SOC 2 readiness sounds like an enterprise project. For a 30-50 seat professional services firm, it doesn't have to be. The controls that satisfy most Type I auditors — access management, encryption at rest, incident response, change management, monitoring — are controls a well-run MSP is already enforcing. The gap is usually documentation, not implementation.
The 60-day sequence
Days 1-14: gap assessment. We map your current controls against the SOC 2 Trust Services Criteria, score each control as implemented, partial, or missing, and prioritize the gaps by audit risk. Days 15-45: remediation. We close the high-risk gaps — usually access reviews, log retention, and a documented incident-response plan. Days 46-60: evidence collection. We package the artifacts the auditor needs: access logs, policy documents, configuration screenshots, and a controls matrix. At day 60 you have a defensible posture and a binder the auditor can open.
What firms usually don't expect
Most firms are already 60-70% of the way there. The biggest surprises are almost always the same: access reviews haven't been done in over a year, offboarding checklists exist on paper but weren't run for the last three departures, and log retention is set to 30 days when the auditor wants 90. None of these are hard to fix. They just need to be fixed before the auditor shows up, not during.
I'm Ethan Higginson, CEO and co-founder of Prime Hour Tech. Years in IT services taught me one thing: technology should work for people, not the other way around, I built this company on that belief. I'm Utah born and raised, working on my Professional MBA.