SOC 2 Consulting: Audit Readiness, Structured and on Schedule
If you sell B2B software or infrastructure, the question arrives sooner or later: “Do you have a SOC 2 report?” We take you from the first gap assessment to a passed audit — structured, on schedule, and with controls that hold up under examination by a licensed CPA firm.
45 minutes, no obligation — we assess your SOC 2 readiness.
What SOC 2 actually is – a report, not a certificate
SOC 2 (Service Organization Control 2) is an auditing standard defined by the AICPA, the American Institute of Certified Public Accountants. It assesses whether a service organisation protects customer data reliably.
Unlike ISO 27001, SOC 2 does not end with a certificate. It ends with an attestation report issued by an independent Certified Public Accountant. The report documents whether your internal controls are suitably designed and – in the case of Type II – whether they operated effectively across a defined observation period.
For enterprise buyers, investors and partners in international supply chains, that report has become a de-facto requirement.
Who needs SOC 2 consulting
SOC 2 becomes relevant the moment you process data on behalf of customers or hold access to their systems. Three groups feel it first:
- SaaS vendors hit the wall at the enterprise deal. Procurement teams request the SOC 2 report as a standard step in vendor risk management, before a contract is signed.
- Cloud providers and managed service providers have to demonstrate that multi-tenant infrastructure meets security, availability and confidentiality requirements – consistently, across every customer environment, and in a way that can be re-tested.
- IT service providers with access to customer networks, data or applications face heterogeneous environments and few standard processes. SOC 2 forces a single, defensible security baseline.
In short: if you serve US customers, plan a US market entry, or operate in a regulated vertical – fintech, healthtech, HR software – SOC 2 is not a nice-to-have. It is a condition for growth.
What we deliver – from readiness to the audit
We run SOC 2 engagements end to end, not in fragments. Four blocks, individually or as a package:
| Service | What you get |
|---|---|
| Readiness assessment | Scope and Trust Services Criteria definition, gap analysis against the criteria, prioritised gap list with effort estimates and a timeline |
| Preparation and implementation | Control design, policies and procedure documentation, evidence pipeline, ownership mapping (RACI) |
| Ongoing support | Guidance through the Type II observation period: keeping controls operating, collecting evidence continuously, correcting deviations early |
| Auditor coordination | Selecting and onboarding the CPA firm, managing evidence requests, supporting audit interviews, working through findings |
SOC 2 is our most specialised service line. We have completed SOC 2 engagements, currently support further clients through Type I and Type II, and work with two dedicated SOC 2 specialists – backed by our practice from more than 50 ISO 27001 and TISAX® projects.
One boundary matters: we are advisors, not your auditor. Only a US-licensed CPA firm may issue the report. Our job is to make you audit-ready.
The five Trust Services Criteria
SOC 2 is built on the Trust Services Criteria defined by the AICPA. Only Security is mandatory in every audit; the remaining four are selected based on your business model and what your customers ask for:
- Security (mandatory): protection against unauthorised access to systems and data – covering multi-factor authentication, access control and logging.
- Availability: systems and services are available as committed in your SLAs – relevant for cloud and hosting providers.
- Processing Integrity: processing is complete, accurate and timely – particularly relevant for fintech and payment platforms.
- Confidentiality: confidential information is disclosed only to authorised parties and protected appropriately.
- Privacy: personal data is handled in line with stated notice and consent – the natural bridge to GDPR.
A typical SaaS combination is Security plus Availability. Companies handling health or HR data add Privacy. Every additional criterion increases audit effort, which is why scope definition at project start decides most of your cost.
SOC 2 Type I vs Type II
Type II is the more meaningful evidence and what enterprise buyers usually expect. Type I works as a fast first step or a bridge.
| Aspect | SOC 2 Type I | SOC 2 Type II |
|---|---|---|
| Point of assessment | Single date – a snapshot | Observation period of 3–12 months |
| Focus | Are the controls suitably designed? | Did the controls operate effectively throughout? |
| Evidential weight | Limited – no proof of security in practice | High – operating effectiveness demonstrated over time |
| Effort | Lower (2–4 months of preparation) | Higher (6–12 months incl. observation period) |
| Use case | First evidence, urgent market requirement | Enterprise sales, mature security organisation |
| Cost | Lower | Substantially higher (audit plus longer preparation) |
Many companies start with Type I and move to Type II after a year, once controls are operating routinely. Which one fits your situation is something we work out in the first call, based on your current maturity and what your customers are asking for.
How a SOC 2 engagement runs
Six phases that build on each other:
- Kick-off and scoping: which systems, services and processes fall inside the audit, and which Trust Services Criteria apply?
- Gap analysis: current control level against SOC 2 requirements. Output is a prioritised gap list.
- Risk assessment and control objectives: identifying material risks and mapping the required controls per criterion.
- Control implementation: technical measures (MFA, logging, vulnerability management) and organisational processes (policies, ownership, training).
- Documentation and evidence: policies, procedures and evidence of control execution – auditable and complete.
- Audit preparation and support: readiness check, closing remaining gaps, coordination with the CPA firm throughout the external audit.
From our project experience, the biggest delays rarely come from technology. They come from phase 5: companies consistently underestimate how much work complete, auditable documentation actually is – while technical controls tend to be in place faster than planned.
What SOC 2 costs
Total cost breaks into four blocks. The table gives realistic ranges for the European market:
| Cost type | Description | Typical range |
|---|---|---|
| External consulting | Gap analysis, control design, documentation, audit support | €15,000–50,000 |
| Audit fee (CPA firm) | Fee for the SOC 2 report itself | from €15,000 |
| Internal effort | Your own team’s time for implementation, interviews, evidence | 20–80 person-days |
| Tooling | GRC platforms, log management, monitoring | €3,000–15,000 p.a. |
For a mid-sized SaaS company (50–200 employees, scope: Security + Availability), a first Type II audit realistically lands between €45,000 and €120,000 one-off, plus annual follow-up audits. Companies already certified to ISO 27001 reduce the consulting effort considerably, since many controls carry over directly.
What SOC 2 consulting costs at 360 Digital Transformation
| Service | Scope | Price |
|---|---|---|
| SOC 2 readiness assessment | Scope, criteria selection, gap analysis, prioritised action plan with timeline | Fixed price €7,500 |
| SOC 2 Type I preparation | Control design, documentation, audit preparation (3–5 months) | from €24,000 |
| SOC 2 Type II preparation | As Type I, plus support through the observation period (9–14 months) | from €42,000 |
All prices excl. VAT. The CPA firm’s audit fee (from €15,000) is not included – it is billed directly between you and the auditor. The readiness assessment is credited in full against a follow-on engagement.
45 minutes, no obligation – we assess your SOC 2 readiness and name the three biggest levers.
How long SOC 2 takes
A SOC 2 Type I project usually runs 3–5 months from gap analysis to report. Type II takes 9–14 months, because the observation period alone requires at least six months of evidence. What moves the timeline:
- Security maturity: companies with documented processes and existing controls (an ISO 27001 base, for instance) start considerably faster.
- Scope width: more criteria and more systems mean more preparation.
- Internal capacity: availability of your people for interviews, policy work and evidence is the most common bottleneck.
- Documentation state: missing or outdated policies routinely add 4–8 weeks.
With an experienced partner and a clear structure the timeline usually holds – provided internal stakeholders are involved from the start. Where internal capacity is missing, a virtual CISO can run the project for you.
Where SOC 2 projects go wrong
Failed and delayed SOC 2 projects share the same causes:
- Audit panic instead of continuous compliance: controls implemented shortly before the audit will not survive a Type II examination. SOC 2 has to be lived, not staged.
- Unclear scope: broad system boundaries increase cost and effort disproportionately. A precise scope at the start saves weeks later.
- Missing documentation: controls exist but cannot be traced. Auditors do not accept verbal assurances – everything has to be evidenced.
- Underestimated third-party risk: subprocessors – cloud infrastructure, payment providers – are part of the scope. No SOC 2 reports from your own vendors mean findings.
- No ownership: where it is unclear who maintains a control internally, gaps appear that surface in the audit.
In our projects the last point is the most common stumbling block. Technical controls are usually in place, but in the audit interview nobody can say clearly who keeps them running. A simple RACI matrix before the audit kick-off prevents most of these findings.
SOC 2 vs ISO 27001
Both pursue similar goals but differ fundamentally in format, geography and audience:
| Criterion | SOC 2 | ISO 27001 |
|---|---|---|
| Issued by | AICPA (USA) | ISO / IEC (international) |
| Evidence | Attestation report | Certificate |
| Geographic focus | USA, internationally recognised | Global standard |
| Audience | Providers with US customers | Companies in any sector |
| Validity | ~12 months in practice | 3 years, then recertification |
| Assessor | Licensed CPA firm | Accredited certification body |
Many European companies run both: ISO 27001 as the internal management system and the basis of the ISMS, SOC 2 as external evidence for international and US business. Because the two overlap heavily in access control, risk management and documentation, the incremental effort pays back quickly. If you already hold ISO 27001, you are well positioned for SOC 2 – we documented what such a project looks like in practice using our own certification.
SOC 2 vs BSI C5, ISAE 3402 and IDW PS 980
If your customers include German enterprises or public sector bodies, SOC 2 is not the only framework you will be asked about. The German counterpart is BSI C5, published by the German Federal Office for Information Security:
| Criterion | SOC 2 | BSI C5 | ISAE 3402 / IDW PS 980 |
|---|---|---|---|
| Issued by | AICPA (USA) | BSI (Germany) | IAASB / IDW |
| Focus | Security, availability, privacy | Cloud security specifically | Internal controls at service organisations |
| Audience | Providers with US customers | Cloud providers in the German market | Outsourcing providers, data centres |
| Report type | SOC 2 report (Type I / II) | Attestation report | ISAE 3402 / PS 980 report |
| Relevance in DACH | High (US and international customers) | Very high (public sector, critical infrastructure) | High (financial sector, outsourcing) |
Rule of thumb: serving primarily US or international enterprise customers means SOC 2. Providing cloud services to German public authorities, critical infrastructure or healthcare means BSI C5. Financial services and data centres under German outsourcing arrangements are better served by ISAE 3402 or IDW PS 980.
“In practice the either-or logic is the exception. Many companies in this market need both standards in parallel – a SaaS vendor serving German authorities and US enterprise customers at the same time, for example.”
— Can Adigüzel, ISO 27001 Lead Auditor, more than 200 audits
SOC 2 and BSI C5 overlap by roughly 60–70% in core areas such as access management, logging and incident response. Planning both from the start avoids duplicated documentation and keeps the incremental effort for the second framework manageable. The same logic applies to TISAX®: one control set, several forms of evidence.
SOC 2 checklist: what to prepare before the audit
Use this before your first consultation. Every open item is a concrete task we prioritise together in the gap analysis.
- Scope defined: all relevant systems, services and subprocessors are documented
- Criteria selected: the applicable Trust Services Criteria are chosen and justified
- Risk assessment done: risks identified, evaluated and mapped to controls
- Policies in place: information security policy, access control policy, incident response plan – current and versioned
- Access controls implemented: MFA enabled, role-based permissions, regular access reviews
- Logging and monitoring active: system access, incidents and changes are logged completely
- Third-party management: SOC 2 reports or equivalent evidence available for all relevant subprocessors
- Incident response tested: plan documented, ownership clear, at least one scenario exercised
- Training evidenced: security awareness training delivered, documented and current
- Evidence complete: every control backed by artefacts – logs, screenshots, records – and retrievable
- Ownership assigned: for every control it is clear who runs it, who reviews it and who owns it
Ready for the next step?
SOC 2 projects rarely fail on technology. They fail on missing structure and a late start. In a 45-minute intro call we assess your current SOC 2 readiness and show you which three measures give you the most leverage.
Frequently asked questions about SOC 2 consulting
Is SOC 2 legally required in Europe?
No. SOC 2 is a voluntary attestation standard. In practice it has become a de-facto requirement – particularly in vendor risk management at large US and international customers, and in regulated industries.
Who is allowed to perform a SOC 2 audit?
Only US-licensed public accounting firms (CPA firms) operating under AICPA standards. Advisors such as us prepare your organisation – the report itself is issued solely by the independent auditor.
How does SOC 2 differ from ISO 27001?
ISO 27001 is an internationally recognised certification for information security management systems. SOC 2 produces a detailed report on the effectiveness of specific controls. They complement each other: ISO 27001 as the management system foundation, SOC 2 as external evidence for international customers.
Can startups achieve SOC 2?
Yes. What matters is process maturity, not headcount. Many startups deliberately start early with Type I to win enterprise deals. A realistically limited scope keeps the effort proportionate.
How long is a SOC 2 report valid?
There is no formal expiry. In practice, customers expect a current report covering the last 12 months. An outdated report quickly loses acceptance in procurement.
What are the most common mistakes in SOC 2 preparation?
Incomplete documentation, missing access controls, unclear ownership, underestimated third-party risk, and preparation started too close to the audit. Type II requires continuous compliance – not a one-off implementation.