Governance / ComplianceB2B SaaS / workflow platform12-week readiness programme, then a 6-month observation window
A clean SOC 2 Type II that unblocked a B2B SaaS company's enterprise pipeline
Series B horizontal SaaS, ~120 staff, enterprise-sales motion
Enterprise prospects were parking six-figure deals in vendor security review because the company had no SOC 2 report, and competitors with one were winning by default. A vCISO owned the programme end to end — closing control gaps, tightening identity and access, and training staff — so the company reached its observation window on a predictable timeline and came through its first Type II audit with a clean opinion.
Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.
- Exceptions at first SOC 2 Type II audit
- 0
- clean opinion
- Control gaps closed across the Trust Services Criteria
- 41
- prioritised by audit risk
- Time to audit-ready
- 12 weeks
- before the observation window opened
- Security-questionnaire turnaround
- weeks → ~2 days
- against a maintained evidence base
The challenge
- Enterprise procurement gated on SOC 2, and deals were stalling in security review with no report to hand over.
- Controls existed informally in engineers' heads but were undocumented and unevenly enforced across identity, access and change management.
- Leadership needed a predictable path to a clean Type II opinion, not an open-ended project that drifted.
What we did
- Placed a vCISO to own scope, the control framework and auditor liaison so the founders could stay focused on the business.
- Ran a gap assessment against the Trust Services Criteria and prioritised remediation by audit risk and engineering effort.
- Conducted an IAM audit to enforce least privilege, remove dormant access and put joiner-mover-leaver controls on a documented footing.
- Rolled out role-based security awareness training so evidence of a security culture was real, not just a slide.
- Stood up evidence collection early so the six-month observation window generated audit-ready artefacts continuously.
The outcome
- The company passed its first SOC 2 Type II audit with no exceptions.
- Security questionnaire turnaround dropped from weeks of back-and-forth to a couple of days against a maintained evidence base.
- Deals that had been stuck in security review moved forward with the report attached.
- The control framework was left documented and owned internally, so the second-year audit did not start from zero.
“We'd lost two deals to 'come back when you have SOC 2.' Having someone own the whole programme meant we stopped guessing. The clean Type II opinion paid for itself with the first contract it unblocked.”