Nobody is legally required to hold a SOC 2. It arrives through procurement, and once it does it is the fastest way through a vendor review. What arrives at the end is not a certificate: it is a licensed CPA firm’s opinion on the controls that you yourself described, in your own chosen words.
A SOC 2 report is an auditor’s opinion. Not a certificate.
Security is always in scope. The other four you elect - and then get tested on, across a period, by a licensed CPA firm rather than by us.
Our promise
“A badge is a logo. The control test is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.
- Each additional system
- $3,000
- Re-audit, same scope
- $8,000
- Renewal, every twelve months
- $10,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework readiness assessment produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this readiness assessmentSOC 2 Type II, in three chapters
Most teams write the controls and discover the evidence problem in month nine. A Type II tests operation over time, so a control producing a record only when somebody remembers to collect one produces nothing at all. Add a model retrained on an unlogged cadence.
We are the independent read before the audit firm arrives, and we cannot be the audit firm. That is not a limitation we apologise for — it is what makes the readiness opinion worth reading. You get the boundary, the control matrix, the evidence plan and the gap list they will ask for.
An opinion on what you described.
An attestation against the Trust Services Criteria — and the description is yours.
- SaaS and platform vendors selling to enterprise buyers
- Anyone processing customer data with a model in the path
- Healthcare and fintech suppliers, where diligence flows down
- Sub-processors reached through their customers’ reports
- Type I: were the controls suitably designed, as at one date
- Type II: did they operate effectively, across a period
- Type I fails where a control is described and never runs
- Buyers now read Type I as a staging post, not an answer
The description is yours. The opinion is theirs.
The service organisation
The system description is yours, and so is everything it describes: the boundary you drew, the categories you elected, the controls you wrote down and the evidence each of them left behind while nobody was watching. An auditor tests your description. They do not write it, and they cannot.
The people who issue the opinion
A licensed CPA firm, working to AICPA standards. They sample, they test, and they express an opinion on whether your controls were suitably designed and - in a Type II - operated effectively across the period. They are not a certification body and the report is not a pass mark, whatever it is called.
Why we cannot be both
The report is issued by a licensed CPA firm working to AICPA standards, not by iDharma, and we claim no affiliation with one. We prepare the description, the evidence and the gap list they will ask for - and no single firm may both prepare you and then issue an independent opinion on that preparation.
“Whoever gets us ready can do the audit too.”
No one may opine on work they did themselves.
Which is why we will never quote you for both.
- Who it is for
- SaaS & platform vendors
- Healthcare & fintech suppliers
- Sub-processors
- Security & compliance
- Teams already on ISO 27001
What replaces the report is a bespoke security questionnaire per customer, answered by your engineers, for as long as you sell without one.
A Type I buys you a staging post, not an answer. The period is the difficulty, and a period that has closed cannot be evidenced afterwards.
Where two vendors are otherwise close, the one holding a current report is the lower-risk choice - and the buyer does not have to explain why.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a readiness opinion.
Your scope check
Four phases, and only three are ours.
The observation period runs in front of the report - so the expensive mistake is starting to collect evidence when fieldwork is booked.
-
Scope
Weeks 1-6Draw the boundary, elect the categories honestly, and find the AI and the sub-service organisations inside that.
-
Design
Weeks 7-14Map each control to its criterion, close the design gaps, and agree what evidence each will leave.
-
Observe
3-12 monthsThe period runs. Evidence is collected continuously rather than at the end, and exceptions are recorded.
-
Attest
Their fieldworkYour audit firm samples, tests and issues the opinion. We are not in the room, which is what makes it worth having.
A Type II tests whether controls operated across a period, and a period that has closed cannot be reconstructed. Teams write the controls in month one, start collecting the records in month nine, and find the window they need evidence for is the one they have nothing from.
What the criteria ask, what we ship
12 requirements, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.
- The system description Everything else hangs off it
- A written boundary - what is inside, what is deliberately outside, and why - including models, training pipelines and inference paths.
- Category election Security always; the other four you choose
- An honest election, with the commitments each added category creates written down before you are tested against them.
- Control environment CC1 - CC2
- Governance, roles and communication evidenced as they actually operate, rather than described as they were intended to.
- Risk assessment CC3 - and it must cover the AI
- A risk assessment reaching the AI estate, with treatment decisions recorded, owners attached and a review date that has passed at least once.
- Monitoring of controls CC4
- Evidence that somebody checks the controls are running - the control over the controls, which is the one most often missing.
- Control activities CC5 - criterion to control to record
- Each control mapped to the criterion it satisfies and to the record it generates on its own, without anyone remembering to collect it.
- Logical and physical access CC6 - where samples land
- Provisioning, deprovisioning and periodic review, including who can reach training data, launch a fine-tune or change production inference.
- System operations CC7 - the part people skip
- Alerting that reaches a person, incidents recorded with severity and owner, and the trail from detection through to closure.
- Change management CC8 - and retraining is a change
- Model retraining, prompt changes and threshold moves treated as changes, with the approval trail that implies.
- Vendor and sub-service CC9 - carve-out or inclusive
- Providers assessed and monitored, and the carve-out or inclusive decision made deliberately and reflected in the description.
- Evidence across the period Type II - not collectable later
- A collection plan running for the whole window, because a Type II tests operation over time and a period cannot be backfilled.
- Readiness opinion Ours - not the attestation
- A findings list with severity and owner, written so your audit firm can start from it rather than discover it during fieldwork.
Readiness, independently read
From the login screen to the training pipeline.
-
Intake
What is inside the boundary, and which categories you are electing.
-
Test
Every control against its criterion, and against what actually happens.
-
Sign off and hand over
You see the draft first. Then the gap list and the evidence pack - for your auditor.
Why teams choose iDharma for the read before the audit
We cannot audit you
Which is the point. We take no fee from an audit firm and issue no opinion on our own work.
Written to the criterion
Every finding names the criterion it sits under, so your auditor can start where we stopped.
Evidence, not intentions
We test whether a control leaves a record on its own - which is what a sample will look for.
The model is in scope
A model in the data path is inside the boundary, and we read the pipeline as part of the system.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
SOC 2 readiness report
The full review against the Trust Services Criteria: what would survive fieldwork today, what would raise an exception, and what is not yet a control at all - findings by criterion, graded by how a sample would land on them, with the boundary and the AI in the data path read as part of the system. A readiness opinion, not an attestation.
System description pack
The boundary written down - systems, models, training pipelines, inference paths and the vendors behind them, with the exclusions argued.
Control matrix
Every control against the criterion it satisfies and the record it generates, so a gap shows up as an empty cell rather than as a surprise.
Evidence collection plan
What to capture, how often and where it lands, running from the first day of the window - because a closed period cannot be reconstructed.
Access review pack
Provisioning, deprovisioning and periodic review - including access to training data and model artefacts, which is where samples land.
Vendor and carve-out memo
Sub-service organisations identified, assessed and placed - with the carve-out or inclusive decision argued rather than defaulted into.
Gap list for your auditor
Findings with severity, owner and a date, ordered by how a sample would land - written to be handed straight to the firm doing the fieldwork.
Real numbers, upfront.
- Scope
- Your boundary, agreed first
- Not included
- The attestation - a CPA firm’s
- Re-review
- Before each new period - $10,500 against your known baseline
The boundary is agreed before anything is charged - your audit firm bills you separately, and we take nothing.
Request this review- System description and boundary
- Control matrix, criterion by criterion
- Evidence plan for the whole period
- Gap list your auditor can start from
Four things fieldwork will ask you to produce
A sample does not care what you intended. Each of these is either in the folder on the day they ask, or it is an exception.
The boundary,
set
A line somebody decided rather than inherited, saying what is outside as clearly as what is in. Every test in the report is a test of the description it produces.
The evidence,
dated
Records generated across the whole observation window. A Type II tests operation over time, and a period that has already closed cannot be backfilled later.
The failures,
owned
The failures you found yourself, with the fix and its date beside each one. An exception you raised yourself reads very differently from one that a sample turned up.
The vendors,
placed
Sub-service organisations named, and the carve-out or inclusive decision taken deliberately - not discovered halfway through somebody else's fieldwork.
Four cards, and the second one is the one you cannot go back for.
Plain answers
What it is, who signs it, the boundary, timing. Answered straight.
Request this reviewIs SOC 2 a certification?
No. It is an attestation - an opinion from a licensed CPA firm on whether your controls were suitably designed and, in a Type II, operated effectively across a period. There is no certificate and no pass mark.
What is the difference between Type I and Type II?
Type I asks whether controls were suitably designed as at one date. Type II asks whether they operated effectively across a period - and the period is the entire difficulty, because it cannot be backfilled.
Can you be our auditor?
No. A SOC 2 is issued by a licensed CPA firm and we are not one. The same firm cannot both prepare you and issue an independent opinion on your preparation - a provider offering both is selling you something the standard does not permit.
Does our model have to be in the boundary?
If it is in the data path, it is inside the system - and leaving it out is a decision your system description has to survive. Excluding it is possible; excluding it quietly is not.
How long does a readiness review take?
Typically four to six weeks from hand-over, longer where the boundary turns out to be wider than expected - which it usually does once the AI pipeline is in scope. Scope is agreed before anything is charged.
Request your readiness review
Tell us what is in the boundary and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have, and nothing we cannot work around if a piece of it is missing - the state of the first two items is usually the finding not the obstacle.
- An architecture diagram, however out of date it is
- Your control set and policies, in whatever state
- Which categories you intend to elect beyond Security
- Whether a model touches customer data, and whose it is
- Your target period, and whether a deal is waiting on it
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- AICPA Trust Services Criteria
- The AICPA guide for service organisations
- Type I
- One point in time Controls suitably designed, as at a stated date
- Type II
- Across a period And the controls operated effectively throughout
What it means
- General information about what the Trust Services Criteria ask — not accounting or legal advice, and no professional relationship.
- Where a boundary or an election is genuinely arguable, our reports say so rather than pick the convenient answer.
Scope & limitation
- Observation-period convention and bridge-letter practice vary by audit firm and are not settled by the criteria. Confirm both with the firm that will sign.
- We are not a licensed CPA firm and issue no attestation. Use this as a starting point for a scoping conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom