SOC 2 readiness
SOC 2 ready in six weeks, enforced on every deploy.
Vanta or Drata tells you what is broken. We fix the AWS behind it, put the controls in code so they cannot drift, and export the evidence continuously. Your auditor gets a clean environment and a current trail.


- Sage AI
Access review due. 41 IAM identities listed with last use and approver. Two unused roles flagged for removal.
Reviewed and signed by the platform lead, Mon 11:20 - Sage AI
Weekly restore test: production database restored to an isolated account from last night's backup. 14 minutes.
Evidence exported to the compliance platform - ClearRisk
CVE published for a library in two images. Reachable in one service. Patch pull request opened.
Merged after review, Wed 16:30 - Sage AI
Deploy blocked: pull request changes a security group without an approver. Returned with the policy that failed.
Approved and merged with a recorded reviewer - Summary
Controls passing: 100%. Evidence current for 38 of 38 mapped controls. Nothing waiting on a person.
Posted to #compliance
Why six weeks
The work is in the infrastructure, not the spreadsheet.
Readiness stalls when controls are documented but not enforced, and when evidence has to be collected by hand. We remove both problems at the source.
Controls as code
IAM, encryption, logging, backups and change management live in Terraform and pipeline policy, with recorded approvals. A control written in code cannot quietly drift back.
Evidence that exports itself
Access reviews, backup tests, key rotation and deploy approvals are produced by the systems that run them and exported continuously. Nobody assembles screenshots in the audit week.
Engineers who have done it before
The same team has taken fintech and crypto companies through readiness while keeping their releases moving. They know which findings matter and which are paperwork.
Week by week
Read-only on day one. Auditor-ready by week six.
- Week 1
Gap review and scorecard
Read-only access to your AWS and your compliance platform. Every control mapped to what exists today, with a scorecard of what we fix first and what is already fine.
- Weeks 2 to 3
Controls in code
Sage and ClearRisk put the controls in place: least-privilege IAM, encryption at rest and in transit, centralized logging, backup and restore tests, vulnerability management, and pipeline gates with approvals.
- Weeks 4 to 5
Evidence and operations
Evidence automation wired to your platform, policies written to match how you actually work, access reviews run, and a disaster recovery run that is tested rather than described.
- Week 6
Readiness review and handoff
A final pass against the control list with your auditor's requests in mind, then handoff. From here the evidence keeps exporting and the gates keep running.
What ends up in place
Controls you can point an auditor at.
Each one lives in Terraform or pipeline policy in your repositories, so it is enforced by the system rather than by a reminder.
- Least-privilege IAM with SSO, MFA and a recorded quarterly access review
- Encryption at rest and in transit on every data store and every load balancer
- Centralized, immutable logging with retention that matches your policy
- Backups on a schedule, restore tested regularly, results exported as evidence
- Vulnerability management: CVEs checked against what runs, patches as pull requests
- Change management: every infrastructure change is a pull request with a named approver
- Pipeline gates that block a deploy when a policy fails, with the reason attached
- Monitoring and incident response with a written process and a tested pager
- A disaster recovery plan that has been run, not only written
- Policies and vendor reviews kept in your compliance platform, current
Works with your platform and auditor
We feed the evidence. We do not replace the system of record.
Vanta, Drata, Secureframe or your auditor's own portal stays where it is. We fix what it flags, wire the evidence so it arrives on its own, and answer the auditor's requests from the export rather than from memory.
If you have not chosen a platform yet, we will tell you what each one automates well for an AWS estate and set it up alongside the controls.
Beyond SOC 2
The same controls carry the other frameworks.
ISO 27001, PCI DSS, HIPAA, SLSA Level 3 and GDPR share most of their technical controls with SOC 2. Once the AWS is in code, adding a framework is mostly mapping, not rebuilding.
Pricing
Fixed before we start.
SOC 2 readiness is part of the Growth tier of the managed plan, where the same engineers keep running your AWS after the audit. If you only need readiness, it runs as a scoped fixed-price project instead.
No hourly billing and no change orders for routine work. The price is quoted after the week 1 review, once we know how far your environment is from the control list.
See how pricing worksQuestions
About SOC 2 readiness.
Is this SOC 2 Type I or Type II?
Readiness in six weeks means the controls are in place, operating and producing evidence, which is what a Type I examines. A Type II report follows the observation window your auditor sets, and the same controls and evidence carry you through it.
Do you replace Vanta or Drata?
No. Your compliance platform stays the system of record. We fix the infrastructure it flags, put the controls in code and feed it evidence, so the dashboard turns green and stays green.
Do you perform the audit?
No. A licensed auditor issues the report. We prepare the environment, map the evidence to their control list and answer their requests during the examination.
We are on GCP or Azure. Does this still work?
Yes. Sage is multi-cloud and the controls translate. Most engagements are on AWS, which is where the deepest automation is, and the six-week timeline assumes an AWS estate.
What does it cost?
SOC 2 readiness is included in the Growth tier of the managed plan, or it runs as a scoped fixed-price project if you only need readiness. Either way the price is fixed before we start and there is no hourly billing.
Will this slow our deployments?
No. The gates run inside the pipeline and approvals are recorded where the pull request already lives. Nobody waits in a queue, and a blocked deploy comes back with the exact policy that failed.
See how far you are from ready.
Book a demo with an engineer. Share your compliance platform's findings on the call and leave with the week 1 review scoped.