IT Audit & ITGC
Access, change and operations controls tested by someone who can read both an access listing and a general ledger.
IT audit & ITGC
Readiness, remediation and the attestation itself, held by one licensed firm instead of split between a consultancy and a remote auditor.
No. Readiness, remediation and the attestation itself can sit with one CPA firm in California. The market treats the split as inevitable: a security consultancy for readiness and remediation, then a separate firm arriving cold to perform the examination. AICPA rules require only the second of those, and keeping the work together removes both the handoff and the cold start.
Most companies searching for a SOC 2 readiness CPA in California arrive holding two quotes, for what they have been told is one unavoidable split in the work.
It is not unavoidable. This practice holds the CPA licence that permits the attestation and the CISA and CISM credentials that make the readiness work substantive. One scope decision, one methodology, one set of judgments about what counts as evidence.
SOC 1 addresses controls at a service organisation that are relevant to its clients' internal control over financial reporting. If your customers' auditors need to rely on what your system does to their numbers (payroll processing, claims administration, loan servicing, transaction processing) SOC 1 is the report they need.
SOC 2 addresses the Trust Services Criteria: security, and optionally availability, processing integrity, confidentiality and privacy. This is what enterprise buyers and their security teams ask for. Security is always in scope; the others are elective and each one added expands the examination.
Type 1 reports on the design of controls at a point in time. Type 2 reports on operating effectiveness across a period. A large share of companies skip Type 1 and go straight to Type 2, and if controls are genuinely implemented that is usually right, enterprise buyers want evidence that controls operated, not that they were designed.
Type 1 earns its place in one specific situation: a deal contingent on demonstrable progress within weeks, where a Type 2 observation window cannot be compressed to fit. It buys credibility while the window runs.
Three decisions set the size of the programme, and all three are made before any control is written.
System boundary. Which product, which infrastructure, which supporting processes. Drawing the boundary around the whole company when the customer commitment concerns one product is the most expensive unforced error available in SOC 2.
Trust Services Categories. Security alone satisfies most enterprise requests. Availability matters where you have made uptime commitments. Confidentiality where contracts impose specific handling obligations. Processing integrity is narrower than it sounds and is genuinely relevant to transaction processors. Privacy overlaps heavily with the CCPA and GDPR work and is frequently added without anyone establishing that a customer asked for it.
Observation window. Three months for a first Type 2 is standard, extending to six or twelve on renewal. Shorter windows reach a report sooner; longer windows are what mature buyers eventually expect.
Three to five weeks, and the single highest-return step in the programme. Skipping it is the most commonly cited cause of audit delays and qualified opinions, for a straightforward economic reason: a gap found during readiness is remediated at remediation cost, while the same gap found during fieldwork is billed at audit rates, may require a control to operate over a fresh window, and can produce an exception in the report itself.
What the assessment produces: an agreed system boundary and description outline; an inventory of controls that already exist, including the many that exist informally and have never been documented; a gap list with effort, dependency and sequence attached; an evidence plan specifying what must be retained and by whom; and a realistic date for the observation window to open.
None of these are difficult. They are simply invisible until someone asks for evidence, and they take longer to fix than companies expect because most require a control to operate for a period before it can be tested.
Drata, Vanta, Secureframe, Scrut and similar tools genuinely reduce total programme cost (commonly by a meaningful margin) by automating evidence collection and continuous monitoring. Where a client already runs one, the engagement works inside it.
What the platform does not do: decide the system boundary, determine whether a compensating control is adequate, tell you an exception will draw a qualification, or remove the auditor's fee. Automation reduces internal effort; it does not remove the requirement for someone to form and sign an opinion.
For companies choosing a platform, the advice is consistently to scope the programme first and select second. The reverse order produces a tool configured against a boundary nobody agreed, and re-scoping afterwards is more work than scoping properly once.
From a standing start, nine to twelve months to a first Type 2 report is realistic; roughly six is achievable for an organised company using a three-month window and an automation platform. The components are readiness and remediation (four to eight weeks of concentrated work, longer where the control environment is immature), the observation window, fieldwork of one to three weeks, and two to six weeks for the report.
Published 2026 market data puts specialist-firm Type 2 audit fees broadly in the $15,000,$50,000 range, with national firms materially above that. Total first-year programme cost (audit, readiness, tooling and internal time) commonly lands between $30,000 and $80,000 for a small or mid-sized company. Penetration testing, platform subscription and remediation are the line items most often left out of an initial budget.
And the cost recurs. The observation window for the next cycle begins as soon as the current one closes, and a gap between reporting periods is something enterprise buyers notice.
System boundary, Trust Services Categories and observation window agreed. These three decisions determine cost more than anything that follows.
Three to five weeks establishing what exists, what is missing, and what it will take to close. Output is a gap list with sequence and effort, not a checklist.
Gaps closed, controls put into operation, and the observation window opened only once controls are actually running, not before.
Fieldwork, exception evaluation, and the report. Where this practice performed the remediation, the examination is referred out; independence is settled at the start, not discovered at the end.
This service is delivered on site and remotely across the firm's service area. See how it applies locally:
Not answered here? Ask Javed directly
No. SOC examinations are performed under AICPA attestation standards and only a licensed CPA firm can issue the report. This is not a formality, the report's value to your customers rests entirely on it.
An MSP or MSSP can do genuinely valuable readiness, remediation and monitoring work. What they cannot do is sign. That is why most companies in this region end up with two vendors and a handoff, and the handoff is where scope disagreements and duplicated effort live.
Usually not. A large majority of companies go straight to Type 2, and if your controls are genuinely implemented and operating there is no reason to spend on a point-in-time design report that most enterprise buyers do not actually want.
The exception is a live deal contingent on visible progress within weeks. A Type 1 provides something to show while the Type 2 observation window runs.
Published 2026 data puts specialist-firm audit fees roughly between $15,000 and $50,000 for a Type 2, with Big Four quotes several times higher. Total first-year programme cost (including readiness, tooling, penetration testing and internal time) commonly falls between $30,000 and $80,000 for small and mid-sized companies.
The variables that move it are the number of Trust Services Categories in scope, the breadth of the system boundary, headcount, and how much remediation the readiness assessment turns up. Costs also recur annually, with continuous monitoring and recertification adding meaningfully where the process is not automated.
Nine to twelve months from a standing start; around six if you are organised, use a three-month observation window, and run an automation platform. There is no legitimate way to compress the observation window itself; that period is the evidence.
Where a customer deadline falls inside that, the usual approach is a combination of a completed readiness assessment, a documented remediation plan with dates, and in some cases a Type 1. Most enterprise security teams accept that as an interim position when it is presented honestly. What they respond badly to is a promise with no evidence behind it.
The delay drivers are consistent and mostly avoidable: engaging the auditor too late, an incomplete or inaccurate system description, slow responses to evidence requests, controls that operate quarterly but have not yet operated once inside the window, and subservice organisations that do not supply their own SOC report on time.
The last one deserves attention because it is outside your control. Request vendor reports at the start of the window, not at the end.
Security is mandatory. Beyond that, add a category only when something specific requires it: availability where you have contractual uptime commitments, confidentiality where customer agreements impose handling obligations, processing integrity where you process transactions on customers' behalf, and privacy where personal information handling is central to the service.
Every additional category expands the examination and the annual cost. Ask the customer who requested SOC 2 what they actually need to see; the answer is very often security alone.
Access, change and operations controls tested by someone who can read both an access listing and a general ledger.
IT audit & ITGCNIST, ISO 27001, PCI DSS and CMMC assessment, with findings expressed as business exposure rather than a severity count.
Security assessmentArchitecture review, IAM and configuration assessment, and FedRAMP or FISMA readiness across the three major cloud platforms.
Cloud securityThree decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.
Get in touch
A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.
Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.
Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.
Or speak to Javed directly (310) 980-3958 Message on WhatsApp