Skip to main content
Compliance Readiness

SOC 2
Readiness

SOC 2 is the report North American enterprise buyers ask for, and the one most often failed for reasons that have nothing to do with security. We run the readiness engagement so that when your auditor arrives, every Trust Services Criterion has an owner, a control, and evidence that survives being asked about.

Type I Type II Readiness Assessment
readiness log SOC 2 assessing
09:14:02scopeSOC 2 Type IIconfirmed
09:14:17assessControl Environmentwalked
09:15:18assessCommunication & Informationwalked
09:16:19assessRisk Assessmentwalked
09:18:40gapmarked complete, no evidence attachedblocker
09:19:05gapcontrol has no named owneropen
09:22:31evidencefiled against control · expiry trackedaccepted
09:24:12handoffrequirement → control → evidencemapped
your team assesses evidence vetted tracked in Talon
10
control areas walked
3
assessment paths
14
frameworks on one programme
0
methodology slides
Fit

Who this is for

Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.

B2B SaaS companies where a signed deal is waiting on a SOC 2 report

Teams told by an enterprise prospect that a security questionnaire is no longer enough

Companies who have picked a CPA firm and want to arrive ready rather than discover gaps in fieldwork

Anyone who has already failed an observation period and does not want to repeat it

Scope of work

What the engagement does

Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.

  • Define the system description and the boundary the report will cover
  • Select the Trust Services Criteria in scope - Security alone, or with Availability, Confidentiality, Processing Integrity, Privacy
  • Assess every control in scope and record where you actually stand, not where the policy says you stand
  • Build the evidence set each criterion needs and name the owner who maintains it
  • Work the gap list down with your team until the exceptions that would be written up are closed
  • Hand the auditor a package that maps criterion to control to evidence

What you walk away with

A control set your team runs, an evidence trail that is defensible on the date the auditor asks about, and a gap list that is closed rather than deferred. If you are heading for a Type II, the observation period starts with the controls already operating, not with a scramble in month one.

Sequence

How it runs

Four phases. You always know which one you are in and what is outstanding.

01

Scoping call

We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.

no charge
02

Assessment

We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.

Lorikeet assessor
03

Remediate and evidence

We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.

joint
04

Hand off to your assessor

You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.

with your assessor
Coverage

What the assessment covers

The control areas we walk for SOC 2. Each breaks down into individual controls carrying status, owner and evidence in Talon.

01 Control Environment
02 Communication & Information
03 Risk Assessment
04 Monitoring Activities
05 Control Activities
06 Logical & Physical Access
07 System Operations
08 Change Management
09 Risk Mitigation
10 Availability
Who performs the assessment

SOC 2 reports are issued by an independent CPA firm. We do not issue the report - that independence is the point of the report. We prepare you for it and work alongside the firm you pick, or introduce you to one.

Where it lives

It runs in Talon, not in a spreadsheet

Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.

  • Control-by-control status, kept current by the people doing the work
  • Evidence filed against the control it satisfies, with expiry dates tracked
  • The auditor request list, so nothing is chased over email
  • A readiness view that shows what an assessor would see
Already running a compliance platform?

Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.

Our partners
Questions

Asked on almost every SOC 2 call

Type I says your controls were designed properly on a single date. Type II says they operated properly across a window, usually three to twelve months. Buyers increasingly ask for Type II. If you need something in hand quickly, a Type I gets you a report while the Type II window runs.

It depends on how much of the control set already exists and how quickly your team can produce evidence. The assessment itself is fast; closing gaps is what sets the timeline. We give you the gap list early so you can start on the long poles while the rest of the assessment continues.

No. Security is required. Availability, Confidentiality, Processing Integrity and Privacy are optional and each one adds scope, cost and evidence. Most companies start with Security alone and add criteria when a buyer actually asks.

Those platforms are good at collecting evidence continuously once your controls exist and work. Readiness is the part before that - deciding the boundary, designing the controls, and closing the gaps the tooling will otherwise monitor as permanently red.

Alongside

Rarely run alone

Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.

Next

SOC 2 readiness, on your timeline

A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!