.ai

SOC 2 readiness

Available

Get SOC 2 audit-ready with an AI vCISO that does the work.

Build the roadmap, draft the policies, organize the evidence, monitor key controls, and prepare for independent testing from $2,490/year.

Open the program view

Clear responsibility

Your AI vCISO prepares the work. Independent judgment stays independent.

The product prepares and coordinates readiness work while your team and the independent reviewer retain their required roles.

Your AI vCISO prepares

  • Build the roadmap and prepare policy drafts
  • Organize evidence and identify likely gaps
  • Prepare remediation and the audit package

Your team approves or performs

  • Provide company context and approve policies
  • Perform operational changes and accept evidence
  • Work with the independent CPA firm

Independent reviewer

  • Define final testing requirements
  • Test controls and evaluate exceptions
  • Issue the SOC 2 report

Product workflow

Move from scope to reviewable proof.

Each stage stays connected to the same controls, policies, evidence, owners, and remediation history.

Readiness depends on

Starting maturity, scope, response time, required remediation, independent-reviewer availability, and any required observation or operating period.

  1. Scope
  2. Prepare controls
  3. Collect evidence
  4. Resolve gaps
  5. Begin independent audit
  6. Complete Type II observation where applicable

What the program prepares

Deliverables are working program records, not an audit opinion or certification.

  • Scoped control program
  • Policy set and approval history
  • Reviewed evidence index
  • Prioritized remediation
  • Organized audit package

Related integrations

Available integrations collect supported read-only observations. They do not replace evidence review or independent testing.

  • Amazon Web Services
  • Google Cloud
  • Microsoft Azure
  • GitHub
  • GitLab
  • Okta
  • Microsoft Entra ID
  • Google Workspace

What is SOC 2?

SOC 2 is an attestation framework created by the AICPA, the American Institute of Certified Public Accountants. An independent CPA firm examines how your company protects customer data and issues the report. B2B software buyers frequently request SOC 2 during procurement.

The framework is built on the Trust Services Criteria. Security is the mandatory category, organized into nine groups of common criteria covering everything from governance and risk to access control, change management, and incident response. Four more categories are optional and added when they match your commitments to customers: Availability, Confidentiality, Processing Integrity, and Privacy.

There are two report types. A Type 1 report looks at the design of controls at a single point in time. A Type 2 report covers an observation period and tests whether controls operated during that period. The right sequence depends on the buyer request, current maturity, available operating evidence, and the independent CPA firm's approach.

All 61 Trust Services Criteria represented

The platform represents all 61 criteria and maps relevant work to ISO 27001 relationships for separate review.

CC1

Control environment

Governance, integrity, and accountability

CC2

Communication

Internal and external information flows

CC3

Risk assessment

Identifying and analyzing risk

CC4

Monitoring

Evaluating controls over time

CC5

Control activities

Policies and procedures that execute

CC6

Access controls

Logical and physical access

CC7

System operations

Detection, incidents, and recovery

CC8

Change management

Controlled changes to systems

CC9

Risk mitigation

Vendors and business disruption

A

Availability

Capacity, backup, and recovery

C

Confidentiality

Protecting confidential information

PI / P

Integrity and Privacy

Processing integrity and personal data

61

criteria, one control set

Each represented SOC 2 criterion maps to implementation work, and reviewed controls and evidence can support relevant ISO 27001 requirements.

Frequently asked questions

Quick answers about the product, frameworks, and getting started.

SOC 2 basics

How long does SOC 2 take?

Timing depends on scope, starting maturity, remediation, responsiveness, CPA-firm availability, and the Type 2 observation period when applicable. The readiness roadmap identifies the work, but it does not guarantee a completion date.

How much does SOC 2 cost in total?

Plan for the platform, the independent CPA firm, remediation, and your team's time. CPA-firm fees vary by scope, report type, complexity, and testing approach. vCISO.ai prices are published on the pricing page; request a current CPA-firm proposal for the audit cost.

Type 1 or Type 2 first?

Follow the report type named by the buyer when one is explicit. Otherwise, compare the need for a point-in-time Type 1 report with the operating-period evidence required for Type 2, then confirm the sequence with the independent CPA firm.

Do you do the audit?

No. SOC 2 reports must come from an independent licensed CPA firm. We get you ready, keep your evidence organized for the auditor, and can introduce you to firms we trust.

Did not find what you were looking for? Talk to us.

Start with the roadmap

Build SOC 2 readiness inside a real security program.

Start with a saved readiness roadmap, then open the first control your team should complete.