/ Drata SOC 2: A Practical, Step-by-Step Guide to Getting Audit-Ready Faster

Drata SOC 2: A Practical, Step-by-Step Guide to Getting Audit-Ready Faster

Drata is a powerful tool. It can transform a slow, resource-draining activity into a value-added automated task.

But in order for it to work, it needs to be set up properly.

This guide explains how SOC 2 actually works inside Drata, what you need before you begin, and how to avoid the most common mistakes that slow teams down. It is written for founders, CISOs, compliance leads, and non-technical executives who want a semi-automated approach to compliance.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

Drata does not replace your SOC 2 program. It operationalizes it. The platform helps you manage controls, evidence, and monitoring, but decisions, ownership, and execution still matter.

A successful Drata SOC 2 project follows a predictable flow: scoping, setup, automation, validation, and audit.

Before You Start: What You Need to Run a SOC 2 Project in Drata

Before logging into Drata, your organization needs to be aligned.

1- Decide your SOC 2 target: Type 1 vs. Type 2 and realistic timelines

SOC 2 comes in two formats defined by the AICPA.

SOC 2 Type I evaluates whether controls are designed correctly at a point in time.
SOC 2 Type II evaluates whether those controls operate effectively over a period, usually three to twelve months.

Report Type

What It Evaluates

Timeframe

SOC 2 Type I

Whether controls are designed appropriately

Point in time

SOC 2 Type II

Whether controls operate effectively

3–12 months

With Drata, many of our clients reach Type I readiness in 6 to 8 weeks if controls already exist. Type II timelines depend on the observation period, which can range from 3 months to up to a year.

If you’re pursuing SOC 2 compliance due to a client’s request, he will till you which type he requires. If you’re proactively seeking SOC 2 compliance, then we recommend going for type 2 compliance. This allows you to cast a wider net of clients.

A successful SOC 2 program follows a predictable lifecycle. While tools and timelines vary, the underlying phases are consistent across most organizations.

  1. Scoping: Define the system being audited, select Trust Services Criteria, set the audit period, and confirm the auditor. Good scoping reduces downstream complexity dramatically.
  2. Setup: Configure Drata, connect integrations, publish policies, and assign control ownership. This phase turns abstract requirements into operational structure.
  3. Automation: Enable continuous evidence collection across identity, infrastructure, code, ticketing, and endpoints. Automation replaces manual tracking, but only when integrations reflect reality.
  4. Validation: Run a readiness review. Confirm that controls are operating as described, evidence is complete, and timing aligns with the audit window. This is where most hidden risks surface.
  5. Audit: Auditors independently test controls and evidence. Clarifications and minor findings are normal. Clear responses and preparation determine how fast this phase moves.
  6. Continuous compliance: After the report is issued, controls continue operating. Monitoring, reviews, and periodic reassessment prevent drift and reduce effort in future audit cycles.

 

2- Select your Trust Services Criteria

Every SOC 2 must include the Common Criteria for Security. Additional criteria are optional and must be justified.

These include Availability, Confidentiality, Processing Integrity, and Privacy.

The choice of additional criteria is driven by the service agreement with the customer, which may require specific criteria, or by the type of business pursuing SOC 2. 

If you’re a SaaS that handles a large amount of private financial data, it makes sense to pursue the confidentiality criteria, for example. Availability makes sense if you sell uptime guarantees or SLAs. Privacy should only be selected if you are prepared to meet the additional criteria around notice, consent, and data subject rights.

 

3- Gather prerequisites: Systems, Owners, and Access

Drata works best when you already know what is in scope. This includes cloud infrastructure, identity providers, repositories, ticketing tools, and endpoints.

You also need named control owners. Automation cannot replace accountability.

 

4- Choose or confirm an auditor early

An external CPA firm ultimately issues the SOC 2 report. Confirm your auditor before proceeding with deep configuration to avoid mismatches in expectations, evidence formats, or control interpretations.

Where Axipro Fits in a Drata-Led SOC 2 Program

Drata is excellent at operationalizing SOC 2. It centralizes controls, automates evidence collection, and enforces timelines that matter to auditors. What it does not do is make judgment calls, resolve ambiguity, or design controls in context. That work still belongs to the experts.

This is where Axipro fits.

In practice, Axipro supports Drata-led SOC 2 programs in four critical areas:

Scoping discipline

Before configuration begins, Axipro helps validate system boundaries, Trust Services Criteria selection, and audit periods. This prevents over-scoping, which is one of the most common reasons SOC 2 projects slow down or fail testing later.

Control ownership and execution clarity

Drata can track controls, but it cannot assign accountability. Axipro works with teams to ensure every in-scope control has a clear owner, a realistic execution process, and an evidence strategy that will stand up to auditor scrutiny.

Readiness validation before auditor access

Many SOC 2 delays happen after auditors are invited. Axipro performs structured readiness reviews to catch weak evidence, misaligned controls, and timing gaps before fieldwork begins. This reduces follow-ups, exceptions, and rework.

Audit navigation and exception handling

During the audit, Axipro helps teams respond to auditor questions, document compensating controls, and resolve findings clearly. This keeps the audit moving and avoids creating long-term issues that resurface in future cycles.

Drata provides the operating system. Axipro helps ensure the program running on top of it is coherent, defensible, and sustainable.

Step 1: Scope Your SOC 2 Program in Drata

Once your prep work is done, it’s time to open Drata and start the real implementation work. Scoping is the first and most important step. It defines what the auditor will test and, just as importantly, what they will ignore.

Create the audit container

In Drata, scope becomes “real” the moment you create the audit.

Navigate to Audit Hub, then select Create Audit. Choose SOC 2 as the framework and define the audit period.

This date range matters more than most teams realize. Drata restricts auditor access to evidence strictly within this window. If your controls weren’t operating during this period, they effectively do not exist for the audit.

Add your auditor once the container is created. From this point forward, you are no longer “preparing”. You are in audit mode.

Define the system boundary before touching anything else

Before clicking deeper into Drata, pause and write a single sentence internally:

“This SOC 2 audit covers the systems, people, and processes used to deliver [Product or Service Name] to customers.”

That sentence becomes your anchor.

SOC 2 is not a company-wide certification. It is a system-level attestation. The American Institute of CPAs, which governs SOC reporting, is explicit about this.

Everything you include in scope must directly support that system. Everything that doesn’t should stay out.

This mindset alone can reduce audit scope by 30–50 percent for early-stage SaaS companies.

Identify what is actually “in scope” inside Drata

Now you translate that boundary into real systems.

A simple rule works well: if it stores, processes, or transmits customer data for the in-scope product, or is required to operate production, it belongs in scope.

Production environments are almost always included. Development and staging environments are in scope only if they use real customer data or are part of enforced change management workflows.

Infrastructure follows the same logic. Cloud accounts, databases, CI/CD pipelines, identity providers, logging, monitoring, and incident management tools typically qualify.

Third-party vendors matter too. SOC 2 explicitly requires the evaluation of subservice organizations that could impact system security or availability. Drata supports this through vendor inventory and SOC report review workflows.

 

Assign owners to everything that falls in scope

A control without an owner is an audit risk.

Inside Drata, each control mapped to your scoped Trust Services Categories needs a clearly assigned owner and a defined evidence source. Automated evidence is ideal, but manual uploads are acceptable if they are consistent and timely.

According to multiple SOC 2 readiness studies, unclear ownership is one of the top three causes of audit delays.

If someone cannot answer “who owns this?” within five seconds, you have a problem.

 

Final check: Does your time scope match your system scope?

Before you move forward, sanity-check one last thing.

Your audit period, your operating controls, and your evidence availability must all align. If your controls went live halfway through the audit window, the earlier period may fail testing.

Drata enforces this strictly, which is good, but unforgiving.

When these elements are aligned, auditors move faster, questions decrease, and SOC 2 stops feeling mysterious.

When scoping is done right

Scoping is complete when:

  1. Your audit exists in Drata,
  2. Your Trust Services Categories are intentional, 
  3. Your system inventory reflects reality, and 
  4. Your System Description matches both.

Step 2: Connect Integrations to Automate Evidence Collection in Drata

This is where Drata delivers real value. Automation replaces screenshots, spreadsheets, and human reminders, but only if integrations match how your company actually operates.

Start with identity and access management. Most organizations connect Drata to Okta, Azure Active Directory, or Google Workspace. This integration powers continuous monitoring for user access, offboarding, MFA enforcement, and periodic access reviews. Identity controls sit at the core of SOC 2 Security and are among the most frequently tested by auditors.

Next, connect your cloud infrastructure. AWS, Azure, and Google Cloud integrations allow Drata to automatically validate account configurations, logging, encryption settings, and change activity. Cloud misconfiguration remains a leading cause of security incidents, which is why auditors scrutinize this area closely.

For source control and CI/CD, integrations with GitHub or GitLab support evidence for change management, code review enforcement, and deployment traceability. These controls demonstrate that production changes are authorized, tested, and auditable.

Ticketing and incident workflows typically integrate with tools like Jira or ServiceNow. This evidence shows how incidents are identified, tracked, resolved, and reviewed. 

Endpoint management often includes platforms such as Jamf or Microsoft Intune, depending on whether your environment is Apple-first or Windows-heavy. These integrations support device inventory, encryption, and security configuration evidence.

Step 3: Run a Gap Analysis Using Drata’s Control Framework

Once integrations are live, it’s time to pressure-test reality. 

Drata maps every SOC 2 control directly to the Trust Services Criteria. This alignment allows you to evaluate readiness control by control, rather than guessing whether you are “mostly compliant.”

Start with Security controls, which are mandatory in every SOC 2 report. These cover access management, logging, monitoring, risk assessment, and incident response. Optional criteria like Availability, Confidentiality, or Privacy introduce additional operational depth, but also increase testing scope.

Inside Drata, review each control and assign a clear status: implemented, partially implemented, or missing. This step should be honest, not optimistic. Auditors test operating effectiveness, not intent. A “partially implemented” control is a signal that evidence will fail under scrutiny.

This visibility is the real value of the gap analysis. It allows you to prioritize remediation based on audit risk, not convenience. Industry data consistently shows that unresolved access controls and change management gaps account for a majority of SOC 2 audit exceptions.

 

Step 4: Implement and Map Controls Inside Drata

At this stage, controls shift from theory to observable behavior over time. Auditors do not care what should happen. They care what does happen, consistently.

Begin with access control execution. This means multi-factor authentication is enforced, single sign-on is actually used, access follows least-privilege principles, and user onboarding and offboarding are documented and repeatable. 

Change management must show evidence of discipline. Every production change should have an approval trail, testing proof, and a clear link between code, deployment, and release. Drata helps map this evidence, but the process must already exist. 

For incident response, auditors look for preparedness, not perfection. Detection mechanisms, response procedures, and post-incident reviews must be defined and followed when incidents occur. Even a “no incidents” period still requires proof that monitoring and escalation processes are active.

Risk management requires a maintained risk register, reviewed periodically, that demonstrates that leadership actively evaluates and responds to evolving threats. 

Vendor risk management must show due diligence before onboarding and ongoing monitoring afterward. Contracts, security reviews, and periodic reassessment matter because auditors treat key vendors as extensions of your system boundary.

If Availability is in scope, controls must demonstrate resilience. Backups should exist, recovery processes should be tested, and uptime should be monitored continuously. 

When controls are implemented this way, Drata becomes more than a tracker. It becomes evidence that your organization operates with intent, consistency, and accountability.

 

Step 6: Publish Policies and Align Employee Training

SOC 2 is not just about systems. It is about intent made visible. Policies are how auditors confirm that your organization understands its responsibilities and has formally committed to them.

Inside Drata, finalize and publish your core policies. Security, access control, incident response, and vendor management policies must be customized to your environment, formally approved by leadership, and acknowledged by employees. Generic templates are easy to spot and often trigger follow-up questions during audits.

Policy acknowledgment matters more than many teams expect. SOC 2 auditors routinely test whether employees have actually attested to policies, not just whether the documents exist. Drata’s automated attestation tracking removes ambiguity, which is exactly what auditors want.

Employee security awareness training is also required. This is not about depth. It is about consistency and coverage. Auditors look for proof that training occurred, that it is relevant to employee roles, and that completion records are maintained.

Step 7: Collect Evidence and Validate Readiness

This is the moment to pause and verify the facts before the auditor does.

Drata automates a large portion of evidence collection, but automation is never 100 percent. Certain artifacts remain manual or point-in-time by design. Examples include policy approvals, management sign-offs, risk review notes, and incident postmortems. These must exist, be current, and fall within the audit period.

Before inviting the auditor, run an internal readiness review. Look for missing screenshots, stale policy versions, disconnected integrations, or controls marked “implemented” without supporting proof. 

The most common readiness mistake is assuming that evidence collected automatically is automatically sufficient. Auditors test relevance and completeness, not tooling.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

Step 8: Prepare for the SOC 2 Audit Using Drata

Once the auditor is invited, Drata becomes the single source of truth for evidence requests, control mapping, and auditor questions. This centralization significantly reduces back-and-forth and prevents version confusion, which is one of the biggest time drains in traditional audits.

That said, auditors will still ask questions. Clarifications, compensating controls, and remediation plans are normal parts of a SOC 2 engagement. The AICPA explicitly frames SOC reporting as a dialogue, not a checklist exercise.

 

Teams that respond early and clearly tend to move through fieldwork faster and with fewer follow-ups.

Step 9: Pass the Audit and Respond to Findings

After testing is complete, auditors issue results. Minor findings or observations do not mean failure. They mean something needs to be clarified, adjusted, or formally documented.

What matters is how findings are addressed. Clear explanations, defined remediation steps, and realistic timelines signal control maturity.

Tracking remediation tasks in Drata ensures lessons learned carry forward rather than being rediscovered next year.

Step 10: Maintain Continuous Compliance

SOC 2 reports are issued annually, but expectations are continuous. Auditors and customers alike assume controls operate every day, not just during audit season.

Ongoing monitoring helps identify drift early. Access reviews, vendor reviews, and risk reviews should run on schedule, not be rushed weeks before renewal. 

This is the inflection point. Teams that operationalize compliance build confidence and speed over time. Teams that treat SOC 2 as a yearly sprint tend to burn out.

SOC 2 is not passed once. It is maintained deliberately.

Recommended Drata SOC 2 Timeline Example

Phase

Typical Duration

Scoping and integrations

Weeks 1–2

Control implementation and policies

Weeks 3–6

Readiness review and Type I audit

Weeks 7–8

Type II observation period

Months 3–6+

Conclusion: Your Next Steps to Get SOC 2 Audit-Ready in Drata

Drata can dramatically simplify SOC 2, but only when paired with clear scoping, ownership, and expert guidance. Automation accelerates good programs. It exposes weak ones.

If you want to shorten timelines, reduce audit risk, and avoid rework, a structured readiness approach matters.

Learn more about SOC 2 fundamentals from the AICPA SOC overview understand the background on SOC 2, and explore Drata’s platform capabilities.

If you want help scoping, implementing, or validating your Drata SOC 2 program, book a readiness assessment or request a demo. The right preparation turns compliance from a blocker into a growth asset.

FAQ: Drata SOC 2 Compliance

Does Drata guarantee I will pass a SOC 2 audit?
No. Drata provides structure and automation, not guarantees. Outcomes depend on control design and execution.

How long does SOC 2 take with Drata for a SaaS company?
Type I readiness often takes 6 to 8 weeks. Type II depends on the observation period.

What is the difference between continuous monitoring and the audit?
Monitoring tracks control health. The audit independently verifies control operation over time.

Which Trust Services Criteria should I choose first?
Security first. Add others only when justified by product behavior or customer demands.

What evidence is still manual?
Risk assessments, policy approvals, some vendor reviews, and exception documentation.

When should I involve an auditor?
Before heavy configuration to align expectations.

Can Drata help with vendor management?
Yes, but judgment and follow-up remain human responsibilities.

Axipro Author

Picture of Pedro Dias

Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

Blog Highlights

Explore More Articles

Compliance software collects the evidence. A consultant builds the system that evidence is meant to prove. That’s the real difference in the ISO 27001 consultant vs software decision, and most teams only figure it out after they’ve bought one and realized they still need the other. Below, we compare what each route covers, where it breaks down, and what it costs you in time, money, and your team’s hours. Short version: software on its own works for a small group of companies. For most SaaS and tech scale-ups trying to get an enterprise deal over the line, consultant-led implementation on a compliance platform is the faster and safer path to a certificate. Quick Answer: Consultant, Software, or Both? Software-only works if you already have an in-house security lead who’s taken a company through ISO/IEC 27001 before and has the time to own the project. Consultant-only still makes sense if you run mostly on-premise or legacy systems that platforms barely integrate with. For everyone else, which means most cloud-native companies under a few hundred people, a hybrid works best: a platform to handle evidence and monitoring, and a consultant to build the management system and stand behind it in front of an auditor. Here’s why. What an ISO 27001 Consultant Handles ISO/IEC 27001:2022 is a management system standard. Clauses 4 to 10 cover how you run information security, and Annex A lists 93 controls you pick from based on risk. Almost none of it is box-ticking. Most of it comes down to judgment calls about your business, and that’s what you’re paying a consultant for. Scoping, Gap Analysis and Risk Assessment Scope is the first decision you make, and the most expensive one to get wrong. Go too wide and you’ll spend months on controls for systems no customer asks about. Go too narrow and the certificate won’t get through the procurement review it was supposed to pass. A consultant scopes around the deals you’re trying to close, runs a gap analysis, and builds a risk assessment based on your real assets and threats. That’s the document auditors dig into hardest. ISMS Documentation and Policy Writing The standard asks for a specific set of documents: the ISMS scope, information security policy, risk assessment and treatment methodology, Statement of Applicability, risk treatment plan, and evidence of competence, monitoring, internal audit, and management review. A consultant writes these around how your company works day to day, instead of how a template imagines it works. Auditors check whether you follow your own procedures, so a mismatch shows up fast. Internal Audit and Certification Audit Support You need an internal audit before certification, and Clause 9.2 says the auditor has to be objective and impartial. In a small company, the people who built the ISMS can’t credibly audit it, so most teams outsource it through ISO 27001 internal audit services. A good consultant also gets your team ready for the Stage 1 and Stage 2 audits, joins the conversations that matter, and handles corrective actions if the auditor raises nonconformities.  What ISO 27001 Compliance Software Handles Compliance automation platforms, often called GRC platforms, have changed how cloud-native companies get certified. They’re very good at the repetitive, evidence-heavy side of the work. Automated Evidence Collection and Continuous Control Monitoring The platform plugs into your cloud provider, identity provider, code repos, HR system, and device management tools, then pulls evidence on its own. It’ll flag an unencrypted storage bucket, an ex-employee who still has access, or a laptop without disk encryption. For technical controls, that saves weeks of screenshots and spreadsheet tracking. Policy Templates and Annex A Control Mapping Most platforms come with a policy library and map each control to the ISO 27001 clauses and Annex A. You get a starting point and a clear view of which controls have evidence and which don’t. Auditor Access and Ongoing Compliance Tracking Auditors can log in and review evidence themselves, which cuts down fieldwork. After you’re certified, dashboards show when controls slip between surveillance audits, so you aren’t rebuilding evidence from scratch every year. Where Each Approach Falls Short Neither route covers everything by itself. The good news is that the ways each one fails are predictable, so you can plan around them. Limits of Compliance Automation Platforms A platform can tell you a control is failing. It can’t decide your scope, run your risk assessment, write a policy that matches your operations, convince your CTO to change the offboarding process, or explain to an auditor why you excluded a control from your Statement of Applicability. Templates can also make you feel further along than you are. A dashboard at 90% can hide an ISMS that won’t survive Stage 1, because the missing 10% is the management system itself. Insider Note: The Stage 1 problem we see most on software-only projects is a risk assessment copied straight from the platform’s default risk library. The risks are generic, the scores are almost identical, and nothing ties back to the company’s own assets. Auditors notice within minutes, and it weakens the Statement of Applicability that’s built on it. The other problem is ownership. Software assumes someone inside the company will drive the project. At most startups that’s a CTO or ops lead who already has a full-time job, and the subscription renews whether the work gets done or not. Limits of a Consultant-Only Approach A consultant working without automation spends billable days on things a platform does for free, like chasing screenshots, updating evidence trackers, and collecting the same proof again before every surveillance audit. You pay more and wait longer. You also end up with a program that’s only accurate on the day it’s handed over. Once the engagement ends, the evidence goes stale and year-two surveillance turns into a scramble. ISO 27001 Consultant vs Software: Side-by-Side Comparison Factor Consultant only Software only Hybrid (consultant + platform) Time to audit readiness 3 to 6+ months Highly variable; depends on internal expertise As little as 6 weeks for well-scoped

Uzbekistan regulates artificial intelligence through two documents. The first is Law ZRU-1115, signed on 21 January 2026. It amends existing legislation to define AI, stops anyone from basing decisions about people’s rights on AI output alone, and fines companies that process personal data unlawfully with AI. The second is the set of Ethical Rules approved by Order No. 3787, in force since 17 June 2026, which spell out what developers, implementers, and users actually have to do. Uzbekistan hasn’t passed a standalone AI act, and its rules don’t sort systems into risk tiers or require conformity assessments. The framework is short and blunt, and it’s already enforceable. Below we walk through what each document requires, who it applies to, how it stacks up against the EU AI Act, and what a company using AI in Uzbekistan should do next. Uzbekistan AI Regulation at a Glance (TL;DR) Instrument Date What it does Who it binds Law ZRU-1115 Signed 21 January 2026 Defines AI in law, sets general rules for AI-built information resources and systems, bans legally significant decisions based only on AI, adds fines for unlawful AI processing of personal data State bodies, organizations, website owners, anyone processing personal data with AI Order No. 3787 (Ethical Rules) Registered 14 March 2026, in force 17 June 2026 Sets eight mandatory ethical principles and lists rights and obligations for developers, implementers, and users Individuals and companies developing, implementing, or using AI in Uzbekistan Law No. 1125 (Personal Data amendments) Adopted 26 March 2026 Limits data localization to biometric, genetic, and local telecom user data, and allows cross-border transfers under conditions Personal data operators, including AI providers AI Strategy until 2030 (RP-358) 14 October 2024 Sets national targets for AI adoption, infrastructure, and skills Government bodies What Is Law ZRU-1115? The law’s official title is a mouthful: “On making additions and changes to certain legislative acts of the Republic of Uzbekistan in connection with the regulation of relations arising from the use of artificial intelligence.” Put simply, it’s an amending law. Instead of creating a new AI code, it writes AI into laws that were already on the books. When It Was Signed and When It Took Effect The Legislative Chamber of the Oliy Majlis adopted the bill on 12 August 2025, and the Senate approved it on 1 November 2025. President Shavkat Mirziyoyev signed it on 21 January 2026. You can read the official text in Lex.uz, Uzbekistan’s national legislation database. The law set out the principles and the penalties. The day-to-day detail arrived later with the Ethical Rules, which came into force on 17 June 2026. For compliance planning, treat mid-June 2026 as the point when the whole framework started applying. Why Uzbekistan Amended Existing Laws Instead of Passing a Standalone AI Act Uzbekistan wants more AI, not less. Its national strategy sets numeric targets for adoption, investment, and local computing capacity, and a heavy EU-style act would have worked against them. So lawmakers kept it light. They defined AI, drew two hard lines (human control over decisions that affect people’s rights, and protection of personal data), and left the Ministry of Digital Technologies to fill in the rest through secondary rules. Businesses get less legal certainty, and the government gets to move faster. Which Laws ZRU-1115 Changes For businesses, two amendments matter most. The Law “On Informatization” (ZRU-560-II, 2003) now contains a legal definition of AI, a new article on using AI in information resources and systems, duties for website owners, and updated powers for the ministry in charge. The Code on Administrative Liability now includes an offense for processing and spreading personal data unlawfully using AI. The Legal Definition of Artificial Intelligence in Uzbekistan Under the amended Law “On Informatization,” AI is a set of technological solutions that imitate human cognitive functions, including learning on their own and solving problems, and that produce results on specific tasks comparable to what a person could do. That’s deliberately broad. It covers generative AI, machine learning classifiers, recommendation engines, and most agentic systems. The Ethical Rules add a narrower term, the AI system: software built on AI that can find, collect, store, analyze, process, evaluate, and use data, and make decisions on its own based on that data. If your product makes a decision from data, or shapes one, assume it counts. Key Rules Introduced by Law ZRU-1115 General Principles for Using AI in Information Systems and Resources The new article in the Law “On Informatization” starts from harm. Information resources created with AI, and information systems running on AI, must not harm people’s life, health, freedom, honor, or dignity, or violate their other inalienable rights. The standard is short and open-ended. It gives regulators something to enforce against without saying in advance what counts as harm. Principle-based rules like this deserve to be taken seriously precisely because the edges are undefined. Human Oversight: No Decisions on Rights and Freedoms Based Solely on AI Most coverage leads with this provision, and it’s easy to see why. When someone makes a legally significant decision that affects human rights and freedoms, they can’t rely only on conclusions produced by AI systems or AI-built information resources. AI can feed into the decision, but a person has to make it. That applies to loan denials, benefit eligibility, hiring rejections, licensing outcomes, and disciplinary action. In each case, someone needs to look at the AI output and own the final call. Insider Note: In AI governance engagements, teams rarely struggle to show that a review step exists. What they struggle to show is that the reviewer could disagree, and sometimes did. If a human clicks “approve” on every AI recommendation and nobody ever records an override, auditors will see automation with a signature on top. Build the override path and log when people use it, starting on day one. Powers of the Authorized State Body (Ministry of Digital Technologies) ZRU-1115 makes the Ministry of Digital Technologies the authorized state body for AI. Among its new jobs, it’s

You can get a SaaS company ready for a SOC 2 audit in six weeks, but you’ll feel every one of them. Most published timelines say three to six months. For a company with no project owner, no identity provider, and nothing written down, that’s about right. A cloud-native startup that already has the basics in place and can protect some time is a different story, and it can fit the work into six hard weeks. This plan walks through that route one week at a time. Each week has an owner, an hour estimate, and a clear test for when it’s finished. The free Google Sheet version turns the plan into a tracker you can hand out to owners and update in your weekly standup. Before you start, know what you’re signing up for. At the end of week 6 you’ll be audit-ready, which isn’t the same as holding a Type II report. Nobody can get you a Type II in six weeks. This is also the do-it-yourself route, and it takes a lot of hours. We’ll show you where those hours go and what the faster option looks like. Is Six Weeks Realistic for Your Company? Six weeks works when most of the plumbing already exists and your job is to formalize it, fill the gaps, and prove it all works. It falls apart when you’re building the foundations and documenting them at the same time. Go through this table honestly before you promise a customer a date. Six weeks is realistic if… Plan for 10 to 16 weeks if… Your product runs on a major cloud provider You host on-premise or across several data centers You already use an identity provider with SSO Every tool has its own login and password You have fewer than about 50 employees You have multiple offices, subsidiaries, or products in scope One named person owns the project with 10 to 15 hours a week Compliance is “everyone’s job,” so in practice nobody owns it An engineer can give you 15 to 20 hours in weeks 3 and 4 Engineering is fully committed to a launch You only need the Security criteria You need Availability, Confidentiality, or Privacy on day one Landing mostly in the right-hand column doesn’t mean you should throw the plan out. Give each week two weeks instead of one and follow the same order. What “SOC 2 Ready” Means at the End of Week 6 SOC 2 doesn’t give you a certificate. An independent CPA firm examines your controls against the AICPA Trust Services Criteria and writes a report, and which of the two report types you go for decides what you can show a buyer after week 6. A Type I report checks whether your controls are designed properly on a single date. Once you’re ready, a Type I audit can start almost right away. A Type II report checks whether those controls kept working over an observation period of at least three months, and usually six to twelve. Most enterprise procurement teams want Type II in the end. Being “ready” at the end of this plan means your in-scope controls are in place, you can pull evidence for any of them on request, and your auditor is booked. From there you either start a Type I audit or open your Type II observation window. Plenty of buyers will sign with a Type I report plus a letter from your auditor saying the Type II period is underway. Important: The Type II clock doesn’t start until your controls are running. If readiness slips by a week, your Type II report slips by a week too. Founders who tell a prospect “we’ll have SOC 2 in Q3” often forget this and end up renegotiating the deal. Before Week 1: Four Decisions to Make First Settle these before the clock starts. If you change any of them halfway through, you’ll redo work. Scope. Decide which systems, teams, and data the report covers. For most SaaS companies that’s the production environment, the code repository, the identity provider, customer data stores, and any support tools that touch customer data. Corporate systems that never see customer data can usually stay out. Trust Services Criteria. Security (also called the Common Criteria) is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are optional. Report type. Pick Type I if a deal is blocked right now and the buyer will accept it. If there’s no deadline, go straight to Type II. You’ll need it eventually, and skipping Type I saves you an audit fee. Owner and tooling. Name one person who’s accountable for the plan, and decide where your controls and evidence will live. The tooling choice gets its own section below. Pro Tip: Adding Criteria Only add optional criteria when a customer contract or security questionnaire asks for them. Each one brings more controls to set up and more evidence to collect, and you can widen the scope in next year’s audit. Spreadsheet or Compliance Software: Choosing Your Tracking Tool Every SOC 2 program needs a system of record, meaning one place where each control, its owner, its status, and its evidence live. You can run it yourself in a spreadsheet or a GRC platform, or have a consultant implement it for you. The right choice depends mostly on which report you’re after and how much of your team’s time you can spare. A spreadsheet is free and familiar. It also makes you understand your own environment before you automate any of it. For a Type I, or for a small team with a tight scope, a well-built spreadsheet can take you all the way to the audit. Axipro’s free GRC workbook for SOC 2 and ISO 27001 covers all 33 SOC 2 Common Criteria plus the optional criteria, with evidence, risk, policy, and gap trackers built in. It has no macros and opens straight in Google Sheets or Excel. A GRC platform connects to your cloud, identity provider, code repository, and HR system.