AICPA SOC 2 · Trust services

Get SOC 2 ready and unblock your US enterprise deals.

US enterprise customers and their security teams ask for a SOC 2 report before they buy. Lexfield prepares you for a clean SOC 2 Type II examination: control design mapped to the Trust Services Criteria, evidence that collects itself as you operate and calm, thorough preparation for the examination. The examination itself is performed by a licensed CPA firm; we get you ready for it.

Every engagement is delivered in plain English by practitioners with hands-on systems experience. The first call is free and carries no obligation.

Why SOC 2

The report that clears US security reviews

SOC 2 is the assurance report American enterprise buyers know and trust. One good Type II report answers the security review before it starts, and the controls behind it make your business genuinely safer to run.

Unblock enterprise deals

Procurement and security teams in the US ask for SOC 2 by name. A current Type II report moves your deal past the security review while competitors are still filling in questionnaires.

One report, fewer questionnaires

Instead of answering the same three-hundred-row spreadsheet for every prospect, you hand over one independent report that covers the questions they were going to ask.

Controls that fit how you work

We design controls around the tooling and habits you already have, mapped to the Trust Services Criteria, so evidence collects itself as you operate instead of becoming a second job.

Groundwork you can reuse

SOC 2 and ISO/IEC 27001 cover overlapping ground, so much of the control work serves both. Each is assessed on its own merits, and having one gives the other a genuine head start in effort.

Working out your route? The first call is free and carries no obligation: clear, practical advice either way.

Book a free introductory call

Services

What our SOC 2 consultancy includes

We do one thing here: readiness consultancy, delivered by practitioners with hands-on systems experience. Advisory and attestation stay in separate hands, which is what keeps your report fully credible. The examination is performed by a licensed CPA firm, and we prepare you for it.

Consultancy

Readiness and examination support

For organisations preparing for their first SOC 2 report or improving an existing one.

  • Readiness assessment against the Trust Services Criteria with a prioritised roadmap
  • Scoping advice: Security is always in; we help you decide whether Availability, Confidentiality, Processing Integrity or Privacy belong in your report
  • Control design and policy documentation sized for a startup, not an enterprise
  • Evidence collection built into your existing tooling, automated wherever possible
  • Type I or Type II strategy and a realistic observation window plan
  • Preparation for the examination and support while it runs
  • Liaison with the licensed CPA firm performing your attestation
  • Remediation support after the report, turning exceptions into closed actions

Two ways to work with us

Both are fixed-price. Pick the balance that suits your team, or move between them as the project runs.

Option 1 We build with you

We take the lead on drafting and building, and you review, decide and approve. The fastest route when your team is stretched.

Option 2 We coach, you build

Your team does the building while we guide, review and course-correct. More of the knowledge stays in-house, and the fee reflects the lighter touch.

Independence protects your report: a SOC 2 attestation is issued by a licensed CPA firm after an independent examination, and that separation is what makes the report worth handing to your customers. We handle the preparation. The examination is theirs, and we support you all the way through it.

Process

From first conversation to report

  1. Readiness assessment

    We review your current controls against the Trust Services Criteria and produce a plain-English report: what already stands, what is missing and a realistic route to your report.

  2. Scope and control design

    Security is in every SOC 2 report. Together we decide which further criteria your customers actually expect, then design controls and policies sized for your team rather than an enterprise.

  3. Operate and collect evidence

    A Type II report covers how your controls operate over an observation window, typically three to twelve months. We wire evidence collection into your existing tooling so the window runs itself.

  4. The examination

    A licensed CPA firm examines your controls and their operation. We prepare you thoroughly, stay available while it runs and help you respond to anything the examiners raise.

  5. Your report, and the next one

    SOC 2 reports are renewed annually, so the observation window never really closes. We help you keep controls running as business as usual, making next year’s report a formality rather than a project.

Who you work with

Practitioner-led, auditor-trained

Lexfield’s consultants bring hands-on experience designing, building and operating digital systems. Security is not theory for us: it is how we have delivered real systems, and our consultancy is led by practitioners with formal auditor training.

  • Formal Lead Auditor training Certified Lead Auditor training in ISO/IEC 27001 and ISO/IEC 42001: the same control-audit discipline SOC 2 examiners apply, so your controls are built to withstand examination.
  • Hands-on systems experience Our consultants have hands-on experience designing, building and operating production systems, so control design reflects how technology actually runs, not just how the paperwork reads.
  • Built for small and medium businesses Fixed-scope engagements, plain-English deliverables and a documentation style sized for teams without a full-time compliance department.
  • One practice across frameworks SOC 2, ISO/IEC 27001, ISO/IEC 42001 and ISO 22301 under one roof, so overlapping control work is done once and each framework is still assessed on its own merits.

The framework explained

What is SOC 2?

SOC 2 is an attestation framework published by the American Institute of Certified Public Accountants (AICPA). Rather than a certificate, it produces a detailed report in which a licensed CPA firm gives its independent opinion on your controls. A Type I report covers the design of your controls at a point in time; a Type II report, the one enterprise customers usually want, covers how those controls actually operated over an observation window of several months.

Every report is built on the Trust Services Criteria. Security is mandatory; the other four categories are included when they matter to your customers:

  • Security The common criteria in every SOC 2 report: access control, change management, risk assessment, monitoring and incident response. If you take only one category, it is this one.
  • Availability Commitments about uptime and resilience: capacity planning, monitoring, backup and recovery. Usually included when customers depend on your service being reachable.
  • Confidentiality How information designated confidential is protected through its lifecycle, from classification and handling to retention and disposal.
  • Processing integrity Whether your system processing is complete, valid, accurate and timely. Relevant when customers rely on your outputs, such as payments or calculations.
  • Privacy How personal information is collected, used, retained and disposed of against your privacy commitments. Distinct from confidentiality, and increasingly requested.

FAQ

Questions we hear most often

How long does SOC 2 Type II take?

Readiness work for a small company typically takes two to four months, and then the observation window runs, usually three to twelve months depending on what your customers will accept. The report follows the examination at the end of the window. If you need something sooner, a Type I report on control design can bridge the gap while your Type II window runs.

What does SOC 2 cost?

Two components: our readiness consultancy, which is a fixed fee agreed after a scoping conversation, and the CPA firm’s examination fee, which they quote separately. Try the cost calculator for an instant indicative figure for the consultancy side.

What is the difference between Type I and Type II?

A Type I report says your controls were suitably designed on a given date. A Type II report says they were designed and operated effectively over a period. Enterprise security teams almost always want Type II, and many will accept a Type I as an interim step while your first observation window runs.

SOC 2 or ISO 27001: which do we need?

Ask your customers, because it is their requirement you are meeting. US enterprise buyers usually want SOC 2; European enterprises and public tenders usually ask for ISO 27001. The two cover overlapping ground, so control work often serves both, and each is assessed on its own merits. We advise on both and will tell you plainly which order makes sense for your pipeline.

Do you issue the SOC 2 report?

The report is issued by a licensed CPA firm after its independent examination, and that independence is exactly what makes the report valuable to your customers. We prepare you for the examination, coordinate with the firm and support you while it runs.

Can we do SOC 2 and ISO 27001 together?

Yes, and it is often efficient: one control set and one evidence pipeline can serve both, with each framework assessed on its own by its own independent examiner. If both are on your roadmap, we design the controls once so nothing is done twice.

Get started

Ready when your customers ask. Better before they do.

Whether a deal is waiting on a report or you are getting ahead of the question, the first call is free, carries no obligation and requires no defined project. Early clarity prevents wasted months later.

Book a free introductory call