Skip to content

Scope, fee and working days are published on every engagement

CorePhysix Labs Technology lab

Specification SEC·103

SEC · Security & Compliance Defined scope Fixed fee

SOC 2 Evidence Groundwork

Technical controls and automated evidence collection for a SOC 2 Type II audit, operating before your observation window opens.

Fee · GST incl.
₹44,999
Duration
30 working days
Deliverables
7

01 Overview

A SOC 2 audit turns on evidence: proof, gathered over months, that access was reviewed, changes were approved, backups were restored and logs were kept. Building that record after the observation window has started is slow and stressful. We put the technical controls in place first, including automated access reviews, change management through pull requests, centralised logging with retention and vulnerability management with SLAs. Evidence collection is automated wherever possible, so nobody is capturing console screenshots the week before the audit.

02 Deliverables

7 items

What you receive at handover

  1. D01 Control gap assessment against the Trust Services Criteria in scope
  2. D02 Automated access review process producing quarterly evidence
  3. D03 Change management enforced through pull request approvals with an audit trail
  4. D04 Centralised logging with retention that meets audit requirements
  5. D05 Vulnerability management workflow with SLAs by severity
  6. D06 Backup, restore and disaster recovery tests with documented evidence
  7. D07 Runbook for evidence collection, mapped to each control

03 Outcomes

What should be true once it ships

  • Audit evidence accumulates automatically instead of being reconstructed later
  • Controls are already operating on the first day of the observation window
  • Fewer findings for the auditor to raise, which keeps the audit shorter and less costly

04 Process

How the 4 stages run

  1. Assess Existing controls are compared with the criteria in scope
  2. Implement Technical controls are built and connected to your current tooling
  3. Automate Evidence collection is scheduled so it builds up without manual effort
  4. Rehearse We issue a mock evidence request in the way an auditor would

05 Fit & inputs

A good fit for

  • Businesses whose enterprise deals stall at the security questionnaire
  • Startups about to begin a SOC 2 Type II observation window
  • Teams that have a compliance platform but nobody to do the engineering work

What we need from you

  • Administrative access to your cloud, identity and code repository systems
  • A designated compliance owner within your organisation
  • Details of your auditor or compliance platform, if you have already chosen one

These inputs are collected through the technical brief in your dashboard after payment. The duration is counted from when they arrive.

06 Answers

Questions about this engagement

No. SOC 2 audits must be performed by a licensed CPA firm. We prepare you and work alongside the auditor you appoint.

The technical controls overlap substantially. ISO 27001 also requires an ISMS and management system documentation, which we scope separately.

A Type II report needs an observation window of three to twelve months once controls are operating. This work shortens the preparation, not the window.

This is technology work delivered digitally — nothing is shipped. Work is delivered into systems you control within the duration stated above, and the delivery and refund policies set out what happens if a date is missed.

REL Related

Often considered alongside.

All Security & Compliance

Web Application VAPT

Manual penetration testing of your web application with evidence for each finding and a retest, so real risks are fixed and proven fixed.

Manual penetration test of authentication, authorisation and business logic

Fixed fee · GST incl.

₹29,999

Duration

12 working days

DPDP Act Readiness Review

A gap assessment against the DPDP Act, 2023 covering consent, retention, notices and breach handling, with a prioritised remediation plan.

Inventory of personal data held across your systems, vendors and storage locations

Fixed fee · GST incl.

₹22,999

Duration

15 working days

Cloud IAM Permissions Audit

Every cloud identity checked against what it actually uses, with over-broad permissions tightened in safe batches to limit breach impact.

Inventory of all users, roles, service accounts and access keys

Fixed fee · GST incl.

₹18,999

Duration

10 working days

GST included

₹44,999

Next step

Have a system that needs building, fixing or securing?