SOC 2 attestation,
issued by a CPA firm.
We scope tightly, test once, and issue a report that survives your customer's vendor-risk review — led by the practitioner who signs it, not handed down to juniors.
Type I or Type II? It depends who's asking.
If a deal is waiting, most companies start with Type I and roll straight into Type II on the same scope — you get something to send now, and the report buyers really want a quarter later.
Five criteria. You almost certainly don't need all five.
Security is mandatory. The rest are elective, and each one you add costs evidence and time — so we scope to what your buyers actually request, not to the maximum.
Security
Access control, change management, monitoring, incident response, vendor risk.
Availability
Add it when you sell an SLA. Capacity, backup, recovery, incident tracking.
Processing integrity
For transaction processors and anyone whose output is the product.
Confidentiality
Commonly requested where you hold commercially sensitive client data.
Privacy
Notice, choice, retention and disposal of personal information.
Five stages, run under AICPA attestation standards.
Walkthroughs first, then a fixed period, then testing — with evidence requested in batches so your team is never blocked twice.
Scoping call
A call with the practitioner who would lead the work. You leave with criteria, boundary, timeline and fee.
Readiness & gap review
We walk through each process with its owner, document the system description and agree the evidence for every control.
Observation window
Controls run for 3–6 months. We check in monthly so evidence is collected as you go, not scrambled at the end.
Fieldwork & testing
Inquiry, inspection, observation and re-performance on your systems, on a schedule that doesn't stall engineering.
Report & renewal
Signed report, buyer-ready summary, bridge letter when needed, and dated milestones for next cycle.
The six gaps we find most often.
None of these are hard to fix — they're just easier to fix before the observation window starts than during it. If you recognize three or more, start with a readiness review rather than an audit.
Ask for a readiness review →They happen, but nobody keeps the artefact that proves they happened.
Access removal isn't tied to the HR trigger, so timing can't be demonstrated.
Approvals live in chat threads instead of the pull request or ticket.
Subservice organizations aren't assessed, and their SOC reports aren't reviewed.
A policy exists; no tabletop or post-incident review has ever been run.
All five criteria and every system in boundary, when two criteria would satisfy the buyer.
One engagement can carry SOC 2, ISO 27001 and HIPAA.
Most of the control set overlaps. We map it once, test it once, and report against each framework separately — materially cheaper and far less disruptive than running the audits back to back.
You meet the person who signs the report.
Before the engagement letter, you'll have spoken to the US CPA or CISA who leads the fieldwork and puts their name on the opinion. Junior staff support them; they never lead your engagement, and they don't own your scope.
Named lead on the engagement letter, not a resourcing pool.
Same lead through readiness, fieldwork and issuance — no handoffs.
One engagement lead from scoping through to the signed report.
What buyers ask us first.
Anything not covered here, email us — we usually reply the same business day.
contact@assurionservices.comCan you audit us if we've never had a SOC 2 before?
Yes, and that's most first engagements. We start with a readiness review so the gaps are fixed before the observation window opens — auditing first and remediating after is how companies end up with exceptions in the report.
Will exceptions in the report lose us the deal?
Rarely, if they're explained. Security teams expect a small number of deviations and read management's response closely. What loses deals is a report with no detail on population sizes, or one that quietly avoids testing something in scope.
Do we need a compliance automation platform?
Not necessarily. If you already run one we'll pull evidence from it. If you don't, we won't make you buy one — for a first Type I the tooling rarely pays for itself, and a spreadsheet plus your existing ticketing is usually enough.
Who can we share the report with?
It's a restricted-use report: your user entities, their auditors, business partners and prospects with sufficient understanding of the system, usually under NDA. That's why we also issue a summary you can share more freely.
How much of our engineering team's time does this take?
Expect a few hours a week during readiness, then roughly a day a week across fieldwork, concentrated in one or two people. We schedule evidence requests in batches rather than trickling them out.
Can you take over from another auditor mid-cycle?
Yes. We'll review the prior report and workpaper scope, confirm the control set still matches your system, and pick up the period without restarting the observation window where the evidence supports it.
What a SOC 2 costs.
Quoted individually, in writing, before anything is payable. We do not publish a rate card, because the same report can mean very different work depending on what you run and what your buyer asked for.
Submitting a request and the scoping call are both free, and no card details are taken at either point. You receive a written fixed-fee proposal within three business days of the call — a single amount in US dollars, exclusive of applicable taxes, covering a stated scope and timeline. You are invoiced only after signing an engagement letter, and only for the fee stated in it. No subscriptions, no automatic renewals.
See how we price, our fees, payment, refunds and cancellation policy and terms of service. Please read both before submitting a request or making a payment.