SOC 2 and HIPAA readiness
Programs
SOC 2 Type I
Reuse: 100% of the base. Extra: Auditor and a 3-month runway.
SOC 2 Type II
Reuse: Base plus ongoing evidence. Extra: 3 to 12 month observation window, usually after Type I.
HIPAA
Reuse: About 80%. Extra: Risk analysis, BAAs, training (health clients).
Investor due diligence
Reuse: About 85%. Extra: Data-room index.
ISO 27001
Reuse: About 75%. Extra: ISMS, Statement of Applicability, internal audit (on demand).
Pricing
- 1st program: $10/user/mo
- 2nd program: $5/user/mo
- 3rd and later: $2.50/user/mo each
Frequently asked questions
How long until we are SOC 2 Type I ready?
Typically about 3 months of runway before the audit.
Do you do the audit?
No. An independent auditor does the audit, client-paid at cost. We prepare you and support you through the audit.
Which GRC platform do you use?
We work with your choice of GRC platform, or recommend one that fits your stack.
Do we need HIPAA if we are not in health care?
Only if you handle protected health information for covered entities.
Can we start with investor due diligence?
Yes. It is the lightest program and reuses about 85% of the base control set.