SOC 2 readiness assessment
End-to-end SOC 2 readiness.From pre-assessment to audit day.
Scope your Trust Services Criteria, build controls that actually run, and walk into fieldwork with network evidence your CPA firm can verify — produced on site by Citadel Audit, signed, and never sent to anyone's cloud.
Evidence you can verify, not claims you have to trust
How we get you ready
Stop chasing screenshots. Start producing evidence.
Most readiness projects fail the same way: policies written in a two-week scramble and evidence gathered the night before the auditor asks. We run it in the right order.
Evidence from the network itself
Citadel Audit discovers every device on the segment, attributes its manufacturer and records exposed services — the asset inventory and network evidence auditors ask for first.
- On-site, agentless, no credentials
- Findings cite the literal observation
- NDAA Section 889 and shadow-AI screening
A readiness program that runs
A Type 2 report tests controls over months, not a single day. We scope your criteria, design controls, write policies that match how your team works and track remediation across the observation window.
- Trust Services Criteria scoping
- Control design and policy
- Remediation tracked to closure
Audit-ready for your CPA firm
Hand your auditor an organised package: the authorisation of record, framework-mapped findings, a remediation plan and signed evidence they can verify with open-source tooling.
- Executive report + signed evidence file
- Mapped to AICPA Trust Services Criteria
- We coordinate evidence requests
Manual vs. GRYHAT
What changes when evidence is produced, not collected
| Capability | Manual compliance | With GRYHAT + Citadel |
|---|---|---|
| Asset inventory | Spreadsheet reconciled by hand, out of date the day it is finished. | Every device on the segment discovered on site, attributed to its manufacturer. |
| Network evidence | Screenshots of firewall consoles and exported config files. | Observed exposure per host, cited to the literal observation, in a signed evidence file. |
| Control mapping | Findings translated into Trust Services Criteria after the fact. | Findings carry the specific criteria they implicate — CC6.1, CC6.6, CC6.8. |
| Evidence integrity | PDFs and spreadsheets anyone could have edited. | Ed25519 signatures your auditor verifies with open-source tooling. |
| Readiness program | Policies written in a scramble the month before fieldwork. | Scoping, control design, policy and remediation run by a GRYHAT lead ahead of the audit window. |
Don't let security questionnaires stall your pipeline
Unblock security reviews with a readiness program and evidence your buyers' security teams can check for themselves.
The basics
What is SOC 2 compliance?
SOC 2 (System and Organization Controls 2) is an attestation framework, developed by the American Institute of Certified Public Accountants (AICPA), that defines how service organisations — cloud providers, SaaS companies, managed IT vendors — must safeguard customer data.
An independent, licensed CPA firm evaluates your controls against five Trust Services Criteria. It is not a legal mandate, but enterprise procurement increasingly requires a report before contracts are signed — and the work aligns closely with CCPA, GDPR and HIPAA.
| Trust criteria | What it evaluates | Objective |
|---|---|---|
| SecurityRequired | Firewalls, access controls, threat prevention and physical security. | Prevents unauthorised system access and protects data against breaches. |
| Availability | Performance monitoring, disaster recovery and system uptime. | Keeps systems operationally accessible and resilient. |
| Processing Integrity | Data inputs and outputs, QA testing and transaction validation. | Processing is timely, accurate, complete and authorised. |
| Confidentiality | Data classification, encryption and secure handling policies. | Protects proprietary and sensitive information restricted to specific users. |
| Privacy | Collection practices, consent mechanisms and regulatory alignment. | Personal information is handled ethically and lawfully. |
Type 1
Assesses the design of your controls at a single point in time. A starting point for a first enterprise security review.
Type 2
Assesses operating effectiveness over an observation period, typically 3 to 12 months. What mature buyers expect.
Audit checklist
The 10 domains a SOC 2 audit examines
Domains marked CITADEL EVIDENCE are where Citadel Audit produces direct, signed network evidence. The rest are covered by the readiness program.
- 01
Governance & Leadership
Organisational hierarchy, governance policies and continuous risk assessment.
- 02
Human Resources
Background checks, security awareness training and formal offboarding.
- 03
Identity & Access Management
MFA, role-based access control and scheduled access reviews.
- 04
Network & Infrastructure SecurityCitadel evidence
Segmentation, exposed services, intrusion detection and penetration testing.
- 05
Physical & Environmental
Facility access logs, surveillance and environmental controls.
- 06
System OperationsCitadel evidence
Asset inventory, centralised monitoring, alerting, logging and incident management.
- 07
Change Management
Formal workflows, test environments, code review and approval before release.
- 08
Data Protection & EncryptionCitadel evidence
Classification, encryption at rest and in transit, retention policies.
- 09
Disaster Recovery & Continuity
Automated backups, failover testing and documented recovery procedures.
- 10
Vendor ManagementCitadel evidence
Third-party risk assessment, SLAs and hardware / supplier provenance.
Effort estimator
How many prep hours could you get back?
Adjust the assumptions to match your team.
Planning estimate of internal preparation effort only. Model: Type 1 ≈ 200 h + 0.5 h per employee; Type 2 ≈ 380 h + 1 h per employee, reduced by the automation share you set. Excludes CPA audit fees and GRYHAT engagement fees. Not a quote.
Common confusion
SOC 1 vs. SOC 2
| Feature | SOC 1 | SOC 2 |
|---|---|---|
| Primary focus | Internal controls over financial reporting (ICFR). | Security, availability, processing integrity, confidentiality and privacy. |
| Audience | Financial auditors, CFOs and accounting teams. | CISOs, compliance teams, IT buyers and customers. |
| Objective | Verifies accuracy and integrity of financial reporting. | Verifies operational safeguards for systems and customer data. |
| Typical use | Payroll providers, financial SaaS, billing platforms. | B2B SaaS, IT infrastructure, managed service and hosting providers. |
Powered by Citadel Audit
Start with one on-site meeting
See every device on your network, mapped to CC6.1, CC6.6 and CC6.8, with a signed report you keep — before you commit to a readiness program.
How Citadel Audit worksFAQ
Frequently asked questions
Only an independent, licensed CPA firm can issue a SOC 2 report. GRYHAT is not a CPA firm: we prepare you for the audit — scoping, controls, evidence and remediation — and work alongside the CPA firm you engage.
Type 1 assesses the design of your controls at a single point in time. Type 2 assesses their operating effectiveness over an observation period, typically three to twelve months. Most enterprise buyers ask for Type 2.
Citadel produces signed, on-premises network evidence — a verified device inventory, exposed services per host and hardware provenance — mapped to Common Criteria CC6.1, CC6.6 and CC6.8. It covers the network portion of the Security criterion; it does not replace policy, HR, change-management or vendor controls.
No. It is a voluntary attestation, but enterprise procurement teams increasingly require a report before signing, and it aligns closely with GDPR, CCPA and HIPAA obligations.
An internal stakeholder accountable for the governance, classification, quality and security of a specific dataset. Data owners set usage policy, approve access and make sure handling standards are met.
Frameworks for deciding how users get access to systems and data. The common ones are role-based (RBAC), attribute-based (ABAC) and discretionary (DAC) access control.
Ready to work toward your SOC 2 report?
Schedule a one-on-one session with a GRYHAT compliance lead. We'll review your current posture, identify gaps and build a roadmap to audit readiness.



