Assessments & SOC 2
Find out where you actually stand, then fix what matters first, whether the yardstick is SOC 2, NIST CSF or your own objectives.
Is this you?
- A customer’s security questionnaire asked for a SOC 2 report you do not have yet.
- You spend on security but cannot say what it buys you.
- New leadership, an acquisition or an incident means you need an honest baseline.
- You are about to buy a security product and want an independent opinion first.
What you get
- A gap assessment against the framework that matters to you: SOC 2, NIST CSF 2.0, CMMC or your own objectives
- A prioritized remediation roadmap with owners, effort and cost
- SOC 2 readiness: scoping, control design, policies and evidence collection
- Support through the audit, working alongside your CPA firm
- Budget right-sizing: your tools, people and contracts measured against your objectives
- Independent verification and validation (IV&V) of security technology before you buy it
How it works
-
Step 1: Frame
Agree on the yardstick and the decisions the assessment has to support.
-
Step 2: Assess
Interviews, configuration reviews and evidence sampling.
-
Step 3: Prioritize
Findings ranked by risk and effort, written in plain language.
-
Step 4: Close
Fix, document and get ready for the auditor or the board.
Every step follows Cyber BAMCIS, our planning method.
Related work
-
Global connectivity provider
CMMC gap assessment, expanded to SOC 2
A CMMC gap assessment across five global locations and a Google Cloud, AWS and Google Workspace estate, expanded to add SOC 2 Type 2 readiness.
-
State government
An endpoint security rollout across 25 agencies
Rollout planning and tracking for 60,000 endpoints moving to a new endpoint detection and response platform, agency by agency.
Questions
Can you perform our SOC 2 audit?
No. SOC 2 reports are issued by independent CPA firms. We get you ready for the audit and support you while it happens.
Type 1 or Type 2?
A Type 1 report looks at whether your controls are designed properly at a point in time. A Type 2 report tests whether they operated effectively over a period, usually several months. Most customers eventually ask for Type 2.
What does budget right-sizing involve?
We inventory your security tools, staff and contracts, map them to your objectives, and show where money is duplicated, missing or pointed at the wrong risk.
Other services
-
CMMC and NIST 800-171
A prime contractor is asking about CMMC.
Explore CMMC readiness -
Virtual CISO
You need a CISO, not a full-time hire.
Explore Virtual CISO -
Zero Trust and cloud
Your network outgrew its perimeter.
Explore Zero Trust & cloud security
Tell us what’s driving the deadline
One short call is enough to know whether we’re the right fit and what the work would take.