Security · Fractional CISO

SOC 2 and ISO 27001 readiness, led by a fractional CISO

Enterprise buyers, banks and investors ask for proof. We design the controls, write the policies, prepare the evidence and stay with you through the audit, alongside the independent firm that issues the report.

When companies bring us in

A questionnaire arrives

A large customer sends a security questionnaire the founders can't answer, and the deal waits.

Diligence asks

A Series A lead or a partner bank asks how customer data is handled and who is accountable for it.

The platform shows gaps

Your compliance platform reports gaps the team can't close on its own.

The path to the audit

  1. Gap assessmentYour current controls measured against SOC 2 or ISO 27001, with a plan and an order of work.
  2. Controls and policiesThe control environment designed and the policy suite written for your board to adopt.
  3. EvidenceEvidence collected and organized, inside your compliance platform where you have one.
  4. AuditYou are prepared for the independent audit firm, and we stay with you through fieldwork.

What we cover

SOC 2

  • Type IControls designed and in place at a point in time.
  • Type IIControls operating over an observation period agreed with your audit firm.

ISO 27001

  • An information security management system built to the standard
  • Certified by an accredited body in a two-stage audit

Questionnaires and diligence

  • Customer security questionnaires and reviews
  • Investor and partner diligence, answered in writing and defended in the meeting
  • AI and vendor risk

Regulated companies

  • Charter-track banks, neobanks and stablecoin issuers
  • Third-party risk and information security programs
  • Examiner-ready evidence, prepared alongside counsel

How long it takes

Readiness work typically takes six to twelve weeks for a company of up to fifty people on modern cloud infrastructure, and less where basic controls are already in place. A SOC 2 Type I report can follow soon after. A Type II report covers an observation period, usually three to twelve months, set with your audit firm. ISO 27001 certification follows a two-stage audit by an accredited body.

Timelines depend on scope and on how much is already in place. You get an honest estimate after the gap assessment, before you commit to the rest.

Questions

How long does SOC 2 take?

Readiness work typically takes six to twelve weeks for a company of up to fifty people on modern cloud infrastructure, and less where basic controls are already in place. A Type I report can follow soon after. A Type II report covers an observation period, usually three to twelve months, set with your audit firm. We give you an honest estimate after the gap assessment.

What is the difference between SOC 2 Type I and Type II?

A Type I report covers whether controls are designed and in place at a point in time. A Type II report covers whether they operated effectively over a period, usually several months. Many enterprise buyers ask for Type II; a Type I can unblock a deal sooner.

Do we need SOC 2 or ISO 27001?

U.S. enterprise buyers usually ask for SOC 2. Customers in Europe and elsewhere often ask for ISO 27001. We help you pick the one your buyers ask for first, and build controls that serve both.

Are you the auditor?

No. SOC 2 reports are issued by licensed CPA firms, and ISO 27001 certificates by accredited certification bodies. Independence rules keep the auditor from designing the controls it examines, which is the work we do.

Do we still need a compliance platform?

Often, yes. Platforms collect evidence and monitor controls. We design the control environment, write the policies and answer customers and banks in their own terms, and we work inside the platform you already use.