Audit-ready, continuously

Your SOC 2 audit is in 23 days. You have 3 critical controls incomplete and 13 that need evidence.

Most compliance programs are audit-week scrambles surrounded by 11 months of hoping nothing changed. The platform runs the other way — continuous readiness across SOC 2, ISO 27001, HIPAA, PCI DSS, and 250+ other frameworks running side by side. Every control gets evidence attached as soon as it fires. Every framework inherits the evidence its underlying controls already satisfy. Every audit becomes a review of what you’ve been doing, not a discovery of what you haven’t.

250+frameworks the platform cross-maps controls against — SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and every other framework you might need nextSecure Controls Framework (SCF) catalog
$25–75Ktypical audit-firm invoice for a first-year SOC 2 Type II — not counting the internal hours automation absorbsIndustry benchmark (AICPA + mid-market audit firm rate cards)
12–18 motypical first-time SOC 2 Type II timeline without compliance automation — most of it manual evidence collection and control-mapping workIndustry benchmark (Big-4 audit + AICPA guidance)
Compliance isn’t a moment. It’s a system that runs between audits, so audits become verification instead of discovery.
The audit-week scramble is a symptom. The system that prevents it is the fix.

How compliance changes

From “the audit is in 23 days” to “the audit is a review of what we’ve been doing.”

Three patterns most compliance programs live with — SOC 2, ISO 27001, HIPAA, PCI DSS or any framework — and what changes on the platform.

Today
On the platform
Evidence gets collected in the 30-day sprint before the audit.Somebody screenshots the access-review UI, exports the SIEM query, saves it to a shared drive. Half the evidence is timestamped weeks after the control fired.
30 days of scramble
Evidence attaches to each control the moment it fires.Access review completes → signed artifact lands. Vulnerability scan runs → signed artifact lands. Auditor sees the actual event trail, not a reconstruction.
0 days of scramble
One control satisfies one framework; the other three audits start from scratch.Same MFA policy answered three different ways for SOC 2, HIPAA, and PCI DSS. Auditors notice the inconsistency; you spend the audit explaining the discrepancy.
1 : 1 control : framework
One control satisfies every framework it maps to, everywhere.One MFA policy answers SOC 2, ISO 27001, HIPAA, and PCI DSS at the same time — same source of truth, same defensible answer to every auditor. Add a fifth framework next year and it inherits the existing evidence too.
1 : 250+ control : framework
Evidence is a folder of screenshots the auditor takes on faith.No cryptographic verification, no chain of custody, no way to prove the screenshot wasn’t doctored. Any experienced auditor treats it as unverifiable and asks for source-system access.
Manual source-system pulls
Every artifact signed at the source, verifiable at a public URL.The auditor checks the evidence themselves — no production-access request, no back-and-forth over whether a screenshot got doctored. Standard cryptographic signatures underneath, so it holds up if the auditor’s technical reviewer looks closer.
0 source-system pulls

Act 00 · Start here

First audit ever? You’re not behind, you’re starting from a defensible baseline.

First SOC 2. First HIPAA. First ISO 27001. First anything. You don’t have policies. You don’t have prior-year evidence. You don’t know what “CC6.1” means and you’re not sure whether Type I or Type II is the right starting posture. That’s every founder who just closed their first enterprise deal and got the compliance ask. The platform bootstraps a compliance program from a short onboarding — stack scan, starter policies generated from your live infrastructure, first-audit-focused control set — so you can answer the buyer’s question honestly and start the audit clock the same week.

  • Framework selectionSOC 2 Type I for US enterprise buyers, ISO 27001 for European. If unsure, we help you pick based on your actual buyer footprint — not a template recommendation.
  • Starter policiesGenerated from your live stack (identity provider, cloud footprint, source hosting, HRIS). Auditor-defensible on day one; refined as your controls mature.
  • Type I now, Type II when readyType I gets you audit-ready in 60-90 days. The 3-12 month Type II observation window starts once your controls are stable. Both timelines are the audit standard, not the platform.
Start with the Starter plan

Act 01·Multi-framework readiness·Every framework, running at the same time

Continuous readiness across every framework you run.

You’re rarely running just one framework. It’s SOC 2 plus HIPAA because you sell into healthcare. SOC 2 plus ISO 27001 for the EU expansion. SOC 2 plusPCI DSS because you process payments. Each framework used to demand its own control tracker, its own audit sprint, its own evidence pile. Not here. The platform runs a live readiness view for every framework in your program — side by side, at the same time — and because the same underlying control satisfies multiple framework requirements, a single evidence update often moves the score on three or four frameworks at once.

  • Every framework, one viewWhatever combination you’re running — SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, FedRAMP, CMMC, GDPR, more — every framework is tracked concurrently, at control granularity, with its own readiness score and next-audit date.
  • One update, multiple scores moveMFA gets enrolled for the finance team — and the readiness score moves on SOC 2, ISO 27001, HIPAA, NIST CSF, and PCI DSS at the same time. The underlying control is one thing; the frameworks scoring it are five.
  • Continuous, not cyclicalNo pre-audit scramble. When the auditor arrives, the readiness view they see is the same view you’ve been looking at all quarter — every framework, current to the hour.

Act 02·Cross-framework multiplier·One control, four audits

Satisfy one control, count it against every framework it maps to.

The MFA policy that answers SOC 2 CC6.1 also answers ISO 27001 A.9.2.3, HIPAA §164.312(a)(1), and PCI DSS Req 8.2 — because they’re describing the same underlying control from different angles. The platform cross-maps every control through the Secure Controls Framework (SCF) catalog — 250+ frameworks total. When you improve a control, the score against every framework it satisfies moves in the same cycle. When your controls change, the platform flags every framework mapping that references them. Nobody maintains the mapping table by hand.

  • One catalog, every frameworkThe mapping runs on the Secure Controls Framework (SCF) — the industry-standard cross-walk auditors already trust. 250+ frameworks mapped; every control you satisfy inherits its downstream framework coverage.
  • Change propagationWhen a control changes, every framework mapping that referenced it flags for review — you update once, everywhere it’s referenced updates too.
  • Any framework, at any timeAdd FedRAMP, CMMC, DORA, or any other framework to your program mid-cycle; it inherits your existing evidence for the controls that cross-map.

Act 03·Evidence with receipts·Tamper-resistance the auditor can verify

Evidence with cryptographic receipts, not folders of screenshots.

Auditors don’t trust screenshots. They can’t. There’s no way to prove the screenshot wasn’t doctored between the time it was taken and the time it landed in the evidence bundle. Which is why most audit engagements end up requesting source-system access — the auditor pulls the access-review CSV themselves, from your identity provider, because it’s the only way they can trust the artifact. Every evidence artifact the platform collects is Ed25519- signed and chain-anchored at collection time. The auditor verifies tamper-resistance at a public URL. No source-system access request. No trust-me-bro.

  • Signed at collectionEvery artifact gets an Ed25519 signature the moment it’s collected — from the source system, before any human sees it. Chain of custody starts at zero.
  • Chain-anchoredSignatures are anchored to a tamper-evident chain so their integrity survives the round trip to the auditor and back. Standard cryptographic verification.
  • Public verifierAuditor runs the verifier from a public URL. No sign-up on their side, no source-system access. The math does the talking; you don’t have to.

Act 04·The evidence graph·See it, sample it, verify it

Continuous compliance you can actually see — for you and for the auditor.

Signed evidence is what makes the artifacts defensible. The evidence graph is what makes them usable. A live 12-month timeline for every control — evidence marks landing continuously, policy attestations dropping on schedule, gaps flagged the day they open, compensating controls filling them, every mark the auditor can verify themselves at a public URL. Same artifact, two audiences, one shared source of truth.

  • For the preparerLive readiness across the whole observation period, not just the audit week. Gaps surface the day they open — you fix them before the auditor asks.
  • For the auditorRapid sampling against any control at any date. Signed evidence verified in-place. Working-paper export in one click.
  • One source of truthSame signed evidence from Act 03 powers the graph. The signatures keep it defensible under audit; the graph makes it usable day-to-day. Both audiences look at the same underlying record.
Carbon compliance evidence graph, SOC 2 CC6.1 (Logical Access Controls) — twelve-month observation window with 1,247 evidence records across five categories, 22/23 sub-controls evidenced, three identified gaps all remediated, one scope-blocked zone, two compensating controls applied, chain attestation verified. Multi-lane timeline shows IAM/access-reviews, MFA enforcement, and SoD/privileged-access lanes with continuous captures, quarterly snapshots, policy attestations, and remediation events; right panel shows a selected gap (MFA capture, Q2 2027) with integration/capability metadata, root cause, and the remediation chain of events.

Live view: CC6.1 — Logical Access Controls, 12-month observation window. Same graph the auditor samples.

Worked example

Your SOC 2 audit is in 23 days. Here’s what happens next.

Day 1
Mon

Readiness board shows 91% ready overall. Three access- control gaps in CC6 (privileged account inventory, quarterly access review evidence, HRIS-to-IdP webhook test log) plus one evidence gap in CC5 (change-management approval workflow last updated 14 months ago). Total work: four discrete items, each with an owner and a due date.

Days 2–5
Tue–Fri

IT lead runs the privileged account inventory (already queued in the platform;2 hrs). Access review for Q1 2026 gets scheduled, runs, and lands as a signed artifact (3 hrs across a week). HRIS-to-IdP webhook test runs; the log gets attached. Change-management workflow gets refreshed with the actual approver chain (which had shifted; the old doc was 14 months stale).

Day 8
Mon

Board: 100% ready. Every control has evidence attached and signed. You export the auditor-ready bundle — signed evidence, the management-representation letter (the sign-off from you to the auditor that every audit requires), and the mapping table showing every SOC 2 control to its underlying artifact. Total elapsed: 8 days, 15 hours of actual work across three people.

Days 8–23
Audit prep

You send the bundle to the CPA firm ahead of the audit kickoff. Their pre-audit review comes back withzero findings— the evidence is complete and cryptographically verifiable, so they don’t need to request source-system access to spot-check.

Day 24
Audit

Audit runs on schedule. Type I report issued 12 business days after kickoff. The Type II observation window starts immediately for the following year’s report — and because the platform is already collecting continuous evidence, next year’s Type II is on-schedule from day one.

The audit was a verification of what you’ve been doing, not a discovery of what you haven’t.

Why this holds up under an audit

Four things that have to be true together.

Continuous readiness needs all four; any one on its own is a compliance-in-name-only tool.

Continuous, not sprint

Evidence attaches the moment a control fires. Not once a quarter, not once before the audit. The audit becomes verification, not discovery.

One control, every framework

The MFA control that answers SOC 2 also answers ISO 27001, HIPAA, and PCI DSS at the same time. Improve one control, credit against every framework it satisfies.

Auditors verify without touching your systems

Every artifact carries a cryptographic signature the auditor checks at a public URL — no production-access request, no back-and-forth over whether a screenshot got doctored. Standard cryptography underneath, so it holds up under technical review.

Auditor-shaped output

Export bundle matches the CPA firm’s intake shape — signed evidence, management-representation letter, control-to-artifact mapping. Zero reformatting on their side.

Don’t want to run the audit prep yourself?

Other20 advisory offers fully-managed audit-prep engagements — SOC 2, ISO 27001, HIPAA, PCI DSS, or any framework we cross-map. Includes the readiness assessment, gap remediation guidance, evidence collection, and CPA-firm-facing handoff. Retainer or per-audit pricing, well under what full-service compliance firms charge.

See Other20 advisory services

COMMON QUESTIONS

Framework-specific questions

  • How long does SOC 2 audit prep take with vCISO Lite?

    Most startups reach SOC 2 Type I audit-ready in 60 days from kickoff, assuming reasonable existing security controls. Type II adds the 3-12 month observation window (regardless of platform — that timing is set by the audit standard, not by us). The bulk of the manual evidence-collection work — the part that turns compliance prep into a full-time job — is automated by the platform, so what's left is the strategic work: policy decisions, control design, and stakeholder alignment.

  • SOC 2 or ISO 27001 first?

    Depends on your buyer footprint. SOC 2 is the default for US-based enterprise SaaS buyers and typically completes faster (60-90 days to Type I audit-ready). ISO 27001 is expected by most European and international enterprise buyers and takes longer (90-180 days) because the audit standard is broader. If you're selling into both, do SOC 2 first for the faster time-to-audit-ready, then extend into ISO 27001 — most SOC 2 controls cross-map directly. For the specific first-audit decision, see SOC 2 vs ISO 27001: Which First, Which Second.

  • Can we reuse SOC 2 evidence for HIPAA?

    Yes, meaningfully. Roughly 60-70% of HIPAA §164.308 (administrative safeguards) and §164.312 (technical safeguards) cross-map to SOC 2 CC-series controls. The platform automatically applies your SOC 2 evidence to the HIPAA controls it satisfies — you'll still need HIPAA-specific policies (BAA management, PHI classification, breach notification cadence) but the underlying access-control, encryption, and monitoring evidence carries over.

  • What does a PCI DSS audit prep sprint look like?

    PCI DSS scope is unusually specific — it applies to cardholder data environments (CDE), not the whole business, so scoping is the first hard question. The platform helps identify the CDE boundary, applies scoping-appropriate controls (Req 6 secure development, Req 8 authentication, Req 10 logging + monitoring, Req 11 quarterly ASV scans), and produces an ROC-ready evidence bundle for your QSA. Typical timeline: 90-120 days from kickoff to QSA-ready, depending on the CDE complexity and starting posture.

  • What frameworks does the platform cover?

    Twelve frameworks are cross-mapped and audit-ready from day one: SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, NIST 800-53, GDPR, CCPA, FERPA, COPPA, CIPA, and the CSA Cloud Controls Matrix. Beyond those, the underlying cross-mapping catalog (the Secure Controls Framework) covers 250+ frameworks — any of them can be added to your program and inherits the same cross-mapping benefits.

  • How does the platform prevent evidence tampering?

    Every evidence artifact collected in the platform is cryptographically signed (Ed25519) and chain-anchored. Auditors verify tamper-resistance at a public URL without needing us to grant access to source systems. The cryptographic verification replaces the traditional "screenshot with a timestamp" audit trail that any experienced auditor treats as unverifiable.

  • What happens when a control changes and it's tied to multiple frameworks?

    Every control that's cross-mapped flags for review across every framework it satisfies when its underlying evidence changes. You update the control once (new policy version, new access-review artifact, new remediation), and the platform propagates the change to every framework mapping that referenced it. Auditors see the change history with cryptographic provenance; you don't maintain the mapping table by hand.

Make the audit a verification, not a discovery.

See how continuous readiness across SOC 2, ISO 27001, HIPAA, PCI DSS, and 250+ other frameworks changes the audit calendar.