Skip to content

SOC 2

SOC 2 readiness that builds the security controls and evidence your customers and partners increasingly require.

Overview

More and more, winning enterprise customers means showing a SOC 2 report. We help you build the security, availability, and confidentiality controls the framework expects, and the evidence to back them, on the Microsoft platform you already use.

We get you ready for the audit by implementing the controls, documenting your practices, and standing up the monitoring that keeps you compliant after the report is signed.

How We Work

1

Readiness assessment

We map your controls against the Trust Services Criteria and define the scope that fits what customers ask for.

2

Control implementation

We close the gaps, stand up evidence collection, and prepare your policies for the audit period.

3

Audit support

We work directly with your auditor, keep evidence flowing, and maintain controls between audit cycles.

What's Included

Readiness assessment

A gap analysis against the SOC 2 trust criteria and a plan to close it.

Security controls

Access, change management, and monitoring implemented and enforced.

Policies and procedures

The documented practices auditors expect to review.

Monitoring and logging

Continuous evidence that controls are operating, not just written down.

Vendor and access review

Recurring reviews that keep access and third parties in check.

Audit support

We help you through the examination and the year-round upkeep.

Implementation Options

Three ways to start, depending on how much certainty you want before you commit. Estimates and rates are quoted in your proposal.

T&M Remediation

Details
  • The full remediation on time and materials, billed to actual hours as consumed
  • A written estimate up front, revisited at every phase gate
  • Design and build run in parallel: the blueprint evolves while early phases are already being delivered
  • Scope stays flexible, with changes approved through a written change order
Best fit for
  • Simpler footprints with a clear picture of their requirements
  • Teams comfortable steering scope as the work unfolds

Fixed-Fee Gap Assessment & Roadmap

Details
  • The first phase of a full remediation, run as a standalone engagement with its own deliverables (we call it Phase 0)
  • Current state documented, future state designed, and the remediation blueprint delivered
  • A fixed-fee remediation proposal, priced against confirmed scope
  • Deliverables are platform-agnostic, not tied to Microsoft or to us, and detailed enough for any qualified partner to quote a fixed fee
  • The fee is credited in full toward the remediation if you proceed with us within three months
Best fit for
  • Complex or unclear scope, where guessing is expensive
  • Boards and leadership teams that prefer the certainty of a detailed roadmap and fixed-fee scope before implementation kicks off
Learn more about Phase 0

Fixed-Fee Remediation

Details
  • Follows a completed Discovery & Design engagement
  • The remediation at a fixed price, quoted against the scope confirmed in discovery and design
  • Milestone billing tied to deliverables you can verify
  • Change orders only when the scope itself changes
Best fit for
  • Budget certainty required before kickoff
  • Regulated or board-governed purchases

Support & Training Options

Compliance is a program, and readiness fades without upkeep. Choose how much of the program we carry. The flat-fee program runs on a rolling 90-day commitment; readiness projects are standalone.

T&M readiness project

Details
  • Gap assessment against SOC 2, scoped in writing and billed hourly
  • Remediation of findings, prioritized by risk
  • A roadmap you could execute with any provider
Best fit for
  • A first engagement, or a deadline-driven push
  • Teams with internal owners who need expert hands

Flat-fee compliance program

Details
  • Reduced professional services rates for your remediation
  • Continuous monitoring of the technical controls
  • Evidence collection that stays current instead of piling up before audits
  • Policy reviews and security awareness training
  • Support during assessments and customer security questionnaires
Best fit for
  • Businesses where SOC 2 is a standing customer or regulator requirement
  • Leadership that never wants to scramble before an audit again

Fully managed IT & compliance

Everything in the flat-fee compliance program option, plus managed IT services:

  • Our lowest professional services rates for your remediation, as part of a holistic ongoing engagement
  • The IT operation underneath the controls, run by the same team
  • Helpdesk, patching, backups, and vendor management
  • Security monitoring, threat response, and email security
  • SLA on system-blocking issues
Best fit for
  • Regulated companies without internal IT
  • Teams tired of compliance and IT vendors pointing at each other

Who This Is For, and Who It Is Not

A strong fit if

  • An enterprise prospect has asked for a SOC 2 report, and the deal is waiting on it.
  • You are a software or services company holding customer data in your own environment.
  • Your security practices work in day-to-day operation and none of it is written down or evidenced.
  • You want Type I first to unblock a deal, with Type II following over a defined observation window.
  • You run on Microsoft 365 and Azure, and want the controls built there rather than in a separate compliance tool.

A poor fit if

  • You need the report next month. Readiness comes first, and a Type II observation window runs for months after that.
  • You expect us to issue the report. The examination is performed by an independent audit firm; we get you ready and stand with you through it.
  • Your customers have asked for ISO 27001 specifically. The control work overlaps, and the framework and the auditor are different.

Frequently Asked Questions

All questions
What is SOC 2?

SOC 2 is an independent audit of how your company safeguards customer data. The output is a report your customers' security teams accept in place of endless questionnaires. We build the controls and keep the evidence current so the audit confirms rather than surprises.

How is this different from just answering security questionnaires?

The alternative is answering every enterprise customer's 300-question security review by hand, forever. One SOC 2 report replaces most of that, and the controls behind it make you genuinely more secure rather than just better at paperwork.

When do we need a SOC 2 report?

When you sell to bigger customers who hold you to their security standards, especially as a software or services business handling client data. The trigger is usually a deal: a prospect asks for the report you do not have yet. If your customers never ask for it and never will, the audit adds cost without opening any doors; get the underlying security right and add the report when the market asks for it.

Do you run the audit or certification itself?

No. Auditors and assessors have to stay independent, so the same firm cannot build your controls and certify the result. We build the controls, assemble the evidence, and sit beside you during the assessment, so the auditor finds a running system rather than a scramble.

Do you require long-term contracts?

No. Our standard commitment is a rolling 90 days, so we earn your business every quarter. Everything we build lives in your own Microsoft tenant with nothing proprietary in the way, which keeps that promise real: you could hand the keys to any provider tomorrow.

What happens in the first 90 days?

Weeks one and two are access and visibility: admin roles audited, MFA enforced, monitoring on your most critical systems, and a shared password vault. Weeks three to eight set the baseline: licensing rationalized, device management everywhere, backups running and test-restored. By week 13 you have a steady rhythm: a weekly status call, a patch cadence, playbooks you own, and a 90-day review that sets the roadmap.

How does pricing work?

Managed services run at a flat monthly rate per person, which covers their primary device; shared and additional devices are a small add-on. Project work is hourly and quoted in writing before it starts, or converted to a fixed monthly fee when you want budget certainty. Microsoft licensing passes through at list price.

Related Reading

All insights
Featured

Latest

Jul 16, 2026CMMC and your Microsoft 365 tenant: why GCC high changes what software can connectA defense-adjacent manufacturer heading into a CMMC mock audit learned that a government-cloud Microsoft tenant can quietly limit which apps integrate with it.Microsoft SecurityJun 5, 2026Getting off paper: ERP for small regulated manufacturersFor a small regulated manufacturer still running on paper and spreadsheets, moving to an ERP is as much a change-management project as a software one. Here is what the system needs to enforce, and how to bring the team with you.Business CentralApr 22, 2026CMMC level 2 for small defense suppliers: wall off your CUI instead of moving the whole companyWhen controlled data touches only a slice of your work, you can shrink CMMC Level 2 scope by walling CUI into a governed enclave instead of dragging the whole company in.Microsoft SecurityApr 16, 2026Your staff are already using AI. For a HIPAA-regulated org, governed Copilot beats banning it.When staff paste protected health information into public chatbots, you can't ban your way out; a governed Microsoft 365 Copilot keeps the data in your tenant.Microsoft 365Apr 7, 2026FDA validation just changed (CSV to CSA): keep your quality system out of your ERPThe FDA's move from computer system validation to Computer Software Assurance, plus keeping quality management out of the ERP, can shrink the biggest cost in a regulated ERP project.Business Central

Get SOC 2 ready

Start before the deal that requires it shows up in your pipeline.

30 minutesNo obligationGet an initial estimate within one week