SOC 2 · READINESS REVIEW · BEFORE THE AUDIT

A compliance platform is not a SOC 2 report.

Enterprise buyers ask for the report, not the dashboard - and only a licensed CPA firm can sign one, after the evidence is real.


A man in a dark shirt sitting at a dark stone table beside a window, pen in hand, reading a set of printed sheets laid out in front of him with a pale stoneware cup at his elbow.
Independent means no stake in the answer
Trust criteria Type II CC1-CC9 Evidence window CPA opinion

Our promise

“A badge is a logo. The control test is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $12,500, and nothing is charged until you approve it.

Each additional system
$3,000
Re-audit, same scope
$8,000
Renewal, every twelve months
$10,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework readiness assessment produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this readiness assessment
The case file

SOC 2 for startups, in three chapters

The Report

A licensed CPA firm's opinion on the controls you run, tested against the AICPA Trust Services Criteria. It is not a certificate and not a badge but a document with a scope, a period and a signature, which is why an enterprise security team asks for it by name and not by brand.

The Gap

Most teams buy a platform and assume the hard part is done. It is not. Tooling collects the evidence, and an auditor tests whether the control actually ran. A dashboard reading green is evidence that a dashboard is green, and that distinction is where most first audits come unstuck.

The Office

Our review is the independent read, and it happens before the audit. We scope the categories, read every control against the criterion it answers, examine what the evidence actually shows, and hand you the matrix and the gap list, so your CPA firm is not the first party to find any of them.

Trust services categories

Five categories. One is compulsory.

You are audited against what you actually promised, not against all five.

The one you cannot skip № 01
  • Security - the common criteria, in every SOC 2 report
  • CC1 environment, CC2 information, CC3 risk assessment
  • CC4 monitoring, CC5 control activities, CC6 access
  • CC7 operations, CC8 change management, CC9 vendors
SOC 2 · iDharma · Presented for assay
The four you opt into № 02
  • Availability - if you have promised uptime or recovery
  • Processing Integrity - if you process data for a customer
  • Confidentiality - if you promised more than security does
  • Privacy - if you handle personal data against a notice
SOC 2 · iDharma · Presented for assay
Know your half

The evidence is yours. The opinion is theirs.

Your side

The evidence is yours to produce

Controls have to exist, run, and leave a trace that someone outside your company can follow and check for themselves. No platform and no auditor can make a control that was never actually operating produce a record saying that it was. This is the half that nobody, at any price, can do on your behalf.

Your CPA firm

The opinion is theirs to sign

A SOC 2 report is an attestation under SSAE 18, and only a licensed CPA firm can issue one. They test the controls you run and state an opinion on them. Choosing that firm early is worth far more than most teams expect: they will tell you, before you build anything, exactly what they will and will not accept.

The catch

Automation is not attestation

A platform pulling screenshots on a nightly basis is a good way to hold evidence and no way at all to have an opinion. A green dashboard is evidence that a dashboard is green, and nothing else at all. What an auditor tests is whether the control itself really ran, and what it left behind when it did.

What most teams assume

“We bought the platform, so we’re SOC 2.”

What the standard says

Platforms hold evidence. A CPA firm signs.

It is the most common finding we write up.

  • Who it is for
  • Seed & Series A SaaS
  • Fintech & payments
  • Health tech
  • Dev tools & infrastructure
  • AI product teams
Why it pays
A kraft document envelope on a dark grey surface, closed with a string-and-button fastener and stamped CONFIDENTIAL in red above the line FOR AUTHORIZED PERSONNEL ONLY: the sealed report a security review asks to be sent.
01 Enterprise security reviews ask for the report by name. Without one the deal does not fail, it stalls - and it stalls at the stage where you have already spent the sales effort.
02

Investor diligence asks the same questions a buyer's security team does, and asks them again at every round. A report answers both.

03

A questionnaire answered from a report takes an afternoon. Answered from memory it takes a fortnight, and it is answered differently each time.

04

The controls are worth more than the report. Access reviews and change management are cheap at twenty people and expensive at two hundred.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. A starting point, not a determination.

0 of 3

Asked for -

The trigger is commercial, not regulatory. No law requires a SOC 2. What requires one is a buyer's security review, a procurement questionnaire, or an investor's diligence.

Beyond security -

Your commitments decide your scope. Security is in every report. The other four categories are added because of something you undertook in a contract, an SLA or a published notice.

Evidence -

Collected is not the same as reviewed. An auditor tests whether the control ran and what it left behind — not whether a tool was configured to watch for it.

The route

Four stages, and one of them cannot be hurried.

Three of these move faster if you spend more on them. The third does not - it is a period, and a period takes the time it takes.

  1. Readiness

    Week zero

    An independent read of what you actually run, against the criteria - before a CPA firm is engaged at all.

  2. Remediate

    Weeks 1-8

    The gaps get closed and the controls start running. Nothing in here can be hurried by paying more for it.

  3. Observe

    3-12 months

    The Type II window. The report describes this period, and this period cannot be created after the fact.

  4. Renew

    Every 12 months

    Reports cover a stated period and buyers read the dates. A lapsed one is a gap in your own timeline.

The trap

Teams book the audit for a date the customer gave them and discover the observation window has not started. A Type II describes a period that has already happened - and no fee, and no auditor, can create one backwards.

Requirement & coverage

What the criteria ask, what we ship

12 requirements, and the artefact that answers each one. Paired, so every claim on this page can be checked against the requirement beside it.

Which report you need Type I is design; Type II is operation over a period
A written recommendation of type and window, with what each one will and will not answer for a buyer.
Which categories are in scope Security always; the other four only if you committed
Your public commitments read against the categories, so you are not audited on a promise you never made.
Control environment CC1 - governance, accountability, competence
Who owns security, what they are accountable for, and the evidence that it is more than an org chart.
Communication and information CC2 - policies that reach the people bound by them
Policies checked for existence, approval and reach - a policy nobody has read is a finding, not a control.
Risk assessment CC3 - identified, rated, and revisited
A risk process you can actually run, not a register written the week before the auditor arrives.
Monitoring activities CC4 - who checks that the checks happened
The review cadence, with proof that reviews took place and that somebody acted when one of them failed.
Control activities CC5 - the controls that actually run
A control matrix: each control, the criterion it answers, its owner, its frequency and its evidence.
Logical and physical access CC6 - joiners, movers, leavers, keys and secrets
Access reviewed against reality - the accounts that exist, not the ones the offboarding doc says exist.
System operations CC7 - detection, incidents, and what happened next
Monitoring and incident response tested against a real incident, or the absence of one accounted for.
Change management CC8 - authorised, tested, traceable
Your deploy pipeline read as a control: what stops an unreviewed change reaching production, and when it did not.
Risk mitigation CC9 - vendors, and what happens when one fails
The subservice organisations named, their reports read, and the controls you are carving out identified.
The evidence window Type II describes a period, and periods are not backdated
Whether your evidence actually spans the window you intend to claim - checked before the window is set.
The engagement

Your controls, independently read

Before the CPA firm, not instead of them.

  1. Scope

    Which categories you have actually committed to, and which systems carry them.

  2. Test

    Every control read against the criterion it answers, and against what it produced.

  3. Sign off and hand over

    You see the draft first. Then the matrix, the gaps and the evidence index - dated.

Request your readiness review
An assessor in a navy suit and open-collared white shirt, standing against a warm pale wall and pointing into the open space alongside.
The gap list is what you are buying.
Struck in your favour

Why teams choose iDharma to read them before the audit

Genuinely independent

We sell no compliance platform and no tooling, and take no fee tied to what we find.

Written to the criteria

Every finding maps to the criterion it answers, so your CPA firm can follow the reasoning.

One engagement, end to end

Scope, controls, evidence and gaps sit in one pass, so nothing falls between two vendors.

Evidence before adjectives

What a control actually produced gets read before anything on this page calls it working.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Readiness report

The full assessment in one document: every control read against the trust services criterion it answers, the evidence behind each one examined rather than assumed, the gaps named with what closing them actually requires, and a recommendation on report type and window - written in plain language rather than the standard's.

Workbook

Control matrix

Every control, the criterion it answers, its owner, its frequency and its evidence - in a workbook your team can keep current after we go.

Register

Evidence index

What exists, where it lives, and which criterion it answers - so the auditor is not the first person to go looking for any of it.

Templates

Policy gap list

Which policies the criteria expect, what you already hold, what is thin, and what is missing - with the approval trail each one needs.

Memo

Scope memo

Which categories and systems were in scope, which were not, and why each call was made - the written record behind your report boundary.

Ranked

Remediation shortlist

Where the gaps sit, what to do first, and why each one is where it is. Ranked by what would actually fail an audit, not by ease of fixing.

Memo

Auditor-readiness memo

What your CPA firm will ask for on day one, what you can answer today, and what would currently come back as an exception.

Format & fee

Real numbers, upfront.

Scope
Set by the criteria, not by us
Input
Your controls and what they produced
Re-read
Annually, or on material change - $10,500 against your known baseline

The criteria fixed the scope - the fee is flat, nothing to meter, and nothing charged until you approve.

Request your review
SOC 2 · Readiness review $12,500 flat
  • Independent readiness report
  • Control matrix, criterion by criterion
  • Evidence index and gap list
  • Auditor-readiness memo included
Show your hand

Four things you have to be able to produce

An auditor is not grading intent. Each of these is either in your hand on the day they ask for it, or it is not.

The scope,
settled

Which categories the report covers and which systems sit inside it, written down before testing starts. Scope decided late is scope decided by whoever asks the loudest question.

The controls,
described

Each control named, mapped to the criterion it answers, with an owner and a frequency. A control nobody owns is a sentence in a document, and it will be tested as one.

The evidence,
dated

What each control actually produced, across the whole window rather than the week before the auditor arrived. A Type II is a claim about a period, and the dates are the claim.

The exceptions,
owned

The controls that did not run, and what was done about them. Auditors expect exceptions; what they judge is whether you found yours first or waited to be shown them.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Scope, timing, and what the report is actually worth.

Request your review
We bought a compliance platform. Is that enough?

No. A platform collects evidence; it does not issue an opinion. Only a licensed CPA firm can do that, and what they test is whether the control ran - not whether a dashboard said it did.

Which trust services categories do we need?

Security is in every SOC 2 and is not optional. Availability, Processing Integrity, Confidentiality and Privacy are added only where you have made commitments that call for them - adding one you have not buys audit scope and nothing else.

Type I or Type II - which do we need?

Buyers want Type II. Type I says the controls were designed properly on one day; Type II says they actually operated across a period. A Type I is a reasonable staging post, and it is not what closes the deal.

How long does a SOC 2 actually take?

Readiness and remediation run weeks; the Type II observation window is three to twelve months and cannot be shortened by paying more. Plan backwards from the date a buyer needs the report in hand.

Does our ISO 27001 already cover this?

They overlap heavily but are not interchangeable. ISO 27001 certifies a management system against a standard; SOC 2 is a CPA firm's opinion on your controls. A buyer asking for one rarely accepts the other.

Get started

Request your readiness review

Tell us what you run and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.

  1. What you run, and who it serves
  2. Whatever policies exist, however rough
  3. How access and changes are handled today
  4. What you have promised customers in writing
  5. The date a buyer needs the report, if there is one

What happens next

  1. You send the five items we need.
  2. You get a scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request your readiness review
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • AICPA Trust Services Criteria
  • SSAE 18 - AT-C sections 105 and 205
Criteria issued
2017, revised 2022
Signed by
A licensed CPA firm

What it means

  • General information about what the Trust Services Criteria ask for — not an attestation, not legal advice, and no professional relationship arises from reading it.
  • Where a scoping question is arguable, our reports say so rather than the convenient thing.

Scope & limitation

  • iDharma is not a CPA firm and issues no SOC 2 report. We run the readiness review.
  • It covers SOC 2 alone - ISO 27001, HIPAA and GDPR can reach the same systems.
  • Use it as a starting point for a scoping conversation, not as your final word.

Something on this page out of date?

Tell us