Readiness status, honestly stated

Our SOC 2 position

We hold no SOC 2 Type 1 or Type 2 report today. What follows is the real state of our readiness program, including the parts that are not finished. If your procurement process requires an audited report before you can engage us, tell us early and we will say plainly whether we can meet that condition.

Pre-audit items complete

4 of 17

Program progress

23%

Criteria with an open gap

7

Scope and approach

The audit scope is the advisory and assessment services we deliver to clients, the systems that hold client information, and the people who deliver that work. It covers the Security trust services category, plus Availability and Confidentiality, because clients depend on us holding their material safely and returning it on time. Processing Integrity is out of scope, because we do not process client transactions.

We are working toward a SOC 2 Type 1 report first, which tests whether the controls are suitably designed on a single date. A Type 2 report, which tests whether they operated effectively over a period, follows once we have a minimum of six months of clean evidence behind us.

The examining firm must be an independent licensed CPA firm for SOC 2, and an accredited certification body for ISO 27001. We do not use the same party for readiness advice and the examination itself.

Where each criteria group stands

These are the trust services criteria groups inside our scope, what an auditor would ask for, and what we can put in front of them today.

  • CC1. Control environment

    Being strengthened

    The organization demonstrates a commitment to integrity, competence, accountability, and oversight of internal control.

    Evidence an auditor would request. Organization chart, role descriptions, background check records, training completion records, and the minutes of the management review.

    Open gap. Management review minutes exist for recent quarters only. We need four consecutive quarters before a Type 2 period closes.

  • CC2. Communication and information

    Evidenced today

    Relevant information about the system and its controls is communicated internally and to external parties.

    Evidence an auditor would request. Client facing commitments, the portal content, the confidentiality terms, and the internal handling rules with acknowledgements.

  • CC3. Risk assessment

    Evidenced today

    The organization identifies and assesses risks to its objectives, including fraud risk and the risk of change.

    Evidence an auditor would request. The risk register with dated reviews, the rating method, and signed risk acceptances.

  • CC4. Monitoring activities

    Being strengthened

    The organization evaluates whether its controls are present and operating.

    Evidence an auditor would request. The internal audit plan, the results, and evidence that findings were actioned.

    Open gap. The full internal audit across every criterion has not been performed yet. It is phase four work.

  • CC5. Control activities

    Evidenced today

    Control activities are selected, developed, and deployed to reduce risk to acceptable levels.

    Evidence an auditor would request. Change records, review records naming the reviewer, and the authorization file for testing work.

  • CC6. Logical and physical access

    Evidenced today

    Access to systems and data is restricted to authorized users, and information is protected in transit, at rest, and on disposal.

    Evidence an auditor would request. The access register with approvals, four quarters of access reviews, multi factor enforcement evidence, and destruction records.

    Open gap. Access reviews are running. We need four consecutive completed quarters to support a Type 2 period.

  • CC7. System operations

    Being strengthened

    The organization detects, responds to, and recovers from security events and system failures.

    Evidence an auditor would request. Alert configuration, a sample of investigated alerts, incident records with timelines, and the exercise report.

    Open gap. Centralised alerting on our own administrative activity is being built, and the annual tabletop has not run yet in the current cycle.

  • CC8. Change management

    Evidenced today

    Changes to infrastructure, data, software, and procedures are authorized, designed, tested, and approved.

    Evidence an auditor would request. Release records, review evidence, and the record of who approved each change.

  • CC9. Risk mitigation

    Being strengthened

    The organization identifies and manages risk arising from business disruption and from vendors.

    Evidence an auditor would request. The vendor register with assessment dates, the flow down terms, and the recovery test record.

    Open gap. The documented restore test against stated recovery objectives has not been performed yet.

  • A1. Availability

    Being strengthened

    The organization maintains and monitors capacity, and recovers the service within its stated objectives.

    Evidence an auditor would request. Recovery objectives, backup configuration, and the measured result of a restore test.

    Open gap. Objectives are written. The measured restore test is outstanding.

  • C1. Confidentiality

    Evidenced today

    Information designated as confidential is protected through its life and disposed of when no longer needed.

    Evidence an auditor would request. Classification rules, storage configuration, share settings, and destruction records with verification.

  • P1 to P8. Privacy commitments

    Evidenced today

    Personal information is collected, used, retained, disclosed, and disposed of in line with commitments and law.

    Evidence an auditor would request. The processing record, screening decisions, the retention schedule, and the notification obligation matrix.

    Open gap. Privacy is not in our first SOC 2 scope, but the controls operate because GDPR requires them independently.

The plan, phase by phase

  1. Scope and gap assessment

    Months 1 and 2

    Fix the audit boundary, confirm which criteria apply, and establish honestly where we stand against each one.

    • A written scope statement naming the services, systems, and locations inside the boundary.
    • Every applicable criterion assessed as designed, partly designed, or absent, with the assessment dated and signed.
    • A gap list with an owner and a target month against every gap.
  2. Policy and control build

    Months 2 to 4

    Close every design gap so each control exists on paper and in practice, not just one of the two.

    • A complete policy set, approved and dated, with every policy read and acknowledged by every team member.
    • Every control in the register at status in place, or carrying a documented and accepted reason it is not.
    • No control relying on a person remembering to do something, where a system could enforce it.
  3. Evidence operation

    Months 4 to 10

    Run the controls for long enough, and record them well enough, that an auditor can sample any month and find the evidence already there.

    • At least six consecutive months of evidence for every recurring control, with no unexplained gap in any month.
    • Quarterly access reviews completed on time, with the removals actioned and timestamped.
    • One completed tabletop exercise and one completed recovery test, each with owned follow up actions closed.
  4. Internal audit and readiness assessment

    Months 10 and 11

    Test ourselves the way the auditor will, so nothing found in the examination is a surprise to us.

    • An internal audit across every criterion, performed by someone who did not operate the control.
    • Every internal audit finding either fixed, or recorded with an accepted reason and a date.
    • A complete evidence index, so any requested item can be produced within one working day.
  5. Examination

    Month 12 onward

    Engage the examining firm, support the fieldwork, and receive the report.

    • An engagement letter signed with an independent licensed CPA firm.
    • Fieldwork supported with every sample request answered inside the agreed turnaround.
    • A report received, and the public website updated to state exactly what the report covers and no more.

What you can ask us for now

Our control register with named owners and dated evidence, a completed security questionnaire answered from that register, our confidentiality and data handling terms, and a walkthrough of any control with the person who operates it.