Overview
More and more, winning enterprise customers means showing a SOC 2 report. We help you build the security, availability, and confidentiality controls the framework expects, and the evidence to back them, on the Microsoft platform you already use.
We get you ready for the audit by implementing the controls, documenting your practices, and standing up the monitoring that keeps you compliant after the report is signed.
How We Work
Readiness assessment
We map your controls against the Trust Services Criteria and define the scope that fits what customers ask for.
Control implementation
We close the gaps, stand up evidence collection, and prepare your policies for the audit period.
Audit support
We work directly with your auditor, keep evidence flowing, and maintain controls between audit cycles.
What's Included
Readiness assessment
A gap analysis against the SOC 2 trust criteria and a plan to close it.
Security controls
Access, change management, and monitoring implemented and enforced.
Policies and procedures
The documented practices auditors expect to review.
Monitoring and logging
Continuous evidence that controls are operating, not just written down.
Vendor and access review
Recurring reviews that keep access and third parties in check.
Audit support
We help you through the examination and the year-round upkeep.
Implementation Options
Three ways to start, depending on how much certainty you want before you commit. Estimates and rates are quoted in your proposal.
T&M Remediation
- The full remediation on time and materials, billed to actual hours as consumed
- A written estimate up front, revisited at every phase gate
- Design and build run in parallel: the blueprint evolves while early phases are already being delivered
- Scope stays flexible, with changes approved through a written change order
- Simpler footprints with a clear picture of their requirements
- Teams comfortable steering scope as the work unfolds
Fixed-Fee Gap Assessment & Roadmap
- The first phase of a full remediation, run as a standalone engagement with its own deliverables (we call it Phase 0)
- Current state documented, future state designed, and the remediation blueprint delivered
- A fixed-fee remediation proposal, priced against confirmed scope
- Deliverables are platform-agnostic, not tied to Microsoft or to us, and detailed enough for any qualified partner to quote a fixed fee
- The fee is credited in full toward the remediation if you proceed with us within three months
- Complex or unclear scope, where guessing is expensive
- Boards and leadership teams that prefer the certainty of a detailed roadmap and fixed-fee scope before implementation kicks off
Fixed-Fee Remediation
- Follows a completed Discovery & Design engagement
- The remediation at a fixed price, quoted against the scope confirmed in discovery and design
- Milestone billing tied to deliverables you can verify
- Change orders only when the scope itself changes
- Budget certainty required before kickoff
- Regulated or board-governed purchases
Support & Training Options
Compliance is a program, and readiness fades without upkeep. Choose how much of the program we carry. The flat-fee program runs on a rolling 90-day commitment; readiness projects are standalone.
T&M readiness project
- Gap assessment against SOC 2, scoped in writing and billed hourly
- Remediation of findings, prioritized by risk
- A roadmap you could execute with any provider
- A first engagement, or a deadline-driven push
- Teams with internal owners who need expert hands
Flat-fee compliance program
- Reduced professional services rates for your remediation
- Continuous monitoring of the technical controls
- Evidence collection that stays current instead of piling up before audits
- Policy reviews and security awareness training
- Support during assessments and customer security questionnaires
- Businesses where SOC 2 is a standing customer or regulator requirement
- Leadership that never wants to scramble before an audit again
Fully managed IT & compliance
Everything in the flat-fee compliance program option, plus managed IT services:
- Our lowest professional services rates for your remediation, as part of a holistic ongoing engagement
- The IT operation underneath the controls, run by the same team
- Helpdesk, patching, backups, and vendor management
- Security monitoring, threat response, and email security
- SLA on system-blocking issues
- Regulated companies without internal IT
- Teams tired of compliance and IT vendors pointing at each other
Who This Is For, and Who It Is Not
A strong fit if
- An enterprise prospect has asked for a SOC 2 report, and the deal is waiting on it.
- You are a software or services company holding customer data in your own environment.
- Your security practices work in day-to-day operation and none of it is written down or evidenced.
- You want Type I first to unblock a deal, with Type II following over a defined observation window.
- You run on Microsoft 365 and Azure, and want the controls built there rather than in a separate compliance tool.
A poor fit if
- You need the report next month. Readiness comes first, and a Type II observation window runs for months after that.
- You expect us to issue the report. The examination is performed by an independent audit firm; we get you ready and stand with you through it.
- Your customers have asked for ISO 27001 specifically. The control work overlaps, and the framework and the auditor are different.
Frequently Asked Questions
All questionsWhat is SOC 2?
SOC 2 is an independent audit of how your company safeguards customer data. The output is a report your customers' security teams accept in place of endless questionnaires. We build the controls and keep the evidence current so the audit confirms rather than surprises.
How is this different from just answering security questionnaires?
The alternative is answering every enterprise customer's 300-question security review by hand, forever. One SOC 2 report replaces most of that, and the controls behind it make you genuinely more secure rather than just better at paperwork.
When do we need a SOC 2 report?
When you sell to bigger customers who hold you to their security standards, especially as a software or services business handling client data. The trigger is usually a deal: a prospect asks for the report you do not have yet. If your customers never ask for it and never will, the audit adds cost without opening any doors; get the underlying security right and add the report when the market asks for it.
Do you run the audit or certification itself?
No. Auditors and assessors have to stay independent, so the same firm cannot build your controls and certify the result. We build the controls, assemble the evidence, and sit beside you during the assessment, so the auditor finds a running system rather than a scramble.
Do you require long-term contracts?
No. Our standard commitment is a rolling 90 days, so we earn your business every quarter. Everything we build lives in your own Microsoft tenant with nothing proprietary in the way, which keeps that promise real: you could hand the keys to any provider tomorrow.
What happens in the first 90 days?
Weeks one and two are access and visibility: admin roles audited, MFA enforced, monitoring on your most critical systems, and a shared password vault. Weeks three to eight set the baseline: licensing rationalized, device management everywhere, backups running and test-restored. By week 13 you have a steady rhythm: a weekly status call, a patch cadence, playbooks you own, and a 90-day review that sets the roadmap.
How does pricing work?
Managed services run at a flat monthly rate per person, which covers their primary device; shared and additional devices are a small add-on. Project work is hourly and quoted in writing before it starts, or converted to a fixed monthly fee when you want budget certainty. Microsoft licensing passes through at list price.
Related Reading
Latest