SOC 2 Audit Services | International Accurate Certification (IAC) — Header
US-Certified Body · In-House CPA Team · Zero to Audit-Ready

SOC 2 Controls,
Built From Scratch, Done Right.

No policies yet? No formal access controls? That's the normal starting point. London Cert's implementation team designs, documents, and stands up everything SOC 2 requires — sized to your actual stack, not a generic template dump.

Talk to an Implementation Lead
No obligation · Response within 24 hours
🧱
SOC 2 Implementation Acme Corp · Built with London Cert
In Progress
Control DesignMapped to your actual systems
Wk 1–2
Policy Drafting18+ documents written, not templated
Wk 2–4
Tooling SetupLogging, access & monitoring configured
Wk 4–6
Team HandoffYour staff trained on the controls
Wk 6–7
🏆
Audit-ReadyHanded to our CPA for attestation
Wk 8
US Certified Body
In-House CPA Team
18+ Policies Included
6–8 Wk To Audit-Ready
Custom Not Templated
AICPA Standard Reports

Nobody Knows Where to Start

This is where most first-time SOC 2 companies get stuck before an audit is even on the table.

📄

Zero Policies Exist

There's no written access control policy, no incident response plan, no vendor management process — just tribal knowledge in a few engineers' heads that nobody's written down.

🧩

Templates Don't Fit

A generic policy pack downloaded off the internet describes infrastructure you don't run and controls you can't actually implement — so it sits unused while the real gaps stay open.

Engineering Time Gets Eaten

Without a clear implementation plan, your engineers spend weeks guessing at what auditors will ask for, building controls that get reworked twice before they're audit-ready.

What Proper Implementation Actually Buys You

Done right the first time, so the audit is a checkpoint, not a discovery process.

🎯

Controls Sized to Your Stack

No generic policy pack. Every control is mapped to the tools and infrastructure you actually run, so nothing gets built that doesn't apply — and nothing critical gets missed.

No Rework at Audit Time

Controls are designed against AICPA criteria from day one, so the auditor isn't the first person to flag a gap. What you build is what passes.

👥

Your Team Actually Understands It

We train the people who'll own these controls day to day — not just hand over a binder of policies nobody reads until the next audit forces them to.

Five Steps From Zero to Audit-Ready

A one-time build-out project. The same team designs, writes, and hands off every control — you're not managing three different vendors.

1
Week 1–2

Discovery & Scoping

We map your actual infrastructure, data flows, and existing (informal) practices against the Trust Services Criteria to see exactly what needs to be built.

2
Week 2–4

Control Design

We design each control around the tools you actually use — not a generic checklist — so nothing gets built that doesn't fit how your team really works.

3
Week 3–5

Policy Drafting

Access control, incident response, vendor management, and the rest of the required policy set get written for your business, not copy-pasted from a template.

4
Week 4–6

Tooling & Configuration

We help set up or configure logging, access management, and monitoring so the controls on paper are actually running in your systems.

5
Week 6–8

Team Handoff

We train the people who'll own each control day to day, then hand you off audit-ready — straight into our audit services team if you're ready to go.

What Happens After Implementation?

Implementation gets you audit-ready. The audit itself is a separate, independent step.

Once your controls are built and your team is trained, an independent CPA has to verify them — that's a legal requirement, not a formality. Our audit services team reviews access logs, tests permission settings, checks monitoring tools, and confirms your written policies match what's actually happening in your systems. Because the same organization ran your implementation, the auditor already knows exactly how your controls were designed.

The auditor checks that controls are followed in practice, not just documented on paper — a policy that exists but isn't enforced won't pass. Since your implementation was built against the same Trust Services Criteria the auditor tests against, there's rarely a surprise gap to remediate mid-audit.

Two Ways to Get Your Controls Built

Both end in the same place — a fully documented, working control environment. The difference is how much of the building your team does.

Guided

We Design, You Build

We map your controls, write every policy, and hand your team a step-by-step configuration guide — your engineers do the technical setup with us reviewing each step.

⏱ 6–8 weeks to audit-ready
  • Full control design mapped to your stack
  • 18+ policy documents, custom-written
  • Step-by-step configuration guide
  • Weekly progress reviews
  • Team training included
Get Guided →

One Partner for Your Whole Compliance Roadmap

SOC 2 is usually the starting point. As your deals get bigger, the next framework is often already on someone's checklist — we cover it without adding a second vendor.

🛡️

SOC 2 Type II

Full attestation, AICPA-standard, in-house CPA

📋

SOC 2 Type I

Fast-track point-in-time report

🌐

ISO 27001

Information security management

🏥

HIPAA

Healthcare data compliance

🇪🇺

GDPR

EU & UK data privacy

⚖️

GRC

Governance, Risk & Compliance

📊

SOX

Sarbanes-Oxley controls

💻

ITGC

IT General Controls review

Guided Implementation vs. Building It Yourself

Building your own controls from scratch is possible. Here's what it usually costs in time and rework compared to having us design it.

London Cert Implementation Built In-House
Time to Audit-Ready 4–8 weeks Often 4–6 months of trial and error
Policy Set 18+ documents, written for your stack Generic templates, rarely fit as-is
Control Design Mapped directly to AICPA criteria Guesswork on what auditors expect
Rework at Audit Time Rare — designed against audit criteria upfront Common — gaps found during fieldwork
Engineering Time Spent Focused, scoped setup work Weeks of research plus rebuilding
Team Training Included as part of handoff Usually skipped or informal
Path to Audit Direct handoff to our audit team Separate vendor search required
Pricing Fixed-price project quote Hidden cost of engineering hours & delays

Where SOC 2 Fits Among the Alternatives

If you're not sure which framework your buyers actually need, this is a fast way to check — and every option below is one we handle in-house.

Framework Best For London Cert Covers
SOC 2 Type II ⭐ SaaS, Cloud, IT Services ✓ Yes
SOC 2 Type I Startups, Fast deal unblocking ✓ Yes
ISO 27001 Global enterprises, EU companies ✓ Yes
HIPAA Healthcare data processors ✓ Yes
GDPR EU & UK data privacy ✓ Yes
GRC Governance & risk management ✓ Yes
SOX / ITGC Public companies, financial controls ✓ Yes
No Certification ✗ Blocked from deals

Questions We Get on Nearly Every Call

If something isn't covered here, it's a five-minute question to answer directly — just reach out.

We have zero security policies today — is that a problem?
That's the normal starting point for most first-time clients, not a red flag. Implementation exists precisely for companies with no formal controls yet. We start from a discovery call, map what you actually run, and build everything from there — nothing assumes you already have infrastructure in place.
Does implementation include the actual audit?
No — implementation builds and documents your controls; the audit is a separate, independent CPA review that verifies they work. Most clients move directly into our audit services once implementation wraps, since the controls are already built to the same criteria the auditor tests against.
What's the difference between Guided and Hands-On?
Guided gives your engineers a step-by-step configuration plan and we review each step as it's completed. Hands-On has our implementation engineers configure the tooling directly alongside your team, which is faster if your engineers don't have spare bandwidth for a multi-week build-out.
How much does implementation cost?
Pricing is a fixed project fee based on scope — how many systems, which Trust Services Criteria apply, and whether you choose Guided or Hands-On. We provide a firm quote after the discovery call, once we've seen what's actually involved.
Which Trust Services Criteria should we include?
The Security criterion (CC) is mandatory for all SOC 2 reports. The remaining four — Availability, Processing Integrity, Confidentiality, and Privacy — are optional and selected based on what your clients and contracts require. We guide you through this scoping decision during discovery, before any controls get built.
Can London Cert also help with ISO 27001, HIPAA, GDPR, and GRC?
Yes — London Cert covers your full compliance roadmap. We offer SOC 2, ISO 27001, HIPAA, GDPR, GRC, SOX, and ITGC under one roof. Since many of these frameworks share overlapping controls, implementing them together often means less duplicated work than doing each one separately.
Will our engineering team need to do a lot of work?
Some, but we scope it to be manageable alongside normal work. With Guided, your engineers handle configuration with our review at each step. With Hands-On, our engineers do most of the technical setup directly, so your team's time is mostly spent on review calls and approvals.
We started building controls ourselves — can you take over partway through?
Yes, this comes up often. We review what's already in place, keep anything that's solid, and fill in the gaps rather than starting from zero. It usually shortens the timeline compared to a full build-out from scratch.

Stop Guessing at What Auditors Will Ask For

Talk to an implementation lead. We'll review your current setup, map exactly what's missing, and quote a fixed price to get you audit-ready — no obligation.

Scroll to Top