SOC 2 readiness assessment

End-to-end SOC 2 readiness.From pre-assessment to audit day.

Scope your Trust Services Criteria, build controls that actually run, and walk into fieldwork with network evidence your CPA firm can verify — produced on site by Citadel Audit, signed, and never sent to anyone's cloud.

Book a free strategy call

Evidence you can verify, not claims you have to trust

15sto inventory a /24 on site
CC6.1 · 6.6 · 6.8Common Criteria cited per finding
Ed25519signed evidence your CPA can verify
0outbound connections from the scanner

How we get you ready

Stop chasing screenshots. Start producing evidence.

Most readiness projects fail the same way: policies written in a two-week scramble and evidence gathered the night before the auditor asks. We run it in the right order.

Evidence from the network itself

Citadel Audit discovers every device on the segment, attributes its manufacturer and records exposed services — the asset inventory and network evidence auditors ask for first.

  • On-site, agentless, no credentials
  • Findings cite the literal observation
  • NDAA Section 889 and shadow-AI screening

A readiness program that runs

A Type 2 report tests controls over months, not a single day. We scope your criteria, design controls, write policies that match how your team works and track remediation across the observation window.

  • Trust Services Criteria scoping
  • Control design and policy
  • Remediation tracked to closure

Audit-ready for your CPA firm

Hand your auditor an organised package: the authorisation of record, framework-mapped findings, a remediation plan and signed evidence they can verify with open-source tooling.

  • Executive report + signed evidence file
  • Mapped to AICPA Trust Services Criteria
  • We coordinate evidence requests

Manual vs. GRYHAT

What changes when evidence is produced, not collected

CapabilityManual complianceWith GRYHAT + Citadel
Asset inventorySpreadsheet reconciled by hand, out of date the day it is finished.Every device on the segment discovered on site, attributed to its manufacturer.
Network evidenceScreenshots of firewall consoles and exported config files.Observed exposure per host, cited to the literal observation, in a signed evidence file.
Control mappingFindings translated into Trust Services Criteria after the fact.Findings carry the specific criteria they implicate — CC6.1, CC6.6, CC6.8.
Evidence integrityPDFs and spreadsheets anyone could have edited.Ed25519 signatures your auditor verifies with open-source tooling.
Readiness programPolicies written in a scramble the month before fieldwork.Scoping, control design, policy and remediation run by a GRYHAT lead ahead of the audit window.

Don't let security questionnaires stall your pipeline

Unblock security reviews with a readiness program and evidence your buyers' security teams can check for themselves.

Start your SOC 2 journey

The basics

What is SOC 2 compliance?

SOC 2 (System and Organization Controls 2) is an attestation framework, developed by the American Institute of Certified Public Accountants (AICPA), that defines how service organisations — cloud providers, SaaS companies, managed IT vendors — must safeguard customer data.

An independent, licensed CPA firm evaluates your controls against five Trust Services Criteria. It is not a legal mandate, but enterprise procurement increasingly requires a report before contracts are signed — and the work aligns closely with CCPA, GDPR and HIPAA.

Trust criteriaWhat it evaluatesObjective
SecurityRequiredFirewalls, access controls, threat prevention and physical security.Prevents unauthorised system access and protects data against breaches.
AvailabilityPerformance monitoring, disaster recovery and system uptime.Keeps systems operationally accessible and resilient.
Processing IntegrityData inputs and outputs, QA testing and transaction validation.Processing is timely, accurate, complete and authorised.
ConfidentialityData classification, encryption and secure handling policies.Protects proprietary and sensitive information restricted to specific users.
PrivacyCollection practices, consent mechanisms and regulatory alignment.Personal information is handled ethically and lawfully.

Type 1

Assesses the design of your controls at a single point in time. A starting point for a first enterprise security review.

Type 2

Assesses operating effectiveness over an observation period, typically 3 to 12 months. What mature buyers expect.

Audit checklist

The 10 domains a SOC 2 audit examines

Domains marked CITADEL EVIDENCE are where Citadel Audit produces direct, signed network evidence. The rest are covered by the readiness program.

  1. 01

    Governance & Leadership

    Organisational hierarchy, governance policies and continuous risk assessment.

  2. 02

    Human Resources

    Background checks, security awareness training and formal offboarding.

  3. 03

    Identity & Access Management

    MFA, role-based access control and scheduled access reviews.

  4. 04

    Network & Infrastructure SecurityCitadel evidence

    Segmentation, exposed services, intrusion detection and penetration testing.

  5. 05

    Physical & Environmental

    Facility access logs, surveillance and environmental controls.

  6. 06

    System OperationsCitadel evidence

    Asset inventory, centralised monitoring, alerting, logging and incident management.

  7. 07

    Change Management

    Formal workflows, test environments, code review and approval before release.

  8. 08

    Data Protection & EncryptionCitadel evidence

    Classification, encryption at rest and in transit, retention policies.

  9. 09

    Disaster Recovery & Continuity

    Automated backups, failover testing and documented recovery procedures.

  10. 10

    Vendor ManagementCitadel evidence

    Third-party risk assessment, SLAs and hardware / supplier provenance.

Effort estimator

How many prep hours could you get back?

Adjust the assumptions to match your team.

Report type
25 people
$85/hr
50%
203 hHours saved
$17,213Labor avoided
203 hPrep hours
Manual preparation405 h · $34,425
With automated evidence203 h · $17,213

Planning estimate of internal preparation effort only. Model: Type 1 ≈ 200 h + 0.5 h per employee; Type 2 ≈ 380 h + 1 h per employee, reduced by the automation share you set. Excludes CPA audit fees and GRYHAT engagement fees. Not a quote.

Common confusion

SOC 1 vs. SOC 2

FeatureSOC 1SOC 2
Primary focusInternal controls over financial reporting (ICFR).Security, availability, processing integrity, confidentiality and privacy.
AudienceFinancial auditors, CFOs and accounting teams.CISOs, compliance teams, IT buyers and customers.
ObjectiveVerifies accuracy and integrity of financial reporting.Verifies operational safeguards for systems and customer data.
Typical usePayroll providers, financial SaaS, billing platforms.B2B SaaS, IT infrastructure, managed service and hosting providers.
Citadel Audit app icon

Powered by Citadel Audit

Start with one on-site meeting

See every device on your network, mapped to CC6.1, CC6.6 and CC6.8, with a signed report you keep — before you commit to a readiness program.

How Citadel Audit works

FAQ

Frequently asked questions

Only an independent, licensed CPA firm can issue a SOC 2 report. GRYHAT is not a CPA firm: we prepare you for the audit — scoping, controls, evidence and remediation — and work alongside the CPA firm you engage.

Ready to work toward your SOC 2 report?

Schedule a one-on-one session with a GRYHAT compliance lead. We'll review your current posture, identify gaps and build a roadmap to audit readiness.

Let's Connect

Get Your Free Security Assessment

Drop your info below and we'll reach out with a personalized security roadmap for your business.
You may also opt in to receive secure 2FA login codes via SMS from GRYHAT CYBERSECURITY LLC.

or