SOC 2 Consulting: Audit Readiness, Structured and on Schedule

If you sell B2B software or infrastructure, the question arrives sooner or later: “Do you have a SOC 2 report?” We take you from the first gap assessment to a passed audit — structured, on schedule, and with controls that hold up under examination by a licensed CPA firm.

45 minutes, no obligation — we assess your SOC 2 readiness.

What SOC 2 actually is – a report, not a certificate

SOC 2 (Service Organization Control 2) is an auditing standard defined by the AICPA, the American Institute of Certified Public Accountants. It assesses whether a service organisation protects customer data reliably.

Unlike ISO 27001, SOC 2 does not end with a certificate. It ends with an attestation report issued by an independent Certified Public Accountant. The report documents whether your internal controls are suitably designed and – in the case of Type II – whether they operated effectively across a defined observation period.

For enterprise buyers, investors and partners in international supply chains, that report has become a de-facto requirement.

Who needs SOC 2 consulting

SOC 2 becomes relevant the moment you process data on behalf of customers or hold access to their systems. Three groups feel it first:

  • SaaS vendors hit the wall at the enterprise deal. Procurement teams request the SOC 2 report as a standard step in vendor risk management, before a contract is signed.
  • Cloud providers and managed service providers have to demonstrate that multi-tenant infrastructure meets security, availability and confidentiality requirements – consistently, across every customer environment, and in a way that can be re-tested.
  • IT service providers with access to customer networks, data or applications face heterogeneous environments and few standard processes. SOC 2 forces a single, defensible security baseline.

In short: if you serve US customers, plan a US market entry, or operate in a regulated vertical – fintech, healthtech, HR software – SOC 2 is not a nice-to-have. It is a condition for growth.

What we deliver – from readiness to the audit

We run SOC 2 engagements end to end, not in fragments. Four blocks, individually or as a package:

ServiceWhat you get
Readiness assessmentScope and Trust Services Criteria definition, gap analysis against the criteria, prioritised gap list with effort estimates and a timeline
Preparation and implementationControl design, policies and procedure documentation, evidence pipeline, ownership mapping (RACI)
Ongoing supportGuidance through the Type II observation period: keeping controls operating, collecting evidence continuously, correcting deviations early
Auditor coordinationSelecting and onboarding the CPA firm, managing evidence requests, supporting audit interviews, working through findings

SOC 2 is our most specialised service line. We have completed SOC 2 engagements, currently support further clients through Type I and Type II, and work with two dedicated SOC 2 specialists – backed by our practice from more than 50 ISO 27001 and TISAX® projects.

One boundary matters: we are advisors, not your auditor. Only a US-licensed CPA firm may issue the report. Our job is to make you audit-ready.

The five Trust Services Criteria

SOC 2 is built on the Trust Services Criteria defined by the AICPA. Only Security is mandatory in every audit; the remaining four are selected based on your business model and what your customers ask for:

  • Security (mandatory): protection against unauthorised access to systems and data – covering multi-factor authentication, access control and logging.
  • Availability: systems and services are available as committed in your SLAs – relevant for cloud and hosting providers.
  • Processing Integrity: processing is complete, accurate and timely – particularly relevant for fintech and payment platforms.
  • Confidentiality: confidential information is disclosed only to authorised parties and protected appropriately.
  • Privacy: personal data is handled in line with stated notice and consent – the natural bridge to GDPR.

A typical SaaS combination is Security plus Availability. Companies handling health or HR data add Privacy. Every additional criterion increases audit effort, which is why scope definition at project start decides most of your cost.

SOC 2 Type I vs Type II

Type II is the more meaningful evidence and what enterprise buyers usually expect. Type I works as a fast first step or a bridge.

AspectSOC 2 Type ISOC 2 Type II
Point of assessmentSingle date – a snapshotObservation period of 3–12 months
FocusAre the controls suitably designed?Did the controls operate effectively throughout?
Evidential weightLimited – no proof of security in practiceHigh – operating effectiveness demonstrated over time
EffortLower (2–4 months of preparation)Higher (6–12 months incl. observation period)
Use caseFirst evidence, urgent market requirementEnterprise sales, mature security organisation
CostLowerSubstantially higher (audit plus longer preparation)

Many companies start with Type I and move to Type II after a year, once controls are operating routinely. Which one fits your situation is something we work out in the first call, based on your current maturity and what your customers are asking for.

How a SOC 2 engagement runs

Six phases that build on each other:

  1. Kick-off and scoping: which systems, services and processes fall inside the audit, and which Trust Services Criteria apply?
  2. Gap analysis: current control level against SOC 2 requirements. Output is a prioritised gap list.
  3. Risk assessment and control objectives: identifying material risks and mapping the required controls per criterion.
  4. Control implementation: technical measures (MFA, logging, vulnerability management) and organisational processes (policies, ownership, training).
  5. Documentation and evidence: policies, procedures and evidence of control execution – auditable and complete.
  6. Audit preparation and support: readiness check, closing remaining gaps, coordination with the CPA firm throughout the external audit.

From our project experience, the biggest delays rarely come from technology. They come from phase 5: companies consistently underestimate how much work complete, auditable documentation actually is – while technical controls tend to be in place faster than planned.

What SOC 2 costs

Total cost breaks into four blocks. The table gives realistic ranges for the European market:

Cost typeDescriptionTypical range
External consultingGap analysis, control design, documentation, audit support€15,000–50,000
Audit fee (CPA firm)Fee for the SOC 2 report itselffrom €15,000
Internal effortYour own team’s time for implementation, interviews, evidence20–80 person-days
ToolingGRC platforms, log management, monitoring€3,000–15,000 p.a.

For a mid-sized SaaS company (50–200 employees, scope: Security + Availability), a first Type II audit realistically lands between €45,000 and €120,000 one-off, plus annual follow-up audits. Companies already certified to ISO 27001 reduce the consulting effort considerably, since many controls carry over directly.

What SOC 2 consulting costs at 360 Digital Transformation

ServiceScopePrice
SOC 2 readiness assessmentScope, criteria selection, gap analysis, prioritised action plan with timelineFixed price €7,500
SOC 2 Type I preparationControl design, documentation, audit preparation (3–5 months)from €24,000
SOC 2 Type II preparationAs Type I, plus support through the observation period (9–14 months)from €42,000

All prices excl. VAT. The CPA firm’s audit fee (from €15,000) is not included – it is billed directly between you and the auditor. The readiness assessment is credited in full against a follow-on engagement.

45 minutes, no obligation – we assess your SOC 2 readiness and name the three biggest levers.

How long SOC 2 takes

A SOC 2 Type I project usually runs 3–5 months from gap analysis to report. Type II takes 9–14 months, because the observation period alone requires at least six months of evidence. What moves the timeline:

  • Security maturity: companies with documented processes and existing controls (an ISO 27001 base, for instance) start considerably faster.
  • Scope width: more criteria and more systems mean more preparation.
  • Internal capacity: availability of your people for interviews, policy work and evidence is the most common bottleneck.
  • Documentation state: missing or outdated policies routinely add 4–8 weeks.

With an experienced partner and a clear structure the timeline usually holds – provided internal stakeholders are involved from the start. Where internal capacity is missing, a virtual CISO can run the project for you.

Where SOC 2 projects go wrong

Failed and delayed SOC 2 projects share the same causes:

  • Audit panic instead of continuous compliance: controls implemented shortly before the audit will not survive a Type II examination. SOC 2 has to be lived, not staged.
  • Unclear scope: broad system boundaries increase cost and effort disproportionately. A precise scope at the start saves weeks later.
  • Missing documentation: controls exist but cannot be traced. Auditors do not accept verbal assurances – everything has to be evidenced.
  • Underestimated third-party risk: subprocessors – cloud infrastructure, payment providers – are part of the scope. No SOC 2 reports from your own vendors mean findings.
  • No ownership: where it is unclear who maintains a control internally, gaps appear that surface in the audit.

In our projects the last point is the most common stumbling block. Technical controls are usually in place, but in the audit interview nobody can say clearly who keeps them running. A simple RACI matrix before the audit kick-off prevents most of these findings.

SOC 2 vs ISO 27001

Both pursue similar goals but differ fundamentally in format, geography and audience:

CriterionSOC 2ISO 27001
Issued byAICPA (USA)ISO / IEC (international)
EvidenceAttestation reportCertificate
Geographic focusUSA, internationally recognisedGlobal standard
AudienceProviders with US customersCompanies in any sector
Validity~12 months in practice3 years, then recertification
AssessorLicensed CPA firmAccredited certification body

Many European companies run both: ISO 27001 as the internal management system and the basis of the ISMS, SOC 2 as external evidence for international and US business. Because the two overlap heavily in access control, risk management and documentation, the incremental effort pays back quickly. If you already hold ISO 27001, you are well positioned for SOC 2 – we documented what such a project looks like in practice using our own certification.

SOC 2 vs BSI C5, ISAE 3402 and IDW PS 980

If your customers include German enterprises or public sector bodies, SOC 2 is not the only framework you will be asked about. The German counterpart is BSI C5, published by the German Federal Office for Information Security:

CriterionSOC 2BSI C5ISAE 3402 / IDW PS 980
Issued byAICPA (USA)BSI (Germany)IAASB / IDW
FocusSecurity, availability, privacyCloud security specificallyInternal controls at service organisations
AudienceProviders with US customersCloud providers in the German marketOutsourcing providers, data centres
Report typeSOC 2 report (Type I / II)Attestation reportISAE 3402 / PS 980 report
Relevance in DACHHigh (US and international customers)Very high (public sector, critical infrastructure)High (financial sector, outsourcing)

Rule of thumb: serving primarily US or international enterprise customers means SOC 2. Providing cloud services to German public authorities, critical infrastructure or healthcare means BSI C5. Financial services and data centres under German outsourcing arrangements are better served by ISAE 3402 or IDW PS 980.

“In practice the either-or logic is the exception. Many companies in this market need both standards in parallel – a SaaS vendor serving German authorities and US enterprise customers at the same time, for example.”
— Can Adigüzel, ISO 27001 Lead Auditor, more than 200 audits

SOC 2 and BSI C5 overlap by roughly 60–70% in core areas such as access management, logging and incident response. Planning both from the start avoids duplicated documentation and keeps the incremental effort for the second framework manageable. The same logic applies to TISAX®: one control set, several forms of evidence.

SOC 2 checklist: what to prepare before the audit

Use this before your first consultation. Every open item is a concrete task we prioritise together in the gap analysis.

  • Scope defined: all relevant systems, services and subprocessors are documented
  • Criteria selected: the applicable Trust Services Criteria are chosen and justified
  • Risk assessment done: risks identified, evaluated and mapped to controls
  • Policies in place: information security policy, access control policy, incident response plan – current and versioned
  • Access controls implemented: MFA enabled, role-based permissions, regular access reviews
  • Logging and monitoring active: system access, incidents and changes are logged completely
  • Third-party management: SOC 2 reports or equivalent evidence available for all relevant subprocessors
  • Incident response tested: plan documented, ownership clear, at least one scenario exercised
  • Training evidenced: security awareness training delivered, documented and current
  • Evidence complete: every control backed by artefacts – logs, screenshots, records – and retrievable
  • Ownership assigned: for every control it is clear who runs it, who reviews it and who owns it

Ready for the next step?

SOC 2 projects rarely fail on technology. They fail on missing structure and a late start. In a 45-minute intro call we assess your current SOC 2 readiness and show you which three measures give you the most leverage.

Frequently asked questions about SOC 2 consulting

  • Is SOC 2 legally required in Europe?

    No. SOC 2 is a voluntary attestation standard. In practice it has become a de-facto requirement – particularly in vendor risk management at large US and international customers, and in regulated industries.

  • Who is allowed to perform a SOC 2 audit?

    Only US-licensed public accounting firms (CPA firms) operating under AICPA standards. Advisors such as us prepare your organisation – the report itself is issued solely by the independent auditor.

  • How does SOC 2 differ from ISO 27001?

    ISO 27001 is an internationally recognised certification for information security management systems. SOC 2 produces a detailed report on the effectiveness of specific controls. They complement each other: ISO 27001 as the management system foundation, SOC 2 as external evidence for international customers.

  • Can startups achieve SOC 2?

    Yes. What matters is process maturity, not headcount. Many startups deliberately start early with Type I to win enterprise deals. A realistically limited scope keeps the effort proportionate.

  • How long is a SOC 2 report valid?

    There is no formal expiry. In practice, customers expect a current report covering the last 12 months. An outdated report quickly loses acceptance in procurement.

  • What are the most common mistakes in SOC 2 preparation?

    Incomplete documentation, missing access controls, unclear ownership, underestimated third-party risk, and preparation started too close to the audit. Type II requires continuous compliance – not a one-off implementation.

360 Digitale Transformation
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.