SSAE 18 / AT-C 205 Every control, every evidence package — verified, not assumed

The most rigorous SOC 2 readiness package a B2B SaaS company can buy.

The SOC 2 Audit-Readiness Engine assembles a documentation-complete audit package — every control mapped, every evidence source wired, every gap remediated, and the auditor package assembled — checked against the AICPA Trust Services Criteria before a specialist releases it.

Every Trust Services Criteria mapped60–120 controls, gate-checkedAWS · GCP · Okta · GitHub · HR evidence sourcesSpecialist release on every package5-business-day SLA
Why readiness fails

A single missing control can block a deal.

A B2B software company's SOC 2 report is only as strong as the readiness behind it. Miss a control mapping, skip an evidence source, mis-time the observation window, or fail to remediate a gap — and the audit can be delayed, qualified, or expose the company to lost revenue.

Most companies run this by hand, from memory, once or twice. The Trust Services Criteria have not been read end-to-end since the last audit. That is exactly where readiness gaps hide.

The SOC 2 Audit-Readiness Engine exists to close that gap with a single, exhaustive standard applied identically to every engagement.

1 of 3
missing control mappings is enough to jeopardize an audit
The benchmark

Measured against the letter of the AICPA standard — criterion by criterion.

We do not summarize the criteria and hope. Every package is scored against a versioned rule pack tied to the exact text of the AICPA Trust Services Criteria and SSAE 18. These are the provisions each package is held to.

AT-C 205

Control mapping to all five Trust Services Criteria

Security, Availability, Processing Integrity, Confidentiality, Privacy — every applicable criterion mapped to a control, or the package does not release.

TSC CC6

Logical and physical access controls

Evidence from AWS/GCP, Okta, GitHub, and HR systems — verified to cover authentication, authorization, and monitoring.

TSC CC7

System operations and monitoring

Evidence of incident response, monitoring, and change management — wired from ticketing and observability tools.

TSC CC8

Change management

Evidence of code review, deployment pipelines, and configuration management — established by search, not assumption.

TSC CC9

Risk mitigation and vendor management

Risk assessment documentation and vendor due diligence evidence — collected and mapped.

SSAE 18 / AT-C 205

Observation window and evidence sufficiency

The 3–12 month observation window is verified; evidence is collected across the full period; the auditor package is assembled with a sufficiency checklist.

How a package is built

Intake to specialist release, with deterministic gates the AI cannot overrule.

AI extracts and drafts. Deterministic rules — running as code, outside the model — decide what is complete. A human specialist signs every release. That order is never reversed.

01

Readiness Gap Scan

Upload your cloud and SaaS stack details. We return a free completeness read: which controls and evidence sources you already have, and which are missing.

02

Evidence & control mapping

As your authorized clerical agent, we map controls to the Trust Services Criteria, wire evidence sources (AWS, GCP, Okta, GitHub, HR, ticketing), and build the evidence matrix.

03

Grounded drafting

Policies, control descriptions, and evidence narratives are drafted from your validated data and the AICPA rule pack into field-locked templates — no legal opinions, no invented facts.

04

Deterministic completeness gates

Control mappings reconcile to the criteria; evidence sufficiency is verified; the observation window is checked; any gap blocks release.

05

Specialist release

A security specialist (vCISO/GRC lead) reviews the exception queue and signs the release. High-value or complex engagements route to attorney review first.

06

Delivery

You receive the package: control matrix, evidence log, policy set, gap remediation plan, and auditor package — ready for the independent CPA firm to attest.

The bar we hold

Rigor you can measure.

100%
Specialist-released
No package ships without a human signature.
5 days
Standard SLA
From complete intake to released package.
<1%
Critical-defect target
Tracked against a gold-standard package library.
5+
Evidence-source types
Cloud, identity, code, HR, ticketing — every applicable source.
Why SOC 2 Audit-Readiness Engine

Built to be the most thorough option a B2B SaaS company has.

Documentation-complete, by design

The deliverable is completeness itself — every control and evidence source accounted for or explicitly exception-coded. Nothing is left implicit.

Deterministic, not vibes

The gates that decide completeness are code, not a model's opinion. A drafting error cannot slip past a criterion requirement.

In its lane, on purpose

We prepare documentation and run evidence collection as your clerical agent. We never give legal advice, design controls without expert review, or perform the attestation.

Engagement

Flat fee, per released package. No contingency, ever.

Simple, predictable, and aligned with a readiness standard — not a cut of any deal.

  • A free Readiness Gap Scan before you commit — see exactly what is missing.
  • One flat fee per released Audit-Readiness Package; disclosed pass-through evidence-source costs.
  • Optional fixed-fee attorney review for complex or high-value engagements.
  • Optional Renewal Continuity Add-on for the annual Type II refresh, pre-scheduled to your observation window.
FAQ

Questions, answered precisely.

Is the SOC 2 Audit-Readiness Engine a law firm?
No. The SOC 2 Audit-Readiness Engine, a service of Your Deputy, Obuke LLC, provides documentation-completeness services. It is not a law firm, does not provide legal advice, and does not represent you in any legal matter. Attorney review is available and recommended for complex engagements.
Do you perform the audit or issue the SOC 2 report?
No. Only a licensed CPA firm can issue a SOC 2 report under SSAE 18. We prepare the readiness package; the independent CPA performs the attestation. We never sign the opinion.
What makes a package 'complete'?
Completeness is defined by the AICPA Trust Services Criteria: all applicable criteria mapped to controls, evidence sources wired, policies drafted, gaps remediated, and the observation window verified. Deterministic gates enforce each one before release.
How fast is it?
The standard SLA is five business days from complete intake to a specialist-released package. The free Gap Scan is returned much sooner and tells you exactly what is still needed.
How are you priced?
A flat fee per released package, plus disclosed pass-through evidence-source costs. No contingency and no percentage of any deal value.

See what's missing before it costs you a deal.

Start with a free Readiness Gap Scan. Send your cloud and SaaS stack details and we'll return a completeness read against every criterion of the Trust Services Criteria.

Documentation-completeness service · not legal advice · the independent CPA performs the attestation.