SOC 2 readiness and evidence
Type 1 and Type 2 readiness, controls and evidence. We build the controls, assemble the evidence pack and do the testing that backs it, so that by the time your auditor starts fieldwork they are verifying work that is already done and already documented.
What SOC 2 actually asks for
SOC 2 reports against the AICPA Trust Services Criteria. Security is the common criteria set and is mandatory; availability, processing integrity, confidentiality and privacy are added only if you commit to them. A Type 1 report describes whether controls were suitably designed at a point in time. A Type 2 report tests whether they operated effectively across a window, which is why it takes longer and carries more weight with an enterprise buyer.
Our part
Readiness work before the auditor arrives: a gap assessment against the criteria you are scoping, the policies and procedures the criteria expect to exist, control implementation guidance for your engineers, and the evidence pack an auditor will ask for. Where a criterion expects technical validation, the penetration test produces it and the report maps findings to the criteria it answers.
Where the work needs a penetration test, it is the plan you already see on the pricing page: Startup at INR 74,999 for one scope, Growth at INR 1,79,999 for two. Growth is the plan that carries the SOC 2 and ISO 27001 control mapping in the report. The sample report shows the format an auditor will be handed.
What we hand over, and who signs it off
What we hand your auditor is a control set that is already built, already operating and already evidenced, so their fieldwork is verification rather than discovery. The opinion itself is issued by a licensed CPA firm, and keeping readiness and audit in separate hands is what makes it worth something to the customer who asked you for it.
Where a penetration test fits, and where it does not
The Trust Services Criteria do not name penetration testing as a line item. What they do expect is that you identify and evaluate vulnerabilities and act on what you find, and a pentest report is the ordinary way a startup evidences that. Treat it as evidence for a control, not as the control itself.
If you are still deciding which one first
SOC 2 questions we are asked
Does SOC 2 require a penetration test?
Not as a named line item. The Trust Services Criteria do not mention penetration testing. What they do expect is that you identify and evaluate vulnerabilities and act on what you find, and a pentest report is the ordinary way a startup evidences that. Treat it as evidence for a control, not as the control itself: a report alone has never satisfied a criterion, and an auditor will ask what you did about the findings.
What is the difference between a SOC 2 Type 1 and a Type 2 report?
A Type 1 report describes whether your controls were suitably designed at a single point in time. A Type 2 report tests whether they actually operated effectively across a window, which is why it takes longer and carries more weight with an enterprise buyer. The difference is what the auditor tests, not how long the engagement runs.
Which Trust Services Criteria do we have to include?
Security is the common criteria set and is mandatory. Availability, processing integrity, confidentiality and privacy are added only if you commit to them. Scoping in a category you do not need is the most common way a first SOC 2 becomes more expensive and slower than it had to be.
Can Cybersecify issue our SOC 2 report?
No, and no consultancy can. A SOC 2 report is issued by a licensed CPA firm. We do the readiness work: the gap assessment, the policies, the control implementation guidance, the evidence pack and the penetration test that backs it. Keeping readiness and audit in separate hands is what makes the opinion worth something to the customer who asked you for it.
What we have written about SOC 2
- SOC 2 Readiness for Indian Startups
- SOC 2 Type 1 vs Type 2: What Indian Startups Need to Know
- SOC 2 Trust Services Criteria Explained
- Penetration Testing for SOC 2 Audit: What Auditors Expect
- Investor Asked for SOC 2? Here’s What to Do
- SOC 2 Dos and Don’ts for SaaS Startups
- Vanta vs Drata vs Sprinto vs Manual SOC 2 (India 2026)
Tell us what the deadline is
An auditor booked, a customer security review, an investor asking, or a renewal due. The date changes the scope and the order of the work, so it is the first thing we ask. Both co-founders are on the call.
Where these requirements come from
Everything this page says about the standards body or regulator's requirements is taken from their own published documentation, linked below and last checked on 2026-10-06. We quote the requirement rather than our reading of it wherever the difference matters.
Our aim is to describe these requirements as accurately and as currently as we can, and to show you where to check us. We are reading someone else's documentation: a standards body or a regulator can revise it without an announcement, and our reading of it can be imprecise or go out of date.
How we source, draft and review what we publish, including where software sits in the drafting, is set out in our editorial policy. A page like this is only as good as the date on it, so we re-read the sources on a standing audit, date what we checked, and update the page when a source moves or when we can state something more precisely.
If something here no longer matches the source, tell us at errors@cybersecify.com. We will review it against the source and tell you what we decide; where it needs changing we change it and date the change.
This page is published for information. It is a best-effort account of someone else's published requirements, not a commitment about your engagement: what we deliver, and what it costs, is set out in the Statement of Work both parties sign, and our terms state that where website content and a signed agreement differ, the signed agreement governs.