SOC 2 & ISO 27001 Readiness

A big customer asks for your SOC 2 report, or a European prospect wants ISO 27001 — and suddenly you’re reading control frameworks at midnight. I’ve taken an IT department through SOC 2 Type II and ISO 27001 at the same time, and wrote the policies both audits required. I’ll tell you what actually matters for a team your size, help you build controls that fit how you really work, and get you to audit day without a policy binder nobody follows.

Signs you need this

If this sounds like you

  • A customer or prospect asked for your SOC 2 report
  • Security questionnaires are stalling deals
  • You bought Vanta or Drata and it’s showing 200 failing tests
  • You’re not sure whether you need SOC 2, ISO 27001, or both
  • Policies exist on paper, but nobody follows them
Deliverables

What you get

01

Gap assessment

Where you stand against the SOC 2 Trust Services Criteria or ISO 27001 Annex A, with gaps ranked by effort and audit risk.

02

Roadmap & scoping

Type I vs. Type II, which criteria to include, what’s in scope, a realistic timeline, and what to fix first.

03

Policies & controls

Right-sized policies and the technical controls behind them: access reviews, MFA, device management, logging, backups, and vendor risk.

04

Audit support

Evidence collection, auditor walkthroughs, and a straight answer when the auditor asks the hard questions.

In scope

  • SOC 2 Type I and Type II readiness
  • ISO 27001 ISMS setup, risk assessment, and Statement of Applicability
  • Compliance platform setup — Vanta, Drata, Secureframe
  • Policy writing, right-sized for a small team
  • Security questionnaires and customer trust requests
  • Choosing and working with an audit firm or certification body

Not included

  • Performing the audit or issuing the report — that’s the independent auditor’s job
  • Legal advice or contract review
  • Penetration testing (I’ll help you scope it and pick a firm)
Common tools
SOC 2ISO 27001VantaDrataSecureframeGoogle WorkspaceMicrosoft 365AWS
FAQ

Common questions

Can you get us certified?

I get you ready. SOC 2 reports are issued by independent CPA firms, and ISO 27001 certificates by accredited certification bodies. My job is to make sure you pass, and that the controls keep working after the auditor leaves.

SOC 2 or ISO 27001 — which do we need?

Usually whichever your customers ask for. SOC 2 is the norm with US buyers; ISO 27001 is more common in Europe and with global enterprises. The two overlap heavily, so doing one makes the other much easier.

How long does it take?

For a small team, getting ready for a SOC 2 Type I often takes a few months. Type II adds an observation period, usually three to twelve months. ISO 27001 is similar. The gap assessment gives you a realistic timeline for your situation.

Do we need a platform like Vanta or Drata?

Not always, but for most small teams it saves real time on evidence collection. I’ll help you decide, and set it up properly if you go that route.

Does this work alongside Fractional IT?

Yes, and it often should. Many controls — access reviews, device management, backups — are exactly what fractional IT management keeps running month to month.

Tell me what’s broken. I’ll map the way up.

A free 30-minute call to talk through your stack, your size, and the actual headache. You’ll leave with next steps, whether or not we work together.