01 The challenge
The engineering team was small and focused on product. Access control, logging, change management, vendor management and incident response existed informally at best. The deadline was fixed by the customer, and failing it meant losing the contract and the enterprise pipeline behind it.
02 What we did
- Gap assessment against SOC 2 Trust Services Criteria, prioritised by audit impact
- Security engineering: SSO and MFA, least-privilege access, centralised logging, encryption, backup and recovery, vulnerability management
- Policies and procedures written for how the team actually works, not boilerplate
- Evidence automation connected to cloud, code and HR systems so audit evidence collects itself
- Auditor liaison and readiness review before the observation period
03 The results
- SOC 2 Type II audit readiness achieved within the twelve-week deadline
- The enterprise contract closed
- Subsequent enterprise sales unlocked with a repeatable security posture
- A security foundation that scales with the company