The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Governance and compliance
Preparation for the report your customer demands.
We prepare your operation for the SOC 2 examination: we define the scope, design the controls, set up the evidence routine, and write the system description in the format the audit firm expects to receive. When the auditor starts fieldwork, nothing is improvised, because every control already has a named owner and a known place for its evidence.
The report type changes the work. Type I is a snapshot of control design at a point in time and can unblock a deal now. Type II requires an observation period of three to twelve months, with real execution samples, and is what your customer's procurement team usually demands in due diligence. We prepare both paths, and the evidence routine is built with you before the period starts counting.
To get there, we need the policies and records you already have, access to the control owners, and clarity on which report your customer asked for. You receive the gap report, the action plan, the approved document set, and the finished system description. The independent CPA firm that signs the report is hired by you, and that is how independence is preserved.
You also choose how far we go: from the gap assessment with an action plan, which your team executes, to full support, with a rehearsal before the audit and presence during fieldwork.
The stages and deliverables below describe the Type II: the film of a period · Full compliance work modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
Audit support
We rehearse the audit beforehand, in the format the auditor will use, so findings surface with us and not with them. During fieldwork we sit in on the sessions and help your team present the right evidence at the right moment. Whatever still gets flagged becomes a corrective action plan, with an owner and a deadline.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.