SOC 2 playbook: readiness in one workspace
Reuse your ISO 27001 controls for SOC 2 CC via automatic crosswalk. Add the SOC 2 specifics (change management, monitoring) and you're audit-ready.
Step-by-step
- 1
Enable SOC 2
Controls → Add framework → SOC 2. Crosswalk from your existing controls happens automatically.
- 2
Fill the SOC 2 gaps
Focus on change management (CC8), risk mitigation (CC9), monitoring (CC7). The dashboard shows what's missing.
- 3
Choose an audit firm
AICPA-licensed CPA firm. Type I first (point in time) then Type II (6 months of operating effectiveness).
- 4
Publish under NDA
Once the report lands, publish gated in Trust Center — buyers self-serve.
- "Do you have a SOC 2 report? Type I or Type II?"
- "What Trust Services Criteria are in scope?"
- "May we see the report under NDA?"
What this workflow produces: US enterprise buyers strongly prefer SOC 2 Type II. UK/EU buyers accept ISO 27001 as equivalent — often both is the answer.
FAQ
6 months minimum for the evidence window + 6–8 weeks for the audit report to be issued.
Ready to run this in your workspace?
Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.
