Control environment
Governance, integrity, and accountability
SOC 2 readiness
AvailableBuild the roadmap, draft the policies, organize the evidence, monitor key controls, and prepare for independent testing from $2,490/year.
Clear responsibility
The product prepares and coordinates readiness work while your team and the independent reviewer retain their required roles.
Product workflow
Each stage stays connected to the same controls, policies, evidence, owners, and remediation history.
Readiness depends on
Starting maturity, scope, response time, required remediation, independent-reviewer availability, and any required observation or operating period.
Deliverables are working program records, not an audit opinion or certification.
Related integrations
Available integrations collect supported read-only observations. They do not replace evidence review or independent testing.
SOC 2 is an attestation framework created by the AICPA, the American Institute of Certified Public Accountants. An independent CPA firm examines how your company protects customer data and issues the report. B2B software buyers frequently request SOC 2 during procurement.
The framework is built on the Trust Services Criteria. Security is the mandatory category, organized into nine groups of common criteria covering everything from governance and risk to access control, change management, and incident response. Four more categories are optional and added when they match your commitments to customers: Availability, Confidentiality, Processing Integrity, and Privacy.
There are two report types. A Type 1 report looks at the design of controls at a single point in time. A Type 2 report covers an observation period and tests whether controls operated during that period. The right sequence depends on the buyer request, current maturity, available operating evidence, and the independent CPA firm's approach.
The platform represents all 61 criteria and maps relevant work to ISO 27001 relationships for separate review.
Governance, integrity, and accountability
Internal and external information flows
Identifying and analyzing risk
Evaluating controls over time
Policies and procedures that execute
Logical and physical access
Detection, incidents, and recovery
Controlled changes to systems
Vendors and business disruption
Capacity, backup, and recovery
Protecting confidential information
Processing integrity and personal data
61
criteria, one control set
Each represented SOC 2 criterion maps to implementation work, and reviewed controls and evidence can support relevant ISO 27001 requirements.
Quick answers about the product, frameworks, and getting started.
Timing depends on scope, starting maturity, remediation, responsiveness, CPA-firm availability, and the Type 2 observation period when applicable. The readiness roadmap identifies the work, but it does not guarantee a completion date.
Plan for the platform, the independent CPA firm, remediation, and your team's time. CPA-firm fees vary by scope, report type, complexity, and testing approach. vCISO.ai prices are published on the pricing page; request a current CPA-firm proposal for the audit cost.
Follow the report type named by the buyer when one is explicit. Otherwise, compare the need for a point-in-time Type 1 report with the operating-period evidence required for Type 2, then confirm the sequence with the independent CPA firm.
No. SOC 2 reports must come from an independent licensed CPA firm. We get you ready, keep your evidence organized for the auditor, and can introduce you to firms we trust.
Did not find what you were looking for? Talk to us.
Start with the roadmap
Start with a saved readiness roadmap, then open the first control your team should complete.