Skip to content

SOC 2 and PCI DSS readiness

Someone asked for your SOC 2 report. Find the gaps before the auditor does.

Readiness and remediation before your SOC 2 examination or your PCI DSS assessment. Controls tested against the full population, gaps closed in order of what they are worth, and one body of evidence mapped to every framework it satisfies.

Your problem

A deal is waiting on a report you have never been through

  • A partner bank, an enterprise customer or a card network has asked for a SOC 2 report or PCI DSS compliance, and the deal waits until you have it.
  • The examination is performed by a licensed CPA firm for SOC 2, or a Qualified Security Assessor for PCI DSS. The work that decides how it goes happens before they arrive.
  • Most teams assemble the same evidence several times over, once for each framework.
  • And most find their gaps when the auditor does, which is the most expensive time to find them.

What you get

No surprises on examination day

  • A readiness assessment against the criteria in scope, with each gap cited and priced.
  • A remediation plan in the order that removes the most exposure first.
  • An evidence set organised the way your auditor or assessor will request it, reusable for the next framework.
  • Work papers for every control tested.

How we do it

Map once, test everything, close in order

  • We map your controls to the criteria that apply: the SOC 2 trust services criteria in scope, or the PCI DSS requirements for your environment.
  • The engine tests the controls against the full population of records, so you know which ones hold before the auditor samples them.
  • We rank the gaps by what each one is worth and work through remediation with your team.
  • A control tested once is mapped to every framework it satisfies, so SOC 2, PCI DSS and your banking requirements draw on the same evidence.

We prepare you for the examination and the assessment. We don't issue a SOC 2 report or a PCI DSS report on compliance; the licensed firm or assessor you engage does.

How the work is done

The audit you already buy, performed by an engine.

  1. Every record testedControls are tested against the full population of accounts and transactions, not a sample of twenty-five.
  2. Every requirement citedEach requirement the work runs against is cited to the rule it comes from, with the facts behind it labelled.
  3. Findings pricedFindings arrive priced in dollars, so remediation is ordered by what each gap is worth.
  4. A signed reportThe report is signed, and any reader can check that nothing in it changed after signing.

Pricing

Less than the months it usually takes

This replaces a readiness consultant, or the months of internal time that usually go into preparing for a first examination.

SOC 2 readiness: Priced at scoping. PCI DSS readiness: Priced at scoping. How pricing works

The published method

How this is normally done

The regulator's and the standard-setter's own method for this work, explained in plain English and cited to the source. We have nothing to hide about how we do it: check our process against it.

What happens next

Three steps from here.

  1. 01

    A scoping call

    Who asked for the report, by when, and which systems and criteria are in scope.

  2. 02

    The readiness assessment

    Every control tested against the criteria, with each gap cited, priced and put in order.

  3. 03

    Close and hand over

    We work the gaps with your team and hand your auditor or assessor an evidence set they can use.

SOC 2 readiness. Ask for a quote

PCI DSS readiness. Ask for a quote