SOC 2 TYPE II · READINESS · AICPA TSC

A SOC 2 report is an auditor’s opinion. Not a certificate.

Security is always in scope. The other four you elect - and then get tested on, across a period, by a licensed CPA firm rather than by us.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
A period cannot be reconstructed
Security Availability Processing integrity Confidentiality Privacy

Our promise

“A badge is a logo. The control test is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework readiness assessment produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this readiness assessment
The case file

SOC 2 Type II, in three chapters

The Report

Nobody is legally required to hold a SOC 2. It arrives through procurement, and once it does it is the fastest way through a vendor review. What arrives at the end is not a certificate: it is a licensed CPA firm’s opinion on the controls that you yourself described, in your own chosen words.

The Gap

Most teams write the controls and discover the evidence problem in month nine. A Type II tests operation over time, so a control producing a record only when somebody remembers to collect one produces nothing at all. Add a model retrained on an unlogged cadence.

The Office

We are the independent read before the audit firm arrives, and we cannot be the audit firm. That is not a limitation we apologise for — it is what makes the readiness opinion worth reading. You get the boundary, the control matrix, the evidence plan and the gap list they will ask for.

What is a SOC 2?

An opinion on what you described.

An attestation against the Trust Services Criteria — and the description is yours.

Who gets asked for one № 01
  • SaaS and platform vendors selling to enterprise buyers
  • Anyone processing customer data with a model in the path
  • Healthcare and fintech suppliers, where diligence flows down
  • Sub-processors reached through their customers’ reports
SOC 2 · iDharma · Presented for review
Type I against Type II № 02
  • Type I: were the controls suitably designed, as at one date
  • Type II: did they operate effectively, across a period
  • Type I fails where a control is described and never runs
  • Buyers now read Type I as a staging post, not an answer
SOC 2 · iDharma · Presented for review
Who signs what

The description is yours. The opinion is theirs.

You

The service organisation

The system description is yours, and so is everything it describes: the boundary you drew, the categories you elected, the controls you wrote down and the evidence each of them left behind while nobody was watching. An auditor tests your description. They do not write it, and they cannot.

Your audit firm

The people who issue the opinion

A licensed CPA firm, working to AICPA standards. They sample, they test, and they express an opinion on whether your controls were suitably designed and - in a Type II - operated effectively across the period. They are not a certification body and the report is not a pass mark, whatever it is called.

The catch

Why we cannot be both

The report is issued by a licensed CPA firm working to AICPA standards, not by iDharma, and we claim no affiliation with one. We prepare the description, the evidence and the gap list they will ask for - and no single firm may both prepare you and then issue an independent opinion on that preparation.

What most teams assume

“Whoever gets us ready can do the audit too.”

What independence requires

No one may opine on work they did themselves.

Which is why we will never quote you for both.

  • Who it is for
  • SaaS & platform vendors
  • Healthcare & fintech suppliers
  • Sub-processors
  • Security & compliance
  • Teams already on ISO 27001
Why this matters in 2026
A string-tied kraft envelope on a dark surface, stamped CONFIDENTIAL in red above a ruled line reading FOR AUTHORIZED PERSONNEL ONLY: the report a buyer asks for and nobody can produce on the day.
01 There is no fine and no regulator. There is a deal that stalls: enterprise procurement now treats a current Type II as a gate rather than a preference, and the gate is answered on their timetable, not yours.
02

What replaces the report is a bespoke security questionnaire per customer, answered by your engineers, for as long as you sell without one.

03

A Type I buys you a staging post, not an answer. The period is the difficulty, and a period that has closed cannot be evidenced afterwards.

04

Where two vendors are otherwise close, the one holding a current report is the lower-risk choice - and the buyer does not have to explain why.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a readiness opinion.

0 of 3

The ask -

Nobody is legally required to hold one. It arrives through procurement, which means the timetable is the buyer’s and the observation period runs in front of it.

In the path -

In the path means inside the boundary. You may draw it to exclude a model, but the system description has to survive being read by an auditor and then by the customer who asked for the report.

You hold -

A report covers a stated window and does not expire - it ages. What a buyer wants is a period that ended recently enough to still describe you.

The roadmap

Four phases, and only three are ours.

The observation period runs in front of the report - so the expensive mistake is starting to collect evidence when fieldwork is booked.

  1. Scope

    Weeks 1-6

    Draw the boundary, elect the categories honestly, and find the AI and the sub-service organisations inside that.

  2. Design

    Weeks 7-14

    Map each control to its criterion, close the design gaps, and agree what evidence each will leave.

  3. Observe

    3-12 months

    The period runs. Evidence is collected continuously rather than at the end, and exceptions are recorded.

  4. Attest

    Their fieldwork

    Your audit firm samples, tests and issues the opinion. We are not in the room, which is what makes it worth having.

The trap

A Type II tests whether controls operated across a period, and a period that has closed cannot be reconstructed. Teams write the controls in month one, start collecting the records in month nine, and find the window they need evidence for is the one they have nothing from.

Criteria & coverage

What the criteria ask, what we ship

12 requirements, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.

The system description Everything else hangs off it
A written boundary - what is inside, what is deliberately outside, and why - including models, training pipelines and inference paths.
Category election Security always; the other four you choose
An honest election, with the commitments each added category creates written down before you are tested against them.
Control environment CC1 - CC2
Governance, roles and communication evidenced as they actually operate, rather than described as they were intended to.
Risk assessment CC3 - and it must cover the AI
A risk assessment reaching the AI estate, with treatment decisions recorded, owners attached and a review date that has passed at least once.
Monitoring of controls CC4
Evidence that somebody checks the controls are running - the control over the controls, which is the one most often missing.
Control activities CC5 - criterion to control to record
Each control mapped to the criterion it satisfies and to the record it generates on its own, without anyone remembering to collect it.
Logical and physical access CC6 - where samples land
Provisioning, deprovisioning and periodic review, including who can reach training data, launch a fine-tune or change production inference.
System operations CC7 - the part people skip
Alerting that reaches a person, incidents recorded with severity and owner, and the trail from detection through to closure.
Change management CC8 - and retraining is a change
Model retraining, prompt changes and threshold moves treated as changes, with the approval trail that implies.
Vendor and sub-service CC9 - carve-out or inclusive
Providers assessed and monitored, and the carve-out or inclusive decision made deliberately and reflected in the description.
Evidence across the period Type II - not collectable later
A collection plan running for the whole window, because a Type II tests operation over time and a period cannot be backfilled.
Readiness opinion Ours - not the attestation
A findings list with severity and owner, written so your audit firm can start from it rather than discover it during fieldwork.
The engagement

Readiness, independently read

From the login screen to the training pipeline.

  1. Intake

    What is inside the boundary, and which categories you are electing.

  2. Test

    Every control against its criterion, and against what actually happens.

  3. Sign off and hand over

    You see the draft first. Then the gap list and the evidence pack - for your auditor.

Request your review
An auditor in a dark navy shirt and trousers, wearing a wristwatch, standing against a warm pale wall and pointing into the open space alongside.
A control that leaves no record did not operate, as far as a sample can tell.
Struck in your favour

Why teams choose iDharma for the read before the audit

We cannot audit you

Which is the point. We take no fee from an audit firm and issue no opinion on our own work.

Written to the criterion

Every finding names the criterion it sits under, so your auditor can start where we stopped.

Evidence, not intentions

We test whether a control leaves a record on its own - which is what a sample will look for.

The model is in scope

A model in the data path is inside the boundary, and we read the pipeline as part of the system.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

SOC 2 readiness report

The full review against the Trust Services Criteria: what would survive fieldwork today, what would raise an exception, and what is not yet a control at all - findings by criterion, graded by how a sample would land on them, with the boundary and the AI in the data path read as part of the system. A readiness opinion, not an attestation.

Document

System description pack

The boundary written down - systems, models, training pipelines, inference paths and the vendors behind them, with the exclusions argued.

Workbook

Control matrix

Every control against the criterion it satisfies and the record it generates, so a gap shows up as an empty cell rather than as a surprise.

Workbook

Evidence collection plan

What to capture, how often and where it lands, running from the first day of the window - because a closed period cannot be reconstructed.

Templates

Access review pack

Provisioning, deprovisioning and periodic review - including access to training data and model artefacts, which is where samples land.

Memo

Vendor and carve-out memo

Sub-service organisations identified, assessed and placed - with the carve-out or inclusive decision argued rather than defaulted into.

Ranked

Gap list for your auditor

Findings with severity, owner and a date, ordered by how a sample would land - written to be handed straight to the firm doing the fieldwork.

Format & fee

Real numbers, upfront.

Scope
Your boundary, agreed first
Not included
The attestation - a CPA firm’s
Re-review
Before each new period - $10,500 against your known baseline

The boundary is agreed before anything is charged - your audit firm bills you separately, and we take nothing.

Request this review
SOC 2 · Readiness engagement $12,500 flat
  • System description and boundary
  • Control matrix, criterion by criterion
  • Evidence plan for the whole period
  • Gap list your auditor can start from
Show your hand

Four things fieldwork will ask you to produce

A sample does not care what you intended. Each of these is either in the folder on the day they ask, or it is an exception.

The boundary,
set

A line somebody decided rather than inherited, saying what is outside as clearly as what is in. Every test in the report is a test of the description it produces.

The evidence,
dated

Records generated across the whole observation window. A Type II tests operation over time, and a period that has already closed cannot be backfilled later.

The failures,
owned

The failures you found yourself, with the fix and its date beside each one. An exception you raised yourself reads very differently from one that a sample turned up.

The vendors,
placed

Sub-service organisations named, and the carve-out or inclusive decision taken deliberately - not discovered halfway through somebody else's fieldwork.

Four cards, and the second one is the one you cannot go back for.

FAQ

Plain answers

What it is, who signs it, the boundary, timing. Answered straight.

Request this review
Is SOC 2 a certification?

No. It is an attestation - an opinion from a licensed CPA firm on whether your controls were suitably designed and, in a Type II, operated effectively across a period. There is no certificate and no pass mark.

What is the difference between Type I and Type II?

Type I asks whether controls were suitably designed as at one date. Type II asks whether they operated effectively across a period - and the period is the entire difficulty, because it cannot be backfilled.

Can you be our auditor?

No. A SOC 2 is issued by a licensed CPA firm and we are not one. The same firm cannot both prepare you and issue an independent opinion on your preparation - a provider offering both is selling you something the standard does not permit.

Does our model have to be in the boundary?

If it is in the data path, it is inside the system - and leaving it out is a decision your system description has to survive. Excluding it is possible; excluding it quietly is not.

How long does a readiness review take?

Typically four to six weeks from hand-over, longer where the boundary turns out to be wider than expected - which it usually does once the AI pipeline is in scope. Scope is agreed before anything is charged.

Get started

Request your readiness review

Tell us what is in the boundary and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have, and nothing we cannot work around if a piece of it is missing - the state of the first two items is usually the finding not the obstacle.

  1. An architecture diagram, however out of date it is
  2. Your control set and policies, in whatever state
  3. Which categories you intend to elect beyond Security
  4. Whether a model touches customer data, and whose it is
  5. Your target period, and whether a deal is waiting on it

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request your readiness review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • AICPA Trust Services Criteria
  • The AICPA guide for service organisations
Type I
One point in time Controls suitably designed, as at a stated date
Type II
Across a period And the controls operated effectively throughout

What it means

  • General information about what the Trust Services Criteria ask — not accounting or legal advice, and no professional relationship.
  • Where a boundary or an election is genuinely arguable, our reports say so rather than pick the convenient answer.

Scope & limitation

  • Observation-period convention and bridge-letter practice vary by audit firm and are not settled by the criteria. Confirm both with the firm that will sign.
  • We are not a licensed CPA firm and issue no attestation. Use this as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us