SOC 2 Type 1
Readiness for a point-in-time examination.
ExploreGovernance, Risk & Compliance
Practical support for SOC 2, ISO 27001 and your evolving compliance requirements.
Frameworks we support
Readiness for a point-in-time examination.
ExploreEvidence of controls operating over time.
ExploreISMS implementation and audit preparation.
ExplorePrivacy readiness and data governance.
Explore| Framework | Why you would need it | Who asks | Typical |
|---|---|---|---|
| SOC 2 Type 1 | Proves your controls are properly built. Fastest route to unblocking a stalled contract. | US enterprise buyers | 2–4 months |
| SOC 2 Type 2 | The one enterprises actually want. Proves controls have been working for months, not just that they exist. | US enterprise, investors | 6–12 months |
| ISO 27001 | A certificate rather than a report. Asked for more often than SOC 2 outside the US. | EU, UK, Middle East, Asia | 6–9 months |
| DPDP Act 2023 | Indian law, not a customer request. You do not get to opt out of this one. | Regulator | 2–4 months |
| PCI DSS | Card data touches your systems. Most of the cost is scope — we cut it before you pay for it. | Acquirers, card brands | 3–6 months |
| CERT-In directions | Six-hour incident reporting and 180-day log retention. Binding in India; most firms have neither. | Regulator | 4–8 weeks |
| GDPR | You hold data on people in the EU, wherever you are based. | EU customers, regulator | Varies |
| HIPAA | You handle US health information. | US healthcare buyers | Varies |
| Security questionnaires | You answer the same 200-question spreadsheet every quarter. A framework costs less than the questionnaires do. | Every prospect | Ongoing |
Timelines assume a standing start. If controls are already in place these compress considerably — the readiness assessment tells you which case you are in before you commit to a date.
Our approach
Define scope and identify gaps.
Build controls and practical policies.
Prepare and organize supporting evidence.
Coordinate independent audit requests.
In detail
The four steps above, with what actually happens and what you receive at each one.
Which systems, which criteria, which report, what deadline. We push back when the scope is wider than the requirement — unnecessary scope is the most common reason these projects overrun.
You get: scope statement, framework recommendation, a realistic date.
Every criterion tested against what exists today. Not a questionnaire — we look at the systems.
You get: a gap register with severity, fix, effort and owner per finding. Useful on its own even if you stop here.
The long part, and the part we are built for: identity and access management, logging and retention, monitoring and alerting, network segmentation, encryption in transit and at rest, backup and tested recovery, change management, vendor risk.
You get: the controls actually running, plus policies that describe what runs rather than an aspiration.
A Type 2 window needs proof for every instance of every control. Retrofitting that at the end is where projects fail, so we automate collection at the start.
You get: evidence accumulating on its own, mapped to the criteria it satisfies.
Three to twelve months in which the controls must keep working. We monitor and correct drift; the window itself cannot be compressed.
You get: monthly control-health reporting, and nothing to discover in month eleven.
The auditor requests, we respond, produce evidence and remediate findings. Your engineers stay on their own work.
You get: the report — and no month lost to answering an auditor.
A report expires. Type 2 is an annual rhythm and the controls have to keep running in between, which is usually where our managed security work continues.
You get: next year's audit as a renewal, not a rebuild.
SOC 2 scope
SOC 2 rests on five Trust Services Criteria. Only Security is mandatory. Every criterion added lengthens the audit and raises the fee, so scoping is the biggest lever on cost — and the one most often got wrong.
Protection against unauthorised access. The common criteria every report contains.
You have committed to uptime in a contract or SLA.
You hold customer information that is commercially sensitive.
You process transactions or calculations where being wrong is the risk.
You handle personal information directly. Overlaps with DPDP and GDPR but replaces neither.
SOC 2
The question that decides your deadline and your budget. Type 1 is a photograph of a clean kitchen; Type 2 is the inspector's record of that kitchen over six months. One proves you can be clean, the other proves you are.
Most companies do Type 1 first and Type 2 the following year. The control work is identical, so nothing is wasted. Ask whoever requested it which they need, in writing, before you spend anything.
Security engineering and compliance support, grounded in your actual environment.
Readiness, remediation, evidence preparation and audit support.
SOC 2 reports from independent CPA firms. ISO certification from accredited certification bodies.
The split
A SOC 2 examination is an attestation engagement under AICPA standards. Only an independent licensed CPA firm may perform it and sign the report — and the firm that builds your controls is never allowed to audit them. Independence is the entire value of the report, so the work splits cleanly.
| NexusSec | The CPA firm |
|---|---|
| Readiness assessment and gap register | Plans and performs the examination |
| Designs and builds the controls | Tests those controls independently |
| Writes policies that match what runs | Samples evidence across the window |
| Engineers automated evidence collection | Forms and signs the opinion |
| Remediates findings, manages the project | Issues the report your customer reads |
No auditor yet? We introduce you to CPA firms we have worked alongside and you choose. We take no commission on that introduction — a financial link between the consultant and the auditor is exactly what undermines the independence the report depends on. The same applies to ISO 27001: the certificate comes from an accredited certification body, never from us.
The difference
| Before | After |
|---|---|
| A deal is stuck behind a compliance request | The report is in the buyer's hands and the deal moves |
| Nobody can say who has access to what | Access is controlled, reviewed and evidenced |
| Logs are missing, or kept for a week | Retention that satisfies the standard and the law |
| Policies describe a company you no longer are | Policies match what actually runs |
| Evidence is screenshots gathered in a panic | Evidence collects itself, all year |
| Every questionnaire costs a week of someone's life | You send the report and move on |
| Nobody knows whether the audit would pass | You know, because we tested it first |
Why us
Most of a compliance project is not paperwork. It is access control, logging, segmentation, backups, monitoring and change management — work we do every day as an infrastructure and offensive-security team.
The failure mode we kept being called in to fix: a client takes infrastructure we built into a compliance project run by people who have never configured any of it. Policies describing a network nobody looked at. Screenshots proving a setting exists but not that it works. A scramble in the final month. One team that both builds the control and can prove it removes that entire class of problem.
We are not accountants and will not pretend to be. We are the engineers who make the evidence real before someone independent comes to check it.
Two things decide it: how far your controls are from the criteria, and how much scope you agreed to. Readiness and remediation is where the time goes; the audit fee is usually the smaller line. Anyone quoting a fixed SOC 2 price before seeing your environment is quoting a template.
We would rather tell you that you are six months away than sell you an audit you will fail. A failed examination is not neutral — you pay for it, and you may have to disclose it.
Questions
No, and nor can any other cybersecurity firm. A SOC 2 examination may only be performed and signed by an independent licensed CPA firm. We handle readiness, control engineering, evidence and audit coordination. We will introduce you to CPA firms we have worked alongside and take no commission on that introduction — a financial link between consultant and auditor is exactly what undermines the independence the report depends on.
Six to twelve months from a standing start: readiness and remediation, then an observation window of at least three months, then the examination. The window is the point of the exercise and cannot be compressed.
If a customer asked for SOC 2 by name, usually yes — they are different instruments and one is not accepted in place of the other. Most of the underlying control work overlaps, so the second framework costs considerably less than the first.
It is not a named line-item requirement, but auditors expect evidence of vulnerability management and independent testing, and most reports include it. Our VAPT work is scoped to produce evidence an auditor accepts rather than a scanner export.
No — and that restriction is the point. Independence is what gives the report its value. Any firm offering to do both is offering a report a serious buyer will discount.
Not on ICAI registration alone. SOC 2 is an AICPA attestation requiring a US-licensed CPA firm; Indian firms that offer it work through a US-licensed entity or affiliate. Ask any prospective auditor for their licence and their peer-review report — both are normal requests.
Tell us your framework, business scope and target date.