Compliance Frameworks

SOC 2 readiness your auditor can actually verify

Updated September 2026

SOC 2 has become the default trust question in B2B sales - procurement sends the questionnaire, the prospect wants the report, and the pipeline stalls until both exist. The report is the easy part. The hard part is operating controls that produce evidence all year, because a Type 2 opinion is a look backward at whether you actually did what you said. Class IV runs SOC 2 the way it needs to be run: as an operating condition inside your IT environment. Our fractional CISO scopes the Trust Services Criteria your business can honestly commit to, closes the gaps in access management, change management, monitoring, and vendor oversight, and keeps the evidence flowing so the auditor samples controls, not stories. For Denver and Houston companies with 30 to 100 employees, that means the SOC 2 conversation stops blocking deals - and stays solved after the report arrives.

Type 1 vs Type 2: what each one proves

A Type 1 report is a point-in-time opinion. The auditor confirms that your controls are designed appropriately and in place on a specific date. A Type 2 report covers an observation period, and the auditor tests whether those controls actually operated, consistently, across that window. The difference matters to buyers. A Type 1 shows you have a plan. A Type 2 shows you followed it, which is why procurement teams and security reviewers increasingly ask for Type 2 by name. Many companies start with a Type 1 to unblock early deals, then move into a Type 2 observation period. That path works only if the controls are running from day one, because the Type 2 looks backward at what you did, not forward at what you intend.

Choosing your Trust Services Criteria

Security is the one required criterion, and every SOC 2 report includes it. The other four are commitments you choose to make: availability, confidentiality, processing integrity, and privacy. Each one you add expands the controls the auditor will test and the evidence you have to produce. The mistake is scoping maximally because it looks stronger on paper. Adding a criterion you cannot operate consistently turns into exceptions in the report, which buyers read closely. Scope honestly instead. Start from what your customers actually rely on you for: uptime commitments point to availability, sensitive client data points to confidentiality, and transaction accuracy points to processing integrity. We help you choose the criteria your business can stand behind every day, then expand the scope as your operations mature.

The controls that break most first attempts

Four areas cause most first-attempt trouble. Access management fails when accounts are not removed promptly or access reviews are skipped; the evidence is dated review records and offboarding tickets that match your HR changes. Change management fails when changes reach production without approval or testing; the evidence is tickets showing request, review, approval, and deployment. Monitoring fails when alerts fire but nobody documents the response; the evidence is logs, alert records, and the follow-up for each. Vendor oversight fails when critical vendors are never reviewed; the evidence is a vendor inventory, risk ratings, and the SOC reports or questionnaires you collected. Because our managed services team runs these processes, the evidence is produced as a byproduct of normal operations rather than reconstructed before fieldwork.

Readiness, report, and the year after

Readiness is where the work starts: scoping, a gap assessment against your chosen criteria, remediation, and policies that match how you really operate. Then comes the audit itself, with an observation period for Type 2 and fieldwork where the auditor samples your evidence. Most companies treat the report as the finish line. It is the beginning. Customers expect a fresh report every year, and each new observation period tests whether controls kept running after the first audit. Programs that relax after the report arrive at year two with gaps, exceptions, and a scramble to rebuild evidence. We keep the controls running, the evidence current, and the scope aligned with how your business changes, so each renewal is routine and the answers you give customers stay true.

One partner from gap to audit

Most SOC 2 efforts stall between the people who write the policies and the people who run the systems. The 10-day Stabilization Sprint is the entry point: it maps your environment against the Trust Services Criteria, surfaces the gaps, and turns them into a prioritized plan with owners. From there, your fractional CISO and our managed services team carry the program from gap to audit.

Frequently asked questions

Does my company need SOC 2 if we do not store customer data?
Often, yes. SOC 2 covers any system that affects the security of the services you provide, not only stored data. If you process, transmit, or access customer information, or your platform touches their operations, buyers may still ask for it. The practical test is whether prospects keep sending security questionnaires that stall deals.
What is the difference between SOC 2 and ISO 27001?
SOC 2 is an attestation report from a CPA firm, built on the Trust Services Criteria and most common with North American buyers. ISO 27001 is a certification to an international standard for an information security management system, more common with global customers. The controls overlap heavily, so a well-run program can support both.
Can we pass a SOC 2 audit without a compliance hire?
Yes. What a SOC 2 program needs is senior ownership and controls that run consistently, not necessarily a full-time compliance employee. A fractional CISO can own scoping, policies, auditor coordination, and evidence, while a managed services team operates the technical controls. That combination gives you accountability without adding headcount.
What do auditors actually sample during a Type 2 review?
Auditors select samples across the observation period and ask for proof each control operated. Typical requests include access reviews, onboarding and offboarding records, change tickets with approvals, security alerts and their responses, backup and recovery tests, vendor reviews, and training completion. Gaps in any sample become exceptions that appear in your report.
Do you support SOC 2 clients outside Colorado?
Yes. Denver and Houston are our primary markets, and our fractional CISO leadership and managed services are delivered remotely nationwide. Scoping, readiness, control operation, evidence management, and auditor coordination all work across locations, so companies outside Colorado get the same program, with on-site support arranged when an engagement calls for it.