opens. We reply within one working day.