InfoSec Consulting
Security judgment, on retainer.
Read the scopeRetained advisory
We prepare organizations for SOC 2 Type II and ISO 27001 by making the controls real first and the evidence automatic second.
Service
Compliance & Audit Readiness
Engagement
Retained advisory
To audit-ready
3 – 6 months
The problem
The fastest route to an audit is a template policy set nobody follows. It survives the readiness review and fails the audit, because Type II tests whether the control operated over a period, not whether it was written down. The slower route is the only one that holds: make the control real first, then collect the evidence automatically.
Scope
Anything outside this list is quoted separately rather than absorbed quietly.
Deliverables
Every item here is an artifact you own, in your systems, readable by someone who was not in the room.
Every framework requirement mapped to the control that satisfies it, the system that enforces it and the evidence that proves it.
Written to describe what your organization does. If a policy and the practice disagree, we change one of them deliberately.
Automated collection wherever the platform allows it, so the observation window takes care of itself.
An honest verdict on whether you would pass today, and what stands between you and that.
To audit-ready: 3 – 6 months
SOC 2 Type II additionally requires an observation window, typically 3 – 12 months, which runs after readiness.
Fit
We would rather lose the engagement at this paragraph than three weeks in.
A good fit if
Not a fit if
Questions
No. Fincham Systems LLC holds no compliance certifications, and you should be skeptical of consultancies that imply otherwise. What we provide is the engineering and advisory work that gets your organization ready for its audit. The audit itself is performed by an independent licensed firm.
Yes. Those platforms are good at collecting evidence and poor at making a control real in the first place. We handle the engineering they assume you have already done.
Readiness typically takes 3 – 6 months depending on your starting point. SOC 2 Type II then requires an observation window, commonly 3 – 12 months, before the auditor can issue. Anyone promising a Type II report in 30 days is describing a Type I.
Often paired with
These are the combinations that come up most often, not an upsell list.
Security judgment, on retainer.
Read the scopeClose the gaps, and prove they are closed.
Read the scopeDeployments that are boring on purpose.
Read the scopeCompliance & Audit Readiness
Tell us what the environment looks like today. We will tell you what we would change first, and whether this is the right engagement for it.