SOC 2 in four months, and a deal waiting on it
Someone in a contract negotiation agreed to a date. Now the controls, the evidence and the auditor all have to exist by then. Policy documents are the easy half. The hard half is the infrastructure those policies claim you have.
Where teams actually get stuck
Compliance software will tell you which controls are failing. It will not build them. That gap is where the four months go.
An enterprise contract is contingent on a SOC 2 report, the audit window is set, and the technical controls behind the policies have not been built.
-
“We need SOC 2 in four months to close an enterprise deal.”
The deadline came from a sales negotiation, not an engineering estimate, and it is not moving.
-
“Every audit is a two-week scramble for screenshots.”
Evidence is assembled by hand each cycle, so the cost repeats every year and grows with the company.
-
Your compliance tool shows red checks nobody on the team knows how to fix.
The dashboard is accurate. The findings describe infrastructure work that no one has been assigned.
-
Access to production is granted by whoever set the account up.
Logical access controls are the first thing an auditor tests and the hardest thing to reconstruct after the fact.
-
Nobody can prove that logging cannot be turned off.
Audit trail integrity is a control in its own right, and "we would notice" is not evidence.
What it costs to leave it
A missed audit window is rarely just a missed audit window. It is a deal, a renewal cycle and a quarter of engineering attention.
- The deal on the other side
- Enterprise buyers do not usually walk away. They wait, and the revenue moves into a quarter you have already committed to the board.
- Engineering time, twice
- Controls built in a rush are built badly, and then rebuilt properly later. The second build is the one you pay for with interest.
- The annual repeat
- Type II is a period of observation, not a one-off exam. Manual evidence collection becomes a permanent tax on the same two engineers.
- Scope creep into other frameworks
- The next customer asks for HIPAA, PCI DSS or a government mapping. Without a control framework underneath, each one starts from zero.
What we do about it
We build and deploy the technical controls a SOC 2 auditor tests, and wire the evidence sources so the next audit pulls from the platform instead of from screenshots.
-
Controls that exist in code, not in a policy PDF
Single sign-on with enforced multi-factor authentication, least-privilege roles, encryption with customer-managed keys, network segmentation, log retention and continuous configuration monitoring, deployed as infrastructure code you keep.
-
An audit trail that cannot be switched off
Organization-wide logging lands in a separate, locked-down account, and a guardrail policy denies anyone, including administrators, the ability to stop or delete it.
-
Evidence produced by the system
Configuration history, security findings, access analyzer results, log integrity and the full pull request history of every change become the evidence pack, gathered by a script rather than by a person.
-
An auditor role with no data access
Auditors get a named, read-only permission set with an explicit deny on reading customer data, so you can grant access to evidence without granting access to the business.
The outcome: When the audit window opens, the controls are already running and the evidence already exists. You spend the window answering questions about a working system instead of building one, and the same foundation carries the next framework a customer asks for.
What that is, in the portfolio
-
BuiltForProd Baseline
A multi-account cloud foundation in OpenTofu and Terragrunt, customized for your organization, deployed into your accounts by our engineers, then handed over with the repositories and the documentation.
-
BuiltForProd Assessment
A fixed-fee assessment of what you run today against the eight properties of the BuiltForProd Standard, with a prioritized gap list at the end.
-
BuiltForProd Managed
Experienced engineers who operate, secure and evolve production as an extension of your team, working through your own access, pull requests and pipelines.
What you get
-
SOC 2 aligned technical controls
A conformance pack of automated rules mapped to the Trust Services Criteria runs from day one, with the rest of the framework library a single flag away.
-
Verification mapped to controls
The deployment ends with verification checks that are mapped to SOC 2 controls and run twice, so the evidence of correct deployment is itself an artifact.
-
Identity you can describe to an auditor
Single sign-on, no standing administrator accounts, production read-only for everyone except named leads, and an analyzer that reports access nobody has used.
-
An evidence routine
A quarterly evidence-snapshot script and a monthly compliance checklist, documented so the work survives the person who normally does it.
-
A path to the next framework
Mappings and control packs for HIPAA, PCI DSS 4.0, NIST CSF, CMMC 2.0 and CIS, so the second audit reuses the first one's foundation.
-
An honest scope statement
A written list of what the platform covers and what remains yours — policies, vendor management, HR controls and the report itself.
Every repository and every cloud account stays yours. We keep no standing access after handover. See security and ownership for how that is enforced, and pricing for how an engagement is quoted.
What is switched on, and what is one flag away
Compliance readiness is countable. These are the numbers behind the claim.
| What | Figure | Where it comes from |
|---|---|---|
| SOC 2 rules on by default | 13 rules | The AWS Enterprise Baseline SOC 2 conformance pack, mapped to Trust Services Criteria CC6.1, CC6.6, CC6.7 and CC7.1. |
| Framework packs available | 29 packs | AWS Config conformance pack templates in the AWS Enterprise Baseline, including HIPAA, PCI DSS 4.0, NIST CSF, CMMC 2.0 and CIS Controls v8. |
| Frameworks with documented mappings | 11 frameworks | The AWS Enterprise Baseline control documentation, mapped control by control. |
| Verification checks at handover | 17 checks | Mapped to SOC 2 controls and run twice on every AWS Enterprise Baseline deployment. |
| Audit log retention | 365 days | The AWS Enterprise Baseline central log archive, in a separate account with lifecycle rules. |
| Auditor data access | Explicit deny | The auditor permission sets in the AWS Enterprise Baseline deny reading customer data. |
The same evidence is documented page by page in the product documentation and measured against the BuiltForProd Standard.
How it works
Four steps from the first conversation to a platform your team owns.
-
Tell us the date and the deal
The audit window, the auditor if you have chosen one, the framework, the compliance tool you already pay for and what your infrastructure looks like today.
-
Gap list and fixed fee
An assessment against the Standard turns the red checks in your dashboard into a prioritized list of infrastructure work, scoped and priced before anything starts.
-
Controls deployed in your accounts
Our engineers deploy the foundation with the compliance profile that matches your framework, then run the verification checks that map to SOC 2 controls.
-
Evidence routine handed over
Your team runs the evidence snapshot and the monthly checklist themselves during handover, so the audit window opens with the routine already in motion.
Yes, but…
The objections we hear on the first call, answered plainly.
Does this make us SOC 2 certified?
No, and anyone who says otherwise is selling something. We deploy the technical controls and the evidence sources. The report is issued by your auditor after their own testing, and certification is their decision, not ours.
We already pay for a compliance automation tool. Does this replace it?
No, they solve different halves. Your tool tracks controls, policies and evidence collection. We build the infrastructure those controls describe, so the checks have something real to pass.
Four months is not much time. Is it even possible?
It depends on what exists today and how much application migration is in scope. We will tell you on the first call whether the date is realistic, and if it is not, what a defensible partial scope looks like.
Will the controls slow our engineers down?
Production being read-only except through a reviewed pipeline is the control. Teams that adopt it usually ship more often, because the gate is automated rather than a person's calendar.
What about HIPAA, PCI DSS or CMMC?
The same foundation carries them. Quick-start profiles for healthcare, financial and government workloads switch on the matching control packs, and the mappings are documented per framework.
Questions
What does BuiltForProd actually provide for SOC 2?
BuiltForProd provides the technical controls and the automated evidence sources a SOC 2 audit examines: identity, access, encryption, network segmentation, logging, monitoring and change management, deployed as code into your own cloud accounts. Policies, vendor management, HR controls and the audit itself remain yours.
Which Trust Services Criteria do the default controls map to?
The SOC 2 conformance pack that ships on by default in the AWS Enterprise Baseline maps to CC6.1, CC6.6, CC6.7 and CC7.1, covering logical access, boundary protection, credential management and monitoring.
Can our auditor get access to the evidence directly?
Yes. There are dedicated auditor permission sets with read-only access and an explicit deny on reading customer data, so an auditor can inspect configuration and logs without touching the business data.
Do we need to be on AWS for this?
No. The Baseline is delivered as the AWS, Azure and GCP Enterprise Baseline editions, all built to the same BuiltForProd Standard. The control counts quoted on this page describe the AWS Enterprise Baseline.
Who keeps the controls working after the audit?
Your team, with drift detection and a monthly checklist to keep it honest. If you would rather have help during audit season, Managed engineers can run the evidence routine and clear findings through your own pull requests.
More answers are in the FAQ and the support center.
Tell us the audit date.
Send us the framework, the deadline and what you run today. We will tell you what is missing, what we would deploy, and whether the date is realistic. If it is not, we will say that too.