The Problem
Enterprise customers and regulated industries increasingly require SOC 2 Type II or ISO 27001 certification as a condition of doing business. Most organisations fail their first attempt โ not because they are insecure, but because compliance requires a specific kind of evidence collection, control documentation, and audit preparation that security teams are not trained for. A failed audit costs time, money, and damages the trust you were trying to build.
Our Approach
Scoping & Framework Selection
We determine which SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) are in scope, and whether SOC 2 Type I or Type II is appropriate. For ISO 27001, we define the ISMS scope and applicable Annex A controls.
Gap Assessment
Structured assessment of your current control environment against all in-scope requirements. Every gap documented with risk rating, remediation effort estimate, and ownership recommendation.
Control Design & Implementation
We design controls that satisfy auditor requirements and actually improve your security posture. Policies written. Technical controls configured. Evidence collection processes established from day one.
Observation Period Management
For SOC 2 Type II: we manage the 6โ12 month observation period, ensuring controls operate consistently, evidence is collected automatically, and exceptions are documented and remediated promptly.
Auditor Liaison & Preparation
We prepare your team for auditor interviews, organise evidence packages, and manage auditor queries. We have worked with all major Nordic and international audit firms and know their specific expectations.
What You Receive
Gap Assessment Report
Detailed gap analysis against SOC 2 TSC or ISO 27001 Annex A with risk ratings and remediation roadmap.
Policy Library
Complete set of information security policies โ 25+ policies โ tailored to your organisation and audit-ready.
Control Implementation
Technical and procedural controls configured and evidenced: access reviews, change management, vulnerability management, and more.
Evidence Collection System
Automated evidence collection and management โ either via GRC platform or structured SharePoint/Drive โ ready for auditor access.
Auditor Liaison
We manage all auditor communications, prepare evidence packages, and attend fieldwork sessions alongside your team.
Attestation & Certificate
SOC 2 report or ISO 27001 certificate, plus an attestation letter suitable for sharing with customers and prospects.
Security Maturity Model
Compliance maturity reflects not just whether you hold a certificate, but how deeply security controls are embedded in your operations and how efficiently you maintain them.
Where you are
No formal compliance programme. Security policies either absent or outdated. No formal risk assessment process. Audit preparation done reactively when a customer demands it.
Where you are
Compliance effort underway โ often triggered by a customer requirement. Policies being written. Gap assessment commissioned. Controls being documented but not yet operationalised consistently.
Where you are
SOC 2 Type I or ISO 27001 Stage 1 audit passed. Controls documented and operating. Evidence collection established. Annual re-certification cycle managed. GRC platform in use.
Where you are
SOC 2 Type II or ISO 27001 with surveillance audits achieved. Continuous control monitoring. Compliance metrics reported to board. Controls integrated into engineering workflows via policy-as-code.
Where you are
Compliance is a business asset. Multiple frameworks maintained simultaneously (SOC 2 + ISO + PCI + HIPAA). Automated evidence collection covers 90%+ of controls. Compliance data feeds product trust pages and sales enablement.
ACE MATES assessment โ Not sure where you sit? Our free 90-minute threat briefing includes a maturity assessment across all security domains.
How We've Helped
The client needed SOC 2 Type II to close an enterprise deal with a US Fortune 500 customer. They had 20 weeks and no existing compliance programme.
ACE MATES completed the gap assessment in 2 weeks, designed and implemented 47 controls, established automated evidence collection via Vanta, and managed the 12-week observation period. The client passed their first SOC 2 Type II audit and closed the โฌ2.4M enterprise deal within the deadline.
Transparent Pricing
We publish indicative pricing because you deserve to know the ballpark before a single call.
- Gap assessment
- Policy library (25+ policies)
- Control design & implementation
- Evidence collection setup
- Auditor selection support
- Audit preparation & liaison
- Type I report coordination
- Everything in Type I
- 12-month observation management
- Automated evidence collection
- GRC platform setup (Vanta/Drata)
- Unlimited auditor liaison
- Exception management
- Type II report coordination
- Customer-facing security page
- ISMS scope definition
- Risk assessment & treatment plan
- Annex A control implementation
- Stage 1 & 2 audit coordination
- Policy & procedure library
- Internal audit programme
- Certificate achievement support
Why ACE MATES
98% First-Attempt Pass Rate
We have guided 120+ organisations through SOC 2 and ISO 27001 audits. Our 98% first-attempt pass rate is a function of control design quality and audit preparation rigour โ not luck.
Auditor Relationships
We work regularly with all major Nordic and international audit firms. We know their specific evidence expectations, their fieldwork processes, and how to resolve common sticking points before they become findings.
Controls That Actually Work
We don't write policies that sit on a SharePoint nobody reads. Every control we implement is operationally effective โ it actually improves your security posture alongside satisfying audit requirements.
Parallel Framework Efficiency
If you need both SOC 2 and ISO 27001, we run them in parallel โ sharing 70% of the work. Separate engagements with separate firms would cost you 2x the time and 1.8x the money.