CPA · CISA · CISM · CDPSE · CCSE · MBA
A readiness meeting seen from above, five people around a table marking up printed control documentation

SOC 1 and SOC 2 Readiness and Attestation

Readiness, remediation and the attestation itself, held by one licensed firm instead of split between a consultancy and a remote auditor.

Does SOC 2 readiness require a separate firm from the examination?

No. Readiness, remediation and the attestation itself can sit with one CPA firm in California. The market treats the split as inevitable: a security consultancy for readiness and remediation, then a separate firm arriving cold to perform the examination. AICPA rules require only the second of those, and keeping the work together removes both the handoff and the cold start.

Most companies searching for a SOC 2 readiness CPA in California arrive holding two quotes, for what they have been told is one unavoidable split in the work.

It is not unavoidable. This practice holds the CPA licence that permits the attestation and the CISA and CISM credentials that make the readiness work substantive. One scope decision, one methodology, one set of judgments about what counts as evidence.

SOC 1 or SOC 2 readiness: what a CPA in California can actually issue

SOC 1 addresses controls at a service organisation that are relevant to its clients' internal control over financial reporting. If your customers' auditors need to rely on what your system does to their numbers (payroll processing, claims administration, loan servicing, transaction processing) SOC 1 is the report they need.

SOC 2 addresses the Trust Services Criteria: security, and optionally availability, processing integrity, confidentiality and privacy. This is what enterprise buyers and their security teams ask for. Security is always in scope; the others are elective and each one added expands the examination.

Type 1 reports on the design of controls at a point in time. Type 2 reports on operating effectiveness across a period. A large share of companies skip Type 1 and go straight to Type 2, and if controls are genuinely implemented that is usually right, enterprise buyers want evidence that controls operated, not that they were designed.

Type 1 earns its place in one specific situation: a deal contingent on demonstrable progress within weeks, where a Type 2 observation window cannot be compressed to fit. It buys credibility while the window runs.

Scope decisions that determine the cost

Three decisions set the size of the programme, and all three are made before any control is written.

System boundary. Which product, which infrastructure, which supporting processes. Drawing the boundary around the whole company when the customer commitment concerns one product is the most expensive unforced error available in SOC 2.

Trust Services Categories. Security alone satisfies most enterprise requests. Availability matters where you have made uptime commitments. Confidentiality where contracts impose specific handling obligations. Processing integrity is narrower than it sounds and is genuinely relevant to transaction processors. Privacy overlaps heavily with the CCPA and GDPR work and is frequently added without anyone establishing that a customer asked for it.

Observation window. Three months for a first Type 2 is standard, extending to six or twelve on renewal. Shorter windows reach a report sooner; longer windows are what mature buyers eventually expect.

The readiness assessment

Three to five weeks, and the single highest-return step in the programme. Skipping it is the most commonly cited cause of audit delays and qualified opinions, for a straightforward economic reason: a gap found during readiness is remediated at remediation cost, while the same gap found during fieldwork is billed at audit rates, may require a control to operate over a fresh window, and can produce an exception in the report itself.

What the assessment produces: an agreed system boundary and description outline; an inventory of controls that already exist, including the many that exist informally and have never been documented; a gap list with effort, dependency and sequence attached; an evidence plan specifying what must be retained and by whom; and a realistic date for the observation window to open.

The gaps that appear in almost every first engagement

  • No formal risk assessment. The Trust Services Criteria require one. Most companies have security practices but no documented risk assessment driving them.
  • Access reviews that have never been performed. Or performed once, before anyone thought to keep the evidence.
  • Vendor management as a spreadsheet of names. Without risk tiering, without obtaining subservice organisation SOC reports, and without reading the complementary user entity controls in them.
  • Onboarding and offboarding without evidence. The process happens; nothing records that it happened for a specific person on a specific date.
  • Incident response documented but never exercised. A plan nobody has walked through is not a control.
  • Change management bypassed for hotfixes. Legitimate under pressure, undocumented afterwards.
  • Policies written and never acknowledged. A policy nobody has read or signed provides no evidence that anyone was informed.

None of these are difficult. They are simply invisible until someone asks for evidence, and they take longer to fix than companies expect because most require a control to operate for a period before it can be tested.

Compliance automation platforms

Drata, Vanta, Secureframe, Scrut and similar tools genuinely reduce total programme cost (commonly by a meaningful margin) by automating evidence collection and continuous monitoring. Where a client already runs one, the engagement works inside it.

What the platform does not do: decide the system boundary, determine whether a compensating control is adequate, tell you an exception will draw a qualification, or remove the auditor's fee. Automation reduces internal effort; it does not remove the requirement for someone to form and sign an opinion.

For companies choosing a platform, the advice is consistently to scope the programme first and select second. The reverse order produces a tool configured against a boundary nobody agreed, and re-scoping afterwards is more work than scoping properly once.

Timeline and budget, stated plainly

From a standing start, nine to twelve months to a first Type 2 report is realistic; roughly six is achievable for an organised company using a three-month window and an automation platform. The components are readiness and remediation (four to eight weeks of concentrated work, longer where the control environment is immature), the observation window, fieldwork of one to three weeks, and two to six weeks for the report.

Published 2026 market data puts specialist-firm Type 2 audit fees broadly in the $15,000,$50,000 range, with national firms materially above that. Total first-year programme cost (audit, readiness, tooling and internal time) commonly lands between $30,000 and $80,000 for a small or mid-sized company. Penetration testing, platform subscription and remediation are the line items most often left out of an initial budget.

And the cost recurs. The observation window for the next cycle begins as soon as the current one closes, and a gap between reporting periods is something enterprise buyers notice.

Javed Peeran CPA

Javed Peeran

CPA · CISA · CISM · CDPSE · CCSE · MBA

Licensed by the California Board of Accountancy and the author of every article published here. Thirty years of practice covering external audit of banks, insurers and mortgage companies, fifteen years as CFO and Corporate Controller inside technology companies, and IT governance and security compliance work spanning SOX 404, SOC 1 and SOC 2, ISO 27001, FISMA, FedRAMP, PCI DSS, HIPAA/HITECH, CCPA and GDPR, plus Oracle ERP migrations and, more recently, generative-AI audit automation.

What the engagement delivers

  • Scoping workshop covering system boundary, categories and observation window
  • Readiness assessment with gap list, effort estimates and dependency sequence
  • System description drafted to AICPA description criteria
  • Control matrix mapped to the applicable Trust Services Criteria
  • Evidence plan specifying artefacts, owners and retention
  • Remediation support and control design for identified gaps
  • Subservice organisation and vendor SOC report review, including CUEC mapping
  • Pre-assessment testing before the observation window closes
  • SOC 1 or SOC 2 examination and report (where independence permits)
  • Annual renewal planning with no gap between reporting periods

How a typical engagement runs

  1. Scope

    System boundary, Trust Services Categories and observation window agreed. These three decisions determine cost more than anything that follows.

  2. Readiness

    Three to five weeks establishing what exists, what is missing, and what it will take to close. Output is a gap list with sequence and effort, not a checklist.

  3. Remediate and observe

    Gaps closed, controls put into operation, and the observation window opened only once controls are actually running, not before.

  4. Examine and report

    Fieldwork, exception evaluation, and the report. Where this practice performed the remediation, the examination is referred out; independence is settled at the start, not discovered at the end.

SOC 1 & SOC 2 Readiness across Ventura County and Los Angeles

This service is delivered on site and remotely across the firm's service area. See how it applies locally:

SOC 1 & SOC 2 Readiness: questions we are asked

Not answered here? Ask Javed directly

Can our MSP or security consultant issue the SOC 2 report?

No. SOC examinations are performed under AICPA attestation standards and only a licensed CPA firm can issue the report. This is not a formality, the report's value to your customers rests entirely on it.

An MSP or MSSP can do genuinely valuable readiness, remediation and monitoring work. What they cannot do is sign. That is why most companies in this region end up with two vendors and a handoff, and the handoff is where scope disagreements and duplicated effort live.

Should we do Type 1 first?

Usually not. A large majority of companies go straight to Type 2, and if your controls are genuinely implemented and operating there is no reason to spend on a point-in-time design report that most enterprise buyers do not actually want.

The exception is a live deal contingent on visible progress within weeks. A Type 1 provides something to show while the Type 2 observation window runs.

How much does a SOC 2 Type 2 audit cost?

Published 2026 data puts specialist-firm audit fees roughly between $15,000 and $50,000 for a Type 2, with Big Four quotes several times higher. Total first-year programme cost (including readiness, tooling, penetration testing and internal time) commonly falls between $30,000 and $80,000 for small and mid-sized companies.

The variables that move it are the number of Trust Services Categories in scope, the breadth of the system boundary, headcount, and how much remediation the readiness assessment turns up. Costs also recur annually, with continuous monitoring and recertification adding meaningfully where the process is not automated.

How long before we can show a customer a report?

Nine to twelve months from a standing start; around six if you are organised, use a three-month observation window, and run an automation platform. There is no legitimate way to compress the observation window itself; that period is the evidence.

Where a customer deadline falls inside that, the usual approach is a combination of a completed readiness assessment, a documented remediation plan with dates, and in some cases a Type 1. Most enterprise security teams accept that as an interim position when it is presented honestly. What they respond badly to is a promise with no evidence behind it.

What causes SOC 2 projects to slip?

The delay drivers are consistent and mostly avoidable: engaging the auditor too late, an incomplete or inaccurate system description, slow responses to evidence requests, controls that operate quarterly but have not yet operated once inside the window, and subservice organisations that do not supply their own SOC report on time.

The last one deserves attention because it is outside your control. Request vendor reports at the start of the window, not at the end.

Which Trust Services Categories do we actually need?

Security is mandatory. Beyond that, add a category only when something specific requires it: availability where you have contractual uptime commitments, confidentiality where customer agreements impose handling obligations, processing integrity where you process transactions on customers' behalf, and privacy where personal information handling is central to the service.

Every additional category expands the examination and the annual cost. Ask the customer who requested SOC 2 what they actually need to see; the answer is very often security alone.

Related services

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

Get in touch

Enquire about soc 1 & soc 2 readiness

A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Talk through a soc 1 & soc 2 readiness engagement

Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.

WhatsApp Us
Call Now