Skip to content
kubepath Book a call
Menu

SOC 2 and ISO 27001 without the template pile.

We implement the controls that matter, make sure the evidence proves them, and sit beside you when the auditor asks questions.

Who it's for

  • US enterprise deals are waiting on SOC 2
  • European buyers ask for ISO 27001
  • You bought a compliance platform and nobody has time to work through it
  • Your audit is booked and you are not sure you will pass

What's covered

Scope

Define the system boundary and the criteria you need, kept as small as your customers allow.

Gap assessment

Policies vs systems vs evidence. Real control gaps separated from paperwork gaps.

Technical controls

Access reviews, MFA, change management, logging, encryption, backups, vulnerability scanning.

Policies

Short, accurate policies that match how your team actually works.

Evidence

Organised per control so the auditor is not chasing you.

Audit support

We answer requests with you, join the calls and close findings.

What you get

TimelineTypically 4 to 10 weeks depending on where you start.
PriceGap assessment from USD 2,500. Readiness from USD 9,000.
  • Gap report with the short list to fix before the audit
  • Controls implemented in your cloud, GitHub and CI/CD
  • Policy set, control matrix and evidence folder
  • Support through to the auditor's report or certificate

Not included

  • The SOC 2 report itself (issued only by a licensed CPA firm)
  • The ISO 27001 certificate (issued only by an accredited certification body)