Service
Compliance Readiness & Scanning
Gap assessment first, then the scanning and testing evidence your assessor asks for. We get you ready for the audit. We do not pretend the audit is the goal.
Questions we get asked
Can you be our auditor as well?
No, and nobody honest can. A SOC 2 opinion comes from a licensed CPA firm, and whoever does your readiness work is disqualified from auditing it. We get you ready and hand you to an assessor; keeping those roles separate is the whole reason the report means anything.
How long does SOC 2 readiness take?
The gap assessment is a couple of weeks. Closing the gaps is the real timeline and it depends entirely on what we find, though three to six months before a Type II observation window starts is a fair planning assumption for a company doing this the first time. Type I is faster because it is a point in time.
Does the penetration test have to be from a third party?
For PCI DSS the tester must be organisationally independent of the systems being tested, which for most companies means external. SOC 2 does not name a requirement at all; the auditor evaluates whatever the organisation committed to in its own control descriptions, and independent testing is simply the easiest way to satisfy one. Customer security questionnaires are frequently stricter than the framework.
We use a compliance automation platform already. Do we still need you?
Those platforms are good at evidence collection and terrible at judgment. They will tell you a control is not satisfied; they will not tell you that the way you implemented it is technically compliant and practically useless. And every one of them still leaves you to source an actual penetration test, because a dashboard cannot perform one.
Which framework applies to us?
Usually whichever one a customer put in a contract. Handle cardholder data and PCI DSS is not optional; handle protected health information and HIPAA applies; sell to enterprise software buyers and SOC 2 gets asked for; sell to the Department of Defense and CMMC with NIST SP 800-171 underneath it is the conversation. If several apply, the controls overlap heavily and there is no sense running the programmes separately.
What happens after we pass?
The scanning and the annual test keep running, because the certificate is a snapshot and the estate is not. Most clients move onto a recurring cycle after the first audit: quarterly scans, an annual penetration test, and a short review before each surveillance visit.
Also from us
Related services
Penetration Testing
Network, web app, API, mobile and internal testing done by hand. You get the attack path, the proof, and a retest once it is fixed.
Vulnerability Assessments
Full-estate scanning, then a human pass to strip the noise and rank what is left by real reachability instead of raw CVSS.
Endpoint Security
CrowdStrike Falcon rollouts, policy tuning and legacy AV migrations, run by people who break into endpoints for a living.
Cloud Security
AWS, Azure, GCP and Kubernetes reviews that chase IAM privilege escalation paths rather than stopping at a benchmark score.
Know what an attacker would reach first.
Tell us what you run and what worries you. We will come back with a scope, a fixed price and the earliest week we can start.