SOC 2 readiness work prepares a service organization for an independent CPA firm's attestation against the AICPA's Trust Services Criteria.
This means a readiness assessment against the relevant criteria (Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are added based on what the product needs), closing control gaps, and designing the evidence-collection process the attesting firm will examine. A Type I report covers a single point in time; a Type II report — which carries more weight with enterprise buyers — covers control effectiveness over a 3-12 month observation period.
Report types supported
AICPA
AICPA Trust Services Criteria