Standards playbooks

SOC 2 playbook: readiness in one workspace

Reuse your ISO 27001 controls for SOC 2 CC via automatic crosswalk. Add the SOC 2 specifics (change management, monitoring) and you're audit-ready.

10 min read · updated July 2026

Step-by-step

  1. 1

    Enable SOC 2

    Controls → Add framework → SOC 2. Crosswalk from your existing controls happens automatically.

  2. 2

    Fill the SOC 2 gaps

    Focus on change management (CC8), risk mitigation (CC9), monitoring (CC7). The dashboard shows what's missing.

  3. 3

    Choose an audit firm

    AICPA-licensed CPA firm. Type I first (point in time) then Type II (6 months of operating effectiveness).

  4. 4

    Publish under NDA

    Once the report lands, publish gated in Trust Center — buyers self-serve.

What corporate buyers look for
  • "Do you have a SOC 2 report? Type I or Type II?"
  • "What Trust Services Criteria are in scope?"
  • "May we see the report under NDA?"

What this workflow produces: US enterprise buyers strongly prefer SOC 2 Type II. UK/EU buyers accept ISO 27001 as equivalent — often both is the answer.

FAQ

How long does SOC 2 Type II take?

6 months minimum for the evidence window + 6–8 weeks for the audit report to be issued.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation