SOC 2 and HIPAA readiness

Programs

SOC 2 Type I

Reuse: 100% of the base. Extra: Auditor and a 3-month runway.

SOC 2 Type II

Reuse: Base plus ongoing evidence. Extra: 3 to 12 month observation window, usually after Type I.

HIPAA

Reuse: About 80%. Extra: Risk analysis, BAAs, training (health clients).

Investor due diligence

Reuse: About 85%. Extra: Data-room index.

ISO 27001

Reuse: About 75%. Extra: ISMS, Statement of Applicability, internal audit (on demand).

Pricing

Frequently asked questions

How long until we are SOC 2 Type I ready?

Typically about 3 months of runway before the audit.

Do you do the audit?

No. An independent auditor does the audit, client-paid at cost. We prepare you and support you through the audit.

Which GRC platform do you use?

We work with your choice of GRC platform, or recommend one that fits your stack.

Do we need HIPAA if we are not in health care?

Only if you handle protected health information for covered entities.

Can we start with investor due diligence?

Yes. It is the lightest program and reuses about 85% of the base control set.