Advisory

SOC 2 & assurance readiness

A successful audit starts long before the auditor arrives. Normstone helps teams scope the work, establish ownership, implement controls, and build a reliable evidence trail.

The mandate

Build controls and evidence customers can trust.

We prepare service organizations for SOC 2 examinations and design security management systems aligned to ISO/IEC 27001.

Discuss this work

How we help

  • SOC 2 system scoping and readiness
  • Control design and operating evidence
  • ISO/IEC 27001 ISMS implementation
  • Integrated control frameworks
  • Independent examination and certification preparation

What the work produces

  • Defined scope and control ownership
  • Working policies, procedures, and records
  • An evidence plan aligned to independent assessment

Common questions

Clarify the mandate before delivery.

Can one project prepare for both SOC 2 and ISO/IEC 27001?

Often yes. Many operating controls and records can serve both goals, but SOC 2 reports on a defined service organization system and ISO/IEC 27001 assesses an information security management system. Scope and evidence must be checked separately.

Who issues a SOC 2 report or ISO/IEC 27001 certificate?

An independent licensed CPA firm performs a SOC 2 examination. An independent certification body makes ISO/IEC 27001 certification decisions. Normstone’s role is implementation and readiness advice.

When should evidence collection begin?

As soon as the controls operate. Collect records in the normal workflow, review samples against the intended assessment scope, and track exceptions while they can still be corrected.

Primary references

Work with Normstone

Let’s build what stands up to scrutiny.

Tell us what you need to achieve. We’ll help define the right first step.

Start a conversation