SOC 2 Controls,
Built From Scratch, Done Right.
No policies yet? No formal access controls? That's the normal starting point. London Cert's implementation team designs, documents, and stands up everything SOC 2 requires — sized to your actual stack, not a generic template dump.
Nobody Knows Where to Start
This is where most first-time SOC 2 companies get stuck before an audit is even on the table.
Zero Policies Exist
There's no written access control policy, no incident response plan, no vendor management process — just tribal knowledge in a few engineers' heads that nobody's written down.
Templates Don't Fit
A generic policy pack downloaded off the internet describes infrastructure you don't run and controls you can't actually implement — so it sits unused while the real gaps stay open.
Engineering Time Gets Eaten
Without a clear implementation plan, your engineers spend weeks guessing at what auditors will ask for, building controls that get reworked twice before they're audit-ready.
What Proper Implementation Actually Buys You
Done right the first time, so the audit is a checkpoint, not a discovery process.
Controls Sized to Your Stack
No generic policy pack. Every control is mapped to the tools and infrastructure you actually run, so nothing gets built that doesn't apply — and nothing critical gets missed.
No Rework at Audit Time
Controls are designed against AICPA criteria from day one, so the auditor isn't the first person to flag a gap. What you build is what passes.
Your Team Actually Understands It
We train the people who'll own these controls day to day — not just hand over a binder of policies nobody reads until the next audit forces them to.
Five Steps From Zero to Audit-Ready
A one-time build-out project. The same team designs, writes, and hands off every control — you're not managing three different vendors.
Discovery & Scoping
We map your actual infrastructure, data flows, and existing (informal) practices against the Trust Services Criteria to see exactly what needs to be built.
Control Design
We design each control around the tools you actually use — not a generic checklist — so nothing gets built that doesn't fit how your team really works.
Policy Drafting
Access control, incident response, vendor management, and the rest of the required policy set get written for your business, not copy-pasted from a template.
Tooling & Configuration
We help set up or configure logging, access management, and monitoring so the controls on paper are actually running in your systems.
Team Handoff
We train the people who'll own each control day to day, then hand you off audit-ready — straight into our audit services team if you're ready to go.
What Happens After Implementation?
Implementation gets you audit-ready. The audit itself is a separate, independent step.
Once your controls are built and your team is trained, an independent CPA has to verify them — that's a legal requirement, not a formality. Our audit services team reviews access logs, tests permission settings, checks monitoring tools, and confirms your written policies match what's actually happening in your systems. Because the same organization ran your implementation, the auditor already knows exactly how your controls were designed.
The auditor checks that controls are followed in practice, not just documented on paper — a policy that exists but isn't enforced won't pass. Since your implementation was built against the same Trust Services Criteria the auditor tests against, there's rarely a surprise gap to remediate mid-audit.
Two Ways to Get Your Controls Built
Both end in the same place — a fully documented, working control environment. The difference is how much of the building your team does.
We Design, You Build
We map your controls, write every policy, and hand your team a step-by-step configuration guide — your engineers do the technical setup with us reviewing each step.
- Full control design mapped to your stack
- 18+ policy documents, custom-written
- Step-by-step configuration guide
- Weekly progress reviews
- Team training included
We Design and Build It
Our implementation engineers configure the logging, access management, and monitoring tooling directly alongside your team — you review and approve, we do the heavy lifting.
- Everything in Guided, plus:
- Direct tooling configuration by our engineers
- Faster timeline — less back-and-forth
- Dedicated implementation lead
- Seamless handoff into audit services
One Partner for Your Whole Compliance Roadmap
SOC 2 is usually the starting point. As your deals get bigger, the next framework is often already on someone's checklist — we cover it without adding a second vendor.
SOC 2 Type II
Full attestation, AICPA-standard, in-house CPA
SOC 2 Type I
Fast-track point-in-time report
ISO 27001
Information security management
HIPAA
Healthcare data compliance
GDPR
EU & UK data privacy
GRC
Governance, Risk & Compliance
SOX
Sarbanes-Oxley controls
ITGC
IT General Controls review
Guided Implementation vs. Building It Yourself
Building your own controls from scratch is possible. Here's what it usually costs in time and rework compared to having us design it.
| London Cert Implementation | Built In-House | |
|---|---|---|
| Time to Audit-Ready | 4–8 weeks | Often 4–6 months of trial and error |
| Policy Set | 18+ documents, written for your stack | Generic templates, rarely fit as-is |
| Control Design | Mapped directly to AICPA criteria | Guesswork on what auditors expect |
| Rework at Audit Time | Rare — designed against audit criteria upfront | Common — gaps found during fieldwork |
| Engineering Time Spent | Focused, scoped setup work | Weeks of research plus rebuilding |
| Team Training | Included as part of handoff | Usually skipped or informal |
| Path to Audit | Direct handoff to our audit team | Separate vendor search required |
| Pricing | Fixed-price project quote | Hidden cost of engineering hours & delays |
Where SOC 2 Fits Among the Alternatives
If you're not sure which framework your buyers actually need, this is a fast way to check — and every option below is one we handle in-house.
| Framework | Best For | London Cert Covers |
|---|---|---|
| SOC 2 Type II ⭐ | SaaS, Cloud, IT Services | ✓ Yes |
| SOC 2 Type I | Startups, Fast deal unblocking | ✓ Yes |
| ISO 27001 | Global enterprises, EU companies | ✓ Yes |
| HIPAA | Healthcare data processors | ✓ Yes |
| GDPR | EU & UK data privacy | ✓ Yes |
| GRC | Governance & risk management | ✓ Yes |
| SOX / ITGC | Public companies, financial controls | ✓ Yes |
| No Certification | — | ✗ Blocked from deals |
Questions We Get on Nearly Every Call
If something isn't covered here, it's a five-minute question to answer directly — just reach out.
Stop Guessing at What Auditors Will Ask For
Talk to an implementation lead. We'll review your current setup, map exactly what's missing, and quote a fixed price to get you audit-ready — no obligation.