Readiness status, honestly stated
Our SOC 2 position
We hold no SOC 2 Type 1 or Type 2 report today. What follows is the real state of our readiness program, including the parts that are not finished. If your procurement process requires an audited report before you can engage us, tell us early and we will say plainly whether we can meet that condition.
Pre-audit items complete
4 of 17
Program progress
23%
Criteria with an open gap
7
Scope and approach
The audit scope is the advisory and assessment services we deliver to clients, the systems that hold client information, and the people who deliver that work. It covers the Security trust services category, plus Availability and Confidentiality, because clients depend on us holding their material safely and returning it on time. Processing Integrity is out of scope, because we do not process client transactions.
We are working toward a SOC 2 Type 1 report first, which tests whether the controls are suitably designed on a single date. A Type 2 report, which tests whether they operated effectively over a period, follows once we have a minimum of six months of clean evidence behind us.
The examining firm must be an independent licensed CPA firm for SOC 2, and an accredited certification body for ISO 27001. We do not use the same party for readiness advice and the examination itself.
Where each criteria group stands
These are the trust services criteria groups inside our scope, what an auditor would ask for, and what we can put in front of them today.
CC1. Control environment
Being strengthenedThe organization demonstrates a commitment to integrity, competence, accountability, and oversight of internal control.
Evidence an auditor would request. Organization chart, role descriptions, background check records, training completion records, and the minutes of the management review.
Open gap. Management review minutes exist for recent quarters only. We need four consecutive quarters before a Type 2 period closes.
CC2. Communication and information
Evidenced todayRelevant information about the system and its controls is communicated internally and to external parties.
Evidence an auditor would request. Client facing commitments, the portal content, the confidentiality terms, and the internal handling rules with acknowledgements.
CC3. Risk assessment
Evidenced todayThe organization identifies and assesses risks to its objectives, including fraud risk and the risk of change.
Evidence an auditor would request. The risk register with dated reviews, the rating method, and signed risk acceptances.
CC4. Monitoring activities
Being strengthenedThe organization evaluates whether its controls are present and operating.
Evidence an auditor would request. The internal audit plan, the results, and evidence that findings were actioned.
Open gap. The full internal audit across every criterion has not been performed yet. It is phase four work.
CC5. Control activities
Evidenced todayControl activities are selected, developed, and deployed to reduce risk to acceptable levels.
Evidence an auditor would request. Change records, review records naming the reviewer, and the authorization file for testing work.
CC6. Logical and physical access
Evidenced todayAccess to systems and data is restricted to authorized users, and information is protected in transit, at rest, and on disposal.
Evidence an auditor would request. The access register with approvals, four quarters of access reviews, multi factor enforcement evidence, and destruction records.
Open gap. Access reviews are running. We need four consecutive completed quarters to support a Type 2 period.
CC7. System operations
Being strengthenedThe organization detects, responds to, and recovers from security events and system failures.
Evidence an auditor would request. Alert configuration, a sample of investigated alerts, incident records with timelines, and the exercise report.
Open gap. Centralised alerting on our own administrative activity is being built, and the annual tabletop has not run yet in the current cycle.
CC8. Change management
Evidenced todayChanges to infrastructure, data, software, and procedures are authorized, designed, tested, and approved.
Evidence an auditor would request. Release records, review evidence, and the record of who approved each change.
CC9. Risk mitigation
Being strengthenedThe organization identifies and manages risk arising from business disruption and from vendors.
Evidence an auditor would request. The vendor register with assessment dates, the flow down terms, and the recovery test record.
Open gap. The documented restore test against stated recovery objectives has not been performed yet.
A1. Availability
Being strengthenedThe organization maintains and monitors capacity, and recovers the service within its stated objectives.
Evidence an auditor would request. Recovery objectives, backup configuration, and the measured result of a restore test.
Open gap. Objectives are written. The measured restore test is outstanding.
C1. Confidentiality
Evidenced todayInformation designated as confidential is protected through its life and disposed of when no longer needed.
Evidence an auditor would request. Classification rules, storage configuration, share settings, and destruction records with verification.
P1 to P8. Privacy commitments
Evidenced todayPersonal information is collected, used, retained, disclosed, and disposed of in line with commitments and law.
Evidence an auditor would request. The processing record, screening decisions, the retention schedule, and the notification obligation matrix.
Open gap. Privacy is not in our first SOC 2 scope, but the controls operate because GDPR requires them independently.
The plan, phase by phase
Scope and gap assessment
Months 1 and 2
Fix the audit boundary, confirm which criteria apply, and establish honestly where we stand against each one.
- A written scope statement naming the services, systems, and locations inside the boundary.
- Every applicable criterion assessed as designed, partly designed, or absent, with the assessment dated and signed.
- A gap list with an owner and a target month against every gap.
Policy and control build
Months 2 to 4
Close every design gap so each control exists on paper and in practice, not just one of the two.
- A complete policy set, approved and dated, with every policy read and acknowledged by every team member.
- Every control in the register at status in place, or carrying a documented and accepted reason it is not.
- No control relying on a person remembering to do something, where a system could enforce it.
Evidence operation
Months 4 to 10
Run the controls for long enough, and record them well enough, that an auditor can sample any month and find the evidence already there.
- At least six consecutive months of evidence for every recurring control, with no unexplained gap in any month.
- Quarterly access reviews completed on time, with the removals actioned and timestamped.
- One completed tabletop exercise and one completed recovery test, each with owned follow up actions closed.
Internal audit and readiness assessment
Months 10 and 11
Test ourselves the way the auditor will, so nothing found in the examination is a surprise to us.
- An internal audit across every criterion, performed by someone who did not operate the control.
- Every internal audit finding either fixed, or recorded with an accepted reason and a date.
- A complete evidence index, so any requested item can be produced within one working day.
Examination
Month 12 onward
Engage the examining firm, support the fieldwork, and receive the report.
- An engagement letter signed with an independent licensed CPA firm.
- Fieldwork supported with every sample request answered inside the agreed turnaround.
- A report received, and the public website updated to state exactly what the report covers and no more.
What you can ask us for now
Our control register with named owners and dated evidence, a completed security questionnaire answered from that register, our confidentiality and data handling terms, and a walkthrough of any control with the person who operates it.