SOC 2 compliance means a CPA firm has examined your controls against the AICPA Trust Services Criteria and issued a Type I or Type II report. IRM gets first-time SaaS companies Type I audit-ready in 90 days and manages the program through Type II.
SOC 2 compliance means a licensed CPA firm has examined your company's controls against the AICPA Trust Services Criteria and issued a SOC 2 report: a Type I report on control design at a point in time, or a Type II report on how those controls operated over a period, usually 3 to 12 months. SOC 2 is an attestation, not a certification, and it has become the security credential enterprise buyers ask a SaaS vendor for before they sign.
IRM's SOC 2 compliance service is the readiness side of that process. We scope your report, run a gap assessment against all 61 Trust Services Criteria, design and document the missing controls, stand up evidence collection, and manage the CPA firm relationship so the examination itself holds no surprises. Most first-time SaaS clients reach Type I audit-ready within 90 days; Type II follows once the observation window has run.
The work is led by a Virtual CISO, so the same person who closes your SOC 2 gaps also owns your GRC program, answers customer security questionnaires, and keeps the controls operating after the report is issued. If you also need ISO 27001, the two programs share the large majority of their controls and we run them as one project through our ISO 27001 consulting service.
If no customer or prospect has asked for a SOC 2 report, and your buyers accept a completed security questionnaire, you are usually better off running a free gap assessment now and spending the audit budget later. SOC 2 has real recurring costs: the CPA firm, the automation platform, and the operating effort of keeping evidence current every month.
If your buyers are in Europe or Asia-Pacific and ask about ISO 27001 instead, start there. If your buyers are US defense primes, they will ask for CMMC, not SOC 2. Tell us who is asking and for what, and we will tell you which framework to sequence first.
The right SOC 2 scope and pace depend on how much revenue is waiting on the report. This is how we size engagements for the SaaS companies we work with.
| Stage | Typical ARR | What You Need | IRM Engagement |
|---|---|---|---|
| Pre-seed and bootstrapped | Under $1M ARR | A completed security questionnaire and a credible plan. SOC 2 is usually premature unless one signed deal depends on it. | Free SOC 2 gap assessment, then a Crawling tier sprint to close the top 10 gaps and answer questionnaires. |
| Seed | $1M to $5M ARR | First SOC 2 Type I, Security category only, so mid-market deals stop stalling in procurement. | Walking tier, 90 days to Type I audit-ready, CPA firm engaged in month 3. |
| Series A and B | $5M to $25M ARR | SOC 2 Type II, often with Availability and Confidentiality, plus a vendor risk program enterprise buyers will inspect. | Walking or Running tier, Type I in 90 days then a 3 to 6 month observation period into Type II. |
| Growth and PE-backed | $25M+ ARR | Annual Type II renewals, SOC 2 plus ISO 27001 in one control set, and board-level reporting on control health. | Running tier managed GRC program with a named vCISO and quarterly control reviews. |
This is the sequence we run for a first SOC 2 Type I. Type II adds an observation period after day 90 in which the same controls keep producing evidence.
SOC 2 readiness is delivered as a monthly Virtual CISO subscription, so you pay for the hours the program needs rather than a fixed project fee that assumes the worst case.
From $4,250 per month
20 to 40 hours per month, sprint under 6 months. Excludes the CPA firm audit fee and any compliance automation platform license.
Bootstrapped teams closing a handful of gaps can start on the Crawling tier from $2,000 per month (15 to 20 hours). Companies running SOC 2 and ISO 27001 together, or maintaining a Type II program year over year, sit on the Running tier from $6,950 per month. Pre-packaged Cyber and AI bundles start at $4,950.
See all Pricing TiersAssess all 61 Trust Services Criteria for Type I or Type II, score each gap on a 5x5 risk matrix, and download a remediation roadmap. Your answers stay in your browser.
Run the SOC 2 Gap AssessmentBook a Free ConsultationBring the report to your free consultation and we will turn it into a scoped 90-day plan on the call. Related: ISO 42001 consulting for SaaS companies shipping AI features, and Fractional CISO services if you need the leadership as well as the report.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


