The deal is stuck in vendor review
An enterprise customer's security team asked for your SOC 2, and the deal will not move until something credible answers them. Readiness done right is how the deal un-sticks.
SOC 1 + SOC 2 readiness
SOC reports are issued by licensed CPA firms after an audit. Our job is everything before that: the gap work, the policies, the evidence, and the coordination, so the audit is a formality instead of a fire drill.
Scope, timing, and fees are documented before work begins.
An enterprise customer's security team asked for your SOC 2, and the deal will not move until something credible answers them. Readiness done right is how the deal un-sticks.
Type I says your controls were designed properly on a date. Type II says they operated over months. Customers increasingly want Type II, which means evidence discipline, not paperwork heroics the week before.
Compliance platforms collect evidence; they do not decide scope, write true policies, or run your program. Somebody accountable still has to do the thinking. That is the part we do.
Best fit: service businesses and SaaS companies of 25 to 200 people whose enterprise customers or partners are asking for a SOC report, with leadership willing to actually operate the controls.
Not the right fit: companies wanting a certificate without changing anything, or needing the audit itself; the audit is performed by a licensed CPA firm we help you select and prepare for.
SOC reports are attestations under AICPA standards, issued by licensed CPA firms after an audit. SOC 2 covers the Trust Services Criteria (security, availability, confidentiality, processing integrity, privacy) and is what customer security teams mean by 'your SOC report.' SOC 1 covers controls relevant to your customers' financial reporting; billing services, payroll processors and claims administrators get asked for it by their customers' finance auditors.
The routing question is simply who is asking: a security or vendor-risk team means SOC 2; a controller or financial auditor means SOC 1. Type I attests your control design at a point in time; Type II attests the controls operated over an observation window of several months, which is why the calendar, not the paperwork, is the real project.
Readiness is everything before the CPA firm arrives: scoping which criteria apply, closing the gaps, writing policies people actually follow, collecting evidence continuously through the window, coordinating the independent penetration test auditors expect, and preparing your team for fieldwork.
Every engagement includes
Example readiness tracker
Illustrative structure only. Your findings, owners, evidence, and priorities are based on your environment.
See what your scope includesWhich report, which type, which criteria, and the readiness plan sequenced backward from your deadline. Price fixed in writing.
Policies adopted, controls operating, evidence accumulating, pen test done by an independent partner. Your team executes; we direct and verify.
We help you choose the audit firm, hand over a clean evidence package, and support your team through fieldwork. The CPA firm issues the report.
How pricing works
Your quote is built from your headcount, your systems, and how far you are from the bar. It is fixed in writing at the free 30-minute call, before any work starts, and it never changes after you approve it.
Separately scoped, always disclosed
The CPA firm's audit fee and the independent penetration test are third-party engagements, quoted by those firms and never hidden inside ours. Compliance-automation tooling is optional; when it helps, you buy it directly and we run it, and we take no commission from anyone.
No, and nobody who is not a licensed CPA firm can. We do the readiness: gaps, policies, evidence, coordination, and audit prep. Then a CPA firm you choose (we help you shortlist) performs the audit and issues the report. That separation is how the system is designed to work.
Ask who wants it. A customer's security or vendor-risk team wants SOC 2. A customer's finance team or their financial auditors want SOC 1, which applies when your service affects their financial reporting, like billing, payroll or claims processing. We route you in the first call.
Type I: often 3 to 5 months. Type II: readiness plus an observation window of 3 to 12 months, then the audit, so plan 6 to 12 months. The biggest schedule lever is starting the window early, which is why readiness should begin the week the customer first asks.
The criteria do not name one explicitly, but CPA auditors expect vulnerability management evidence and most expect a pen test. Ours is delivered by an independent testing partner, never by us, so the evidence carries an outside firm's name.
We cover your organization, your deadline, and who is asking for what. You leave knowing the likely scope, the timeline, and your next step, with the price fixed in writing before any work starts.
Prefer phone or email?
(754) 216-9664 info@hardenwell.com
Do not include PHI or sensitive records in booking notes. See our Privacy Policy.