SOC 2, written and implemented, in 90 days#

Most compliance work hands you a binder and walks away. You are left to figure out how the policy turns into a real control in your cloud, and how you prove it to an auditor. I do all three parts: I write the policy, I write the Terraform and Ansible that enforce it in your environment, and I produce the evidence package the auditor signs off on. That is the whole offer.

Who this is for#

  • A SaaS company with an enterprise deal stuck behind a SOC 2 requirement.
  • An organization that already knows how to write policy but doesn’t know how to implement it: the controls, the infrastructure, the evidence pipeline that makes it auditable.
  • Any team that has bought a compliance automation tool and discovered it tracks controls but does not build them.

What you get#

  • A real risk analysis. The honest assessment of where your risk actually sits, which is what tells us where to spend effort instead of guessing.
  • Policies and controls written to how you operate. Not generic templates. The policy says what you do, you do what the policy says, and the two match.
  • Implementation in your cloud, as code. Controls enforced in Terraform and Ansible so they stay enforced instead of drifting the week after the audit.
  • The evidence package. Collected, organized, and mapped to the controls, so the audit is a review and not a fire drill.

How it is structured#

Every organization is different, so no two programs look exactly alike. But the shape is consistent: a focused upfront engagement to stand the program up, followed by long-term support to keep it running and carry you through successive audit periods.

  • The upfront standup. A defined, time-boxed engagement that takes you from where you are to audit ready. This is where most of the work lives: building the policies, implementing the controls, and standing up the evidence pipeline. For most organizations, this first phase is the heavy lift.
  • Long-term support, behind it. Compliance is not a one-time event. Controls need to keep running, evidence needs to keep accumulating, and the program needs an owner as you grow. Once the program is standing, maintaining it should be straightforward. The retainer keeps the program alive between audits. Usually this is the affordable part.

FAQ#

Why 90 days? Because a defined scope with a real deadline is what actually ships. The timeline assumes you can give me access and answer questions. A larger or messier environment may run longer, and I will tell you that up front rather than after.

Do you just resell a compliance tool? No. I will work with the tool you already have, but the value here is the work those tools do not do: writing controls to your operation and implementing them in your infrastructure.

SOC 2 Type 1 or Type 2? Type 1 proves the controls are designed and in place on a date. Type 2 proves they operated over a period. The 90 day project gets you to a defensible Type 1 and stands up everything Type 2 needs to observe. The retainer carries you through the Type 2 window.

What about a framework you have not named here? The same approach applies to most frameworks. Tell me what you are up against.

Talk through your SOC 2 project →