SOC 2 readiness · For US-facing SaaS
A US enterprise deal stalls the moment procurement asks for a SOC 2 report. We scope the Trust Services Criteria, build the controls and evidence, and get you audit-ready - so the CPA's examination confirms what is already true instead of exposing gaps.
Independent advisory - not a CPA firm. We prepare you; the report is issued by a licensed CPA.
Typical investment
2-4 weeksFrom $5,000
Typical $5,000-$12,000
What changes it: Number of Trust Services Criteria in scope · Type I (point in time) vs Type II (over a period) · Company size · Current evidence quality
Kellwick prepares you; the SOC 2 report itself is issued by a licensed CPA firm (their fee is separate).
What SOC 2 actually is
SOC 2 (System and Organization Controls 2) is an AICPA framework. A licensed CPA firm examines your controls against the Trust Services Criteria and issues a report - there is no certificate and no accreditation body. You share the report with customers, usually under NDA, to answer their security due diligence.
Security (the Common Criteria) is always in scope. Availability, Confidentiality, Processing Integrity and Privacy are added only where your customers ask for them - scoping them correctly is the first place teams overspend. A Type I report covers control design at a point in time; a Type II covers whether they operated effectively over a period.
ISO 27001 vs SOC 2
They are not competitors - they answer different customers. The control overlap is large, so if you run one, most of the evidence carries onto the other.
| ISO 27001 | SOC 2 | |
|---|---|---|
| What it is | An international certification of an information security management system (ISMS) | A US attestation report on controls, written by a licensed CPA firm |
| Who issues it | An accredited certification body, after a Stage 1 + Stage 2 audit | A licensed CPA firm (AICPA), after an examination |
| What you get | A certificate you can publish | A report you share with customers under NDA |
| Who asks for it | International and EU buyers, tenders, regulators | US enterprise buyers, especially SaaS procurement |
| Cadence | 3-year cycle with annual surveillance | Type II typically renewed every 12 months |
Deciding between them? Read the full ISO 27001 vs SOC 2 comparison.
What SOC 2 readiness includes
FAQ
No, and this trips a lot of teams up. SOC 2 is an attestation: a licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report. There is no certificate and no accreditation body. You share the report with customers, usually under NDA. ISO 27001 is the actual certification.
No. Only a licensed CPA firm can perform the examination and issue the report - that independence is the point of it. Kellwick is an independent advisory practice: we get you audit-ready (scope, controls, evidence, gap closure) so the CPA's examination is a confirmation, not a scramble. Their fee is separate from ours.
Type I reports on whether your controls are suitably designed at a single point in time. Type II reports on whether they operated effectively over a period (commonly 3 to 12 months). Most enterprise buyers eventually want Type II. Type I is a faster way to have something to show while the Type II observation window runs.
Often yes - not because one replaces the other, but because different buyers ask for different things. US enterprise procurement asks for SOC 2; international buyers and tenders ask for ISO 27001. The good news is the control overlap is large, so most of your ISO evidence maps straight onto the Trust Services Criteria. We build the SOC 2 readiness on top of what you already have rather than starting again.
Readiness itself is typically 2-4 weeks of work depending on scope and how organised your evidence is. For a Type II, the examination then observes your controls over a period after that, so the total calendar time to a Type II report is longer - we plan the observation window with you.
Readiness is fixed-scope with public ranges on our pricing page. It scales with how many Trust Services Criteria are in scope, Type I versus Type II, your size and your current evidence quality. The CPA firm's examination fee is separate and quoted by them.
Tell us the deal and the deadline. We will scope the readiness and give you a fixed price - and if you already hold ISO 27001, we build on it.