SOC 2 and ISO 27001 readiness
The usual trigger is not a regulator. It is an enterprise deal that has stopped moving, a procurement portal with a mandatory field, or an investor asking a question the last round did not. Whatever started it, the clock is now somebody else’s.
The short version: readiness is the preparation, not the examination
Two different pieces of work are involved, done by two different parties, and this page separates them everywhere because conflating them is how organizations end up surprised at the worst moment.
Readiness is scoping, gap assessment, evidence architecture, policy work and remediation. It is what you do so that the examination is uneventful. The examination itself is performed by an independent party, and the report or the certificate comes from them. That party is never this practice, and cannot be: the whole value of their opinion rests on their independence from whoever prepared you.
Who issues what
| Outcome | Who produces it | What readiness work does |
|---|---|---|
| SOC 2 report | A CPA firm, following an examination under the AICPA’s standards | Prepares the scope, the controls and the evidence, and supports you through the examination |
| ISO/IEC 27001 certificate | One of the accredited certification bodies, after its own assessment | Builds the management system and the records the body will ask to see |
The AICPA describes System and Organization Controls as a suite of service offerings CPAs may provide in connection with system-level controls of a service organization or entity-level controls of other organizations. ISO/IEC 27001 is published by ISO and the IEC; no clause content is reproduced here, because the standard is theirs to publish and yours to buy.
Scoping: the decisions that change everything downstream
Scope is the cheapest thing to get right and the most expensive thing to get wrong, because every later cost scales with it. The decisions that matter most:
- Which system — the product your customers are asking about, or everything the organization runs. Broader is not better; it is slower, and a report covering a system nobody asked about answers nobody’s question.
- Which criteria — for SOC 2, security is always in, and availability, confidentiality, processing integrity and privacy are each a decision with its own evidence burden. Add one because a customer asked, not because it looked thorough.
- Which type — a Type 1 report describes the design of controls at a point in time; a Type 2 covers their operation across a period. Buyers increasingly want the second, which means the observation period is on the critical path and has to be started deliberately.
- Which boundary — what is carved out to subservice organizations, and what your customers will therefore have to assess themselves.
Choosing between the two frameworks, or doing both, is compared at length in SOC 2 versus ISO 27001.
Control-by-control gap assessment
Each control in scope is assessed on three questions rather than one: is there a stated intent, is the practice actually performed, and is there an artifact that demonstrates it was performed. Most organizations score well on the first, unevenly on the second and badly on the third — and the third is the one an examination turns on.
The output is a register with a status per control, the evidence that exists today, the evidence that is missing, and what has to change. Where a control is met by something you already do under a different name, it is recorded as met rather than rebuilt, which is where a good deal of the saving comes from.
Evidence architecture: producing evidence as a by-product
The failure pattern is familiar. Controls are designed, everyone agrees they are sensible, and then four weeks before the examination somebody spends their nights reconstructing twelve months of access reviews from memory. That evidence is weak, its production is miserable, and the same scramble repeats every year.
Evidence architecture designs the other way round: the control is performed through a system that records it, so the artifact exists because the work happened. Access reviews that generate a dated record. Change approvals that live in the tool that performs the change. Onboarding and offboarding checklists that leave a trail. An immutable audit log where the event matters and the application must not be able to rewrite it. Done this way, being ready for an audit stops being an annual project and becomes a property of how the organization works.
What that assembled evidence looks like when a customer asks for it is described in the evidence pack, and the written style of the assessment itself is shown in the sample report.
Policy set, written to be followed
Policies are the most commonly downloaded and least commonly read artifact in this field. A borrowed set describes an organization that does not exist, and the gap between the document and the practice is exactly what an examination surfaces.
The set written here is sized to the organization, names roles that exist, describes practices that are actually performed, and states review responsibility and cadence. Where a policy would describe something you have decided not to do, it says so rather than asserting a control you do not have.
Remediation, sequenced
Sequencing is where readiness engagements are won or lost. Items that require an observation period go first, because they gate the date. Items that unlock other items go next. Items that are expensive and cosmetic go last, or are recorded as a deliberate decision not to do them.
Where the date is fixed by a customer commitment, the plan states plainly what is achievable by then and what is not, rather than producing a plan that is arithmetically impossible and discovering it in month five.
Through the examination itself
Support continues into the examination: preparing the evidence request responses, walking through the control narratives, and handling the questions that come back. The independent party runs their own process and reaches their own conclusions; the role here is to make sure they get accurate answers quickly and that nothing lands as a surprise.
Frameworks driven by a contract or a regulator rather than by a sales cycle — payment card, health information, defence procurement — are covered on PCI DSS, HIPAA and CPCSC readiness, and the wider section index is compliance and privacy.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Can you issue our SOC 2 report?
No. A SOC 2 report is issued by a CPA firm after an examination, and the work here prepares an organization for that examination rather than performing it. A firm that offers to prepare you and then to examine you is offering something the independence rules exist to prevent, and a buyer who reads carefully will notice.
Can you issue our ISO/IEC 27001 certificate?
No. An ISO/IEC 27001 certificate is issued by an accredited certification body after its own assessment of your management system, and readiness work is what you do beforehand. Choosing that body, and scoping what they will assess, is part of the readiness work.
How long does readiness take?
Readiness commonly runs three to nine months, and the pace is set by how long remediation takes and how long an observation period has to run, not by the gap assessment. If a customer has given you a date, the first useful output is an honest statement of whether that date is reachable.
Do we need a penetration test for either?
Neither framework hands you a line item that says buy a penetration test. What is asked for is evidence that weaknesses are found and fixed, and testing is the usual way organizations produce it.
In practice most organizations buy penetration testing during readiness, partly for the evidence and partly because finding a serious defect after the examination has started is the expensive order to do it in.
Find out what the examination would actually ask for
Describe the product, the framework being asked for and the date you are working to. The reply says what a scope and a gap assessment would cover and what you would receive.