Our Assurance Audit Process

Six phases, from readiness to final report. A SOC 2 Type I runs one to two months from kickoff; a Type II covers a six to twelve month observation window, with the final report issued within five to seven weeks of period end.

Typical Engagement Timelines

SOC 2 Type I  1 to 2 months

Point-in-time, often a first engagement

SOC 2 Type II  Final report within 5 to 7 weeks of period end

Most common ongoing engagement

SOC 1 Type II  Report within 6 to 8 weeks of period end

For financial reporting service providers

Timelines vary based on environment complexity, scope, and client readiness. Per-phase estimates are shown in each section below.

The Year at a Glance

How a First Time SOC 2 Engagement Unfolds

Readiness before the period opens, a lighter touch while your controls operate, and a concentrated fieldwork window as the period closes. Some companies take a Type I once remediation is done and open the Type II period after it; others go straight into the Type II. Exact dates are set during planning around your reporting calendar.

First time SOC 2 engagement timeline: readiness and remediation run 1 to 6 months before the period begins, with an optional Type I report issued once remediation is complete, the observation period runs typically 6 to 12 months, fieldwork is a concentrated 3 to 4 week window late in the period, the draft report arrives about 2 weeks after fieldwork, and the final report follows within 5 to 7 weeks of period end.

A Sage Approach to SOC Audits

We structure every SOC engagement, whether SOC 1 or SOC 2, to be collaborative and efficient. Each phase below is designed so you always know where things stand, what is next, and what is expected. No surprises, no wasted effort.

Readiness Assessment Optional

A readiness assessment helps if this is your first SOC audit, you've recently changed your environment, or you want a clearer picture of where you stand before the examination begins.

Typical duration: 4 to 8 weeks for the assessment; 1 to 6 months including remediation

  • Purpose of SOC 2 Readiness
    • Identify and document the services and systems to be included in the SOC 2 scope
    • Map your current controls to the applicable Trust Services Criteria (TSC)
    • Determine where gaps or weaknesses exist
    • Help your team prepare the system description and control listing needed for the audit
  • Typical Activities
    • Reviewing policies, procedures, and system documentation
    • Interviewing control owners to understand how your environment is managed
    • Assisting with alignment of controls to the selected TSC categories and points of focus
    • Highlighting control gaps, missing documentation, or areas needing improvement
    • Providing recommendations that help you prepare for the formal audit
  • Management Responsibilities
    • We may assist with drafting the system description but do not assume management responsibilities
    • We do not design or implement controls. Our role is strictly advisory to maintain independence
  • Timing and Deliverables
    • A typical readiness assessment lasts 4 to 8 weeks; with remediation, plan on 1 to 6 months before your audit period begins
    • Includes a control listing mapped to the TSC
    • Summary of reviewed documentation
    • Identification of any control or documentation gaps, delivered as a prioritized gap tracker and remediation roadmap

While optional, this phase can save significant time and effort during the actual audit and help you approach your SOC 2 journey with confidence.

Defining Scope

We meet with your team to understand your environment, clarify goals, and confirm readiness. This phase helps both sides assess fit, define expectations, and identify pre-engagement requirements needed to maintain independence.

Typical duration: 1 to 2 weeks

  • Initial Planning Session
    • Meet with management and stakeholders to discuss goals for SOC 2
    • Review the nature of services, infrastructure, and key systems
    • Identify primary control owners and supporting teams
    • Understand what's driving the need for a SOC Report (e.g., customer demands, growth, contracts)
  • Determine the Examination Type
    • Decide whether a Type I (point-in-time) or Type II (period-based) report is appropriate
    • Discuss timing, audit history, and whether this is a first-time examination
  • Select Applicable Trust Services Categories
    • Review the five Trust Services Categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy
    • Select those that align with your customer expectations and service delivery
  • Define System Boundaries
    • Identify the systems, infrastructure, data flows, and locations in scope
    • Note subservice organizations and any exclusions
    • Clarify what is considered out of scope
  • Set Timeline and Align Expectations
    • Outline key dates and engagement milestones
    • Walk through the full audit process to explain what to expect
    • Clarify pre-engagement documentation needs, roles, and communication preferences

This step lays the groundwork for testing and helps ensure the audit proceeds efficiently and accurately.

Evidence Gathering & System Definition

Your organization submits a draft control listing, system description, and scope details. We review these and provide a tailored evidence request list specific to your environment.

Typical duration: 2 to 4 weeks

  • Evidence Submission
    • Upload files directly to Artifact, our secure client portal, for a streamlined process (see below)
    • Receive a customized list of requested items based on your control set and system design
  • Evidence Quality Guidance
    • Learn what constitutes strong evidence
    • Understand completeness and accuracy requirements
    • Receive tips for preparing screenshots, exports, and other artifacts
  • System Description Collaboration
    • Refine Section 3 of your report (the System Description)
    • Clarify how your services, systems, and controls work together
    • Ensure a near-final draft is ready by the end of this phase

This step lays the groundwork for testing and helps ensure the audit proceeds efficiently and accurately.

See how our audit platform makes evidence collection easier →

Artifact · Our Client Portal

Evidence Collection Without the Chaos

One place to see every request, upload every document, and track the audit from kickoff to acceptance. It is the same system we plan and run your audit in.

Answers stay attached
Questions and answers live on the request itself instead of vanishing into inboxes.
Year two starts warm
Returning clients roll forward last year's list instead of starting from zero.

Testing and Validation

The core phase. We independently test your controls to determine whether they are designed effectively and, for Type II reports, whether they operated effectively throughout the audit period.

Typical duration: concentrated 3 to 4 week window (Type II) · 2 to 3 weeks (Type I)

  • Control Effectiveness Testing
    • Review submitted evidence and test whether controls meet the Trust Services Criteria
    • Evaluate control design and operational effectiveness over time (for Type II reports)
  • Sampling and Validation
    • Select samples from relevant populations to assess completeness, accuracy, and consistency
    • Use testing procedures aligned with the AICPA standards
  • Ongoing Communication
    • Conduct follow-up calls and status meetings as needed
    • Address questions or gaps through ongoing dialogue with your team
  • Exception Handling
    • Discuss any findings or issues before finalizing results
    • Collaborate on clarification or remediating documentation if needed

This phase results in a complete set of validated test results that support our final assurance opinion.

QA Review and Draft Report Preparation

We perform a thorough QA review of all testing and documentation to ensure everything meets professional standards before preparing the draft report. We target a draft report within two weeks of completing fieldwork.

Typical duration: approximately 2 weeks

  • Internal QA Review
    • Audit team conducts a detailed review of all testing procedures and supporting evidence
    • Confirm that testing aligns with the selected Trust Services Criteria and audit scope
  • Draft Report Preparation
    • Prepare a complete draft report for internal and client review
    • Ensure descriptions and results accurately reflect the engagement and testing outcomes
  • Client Review and Feedback
    • Share draft with management for review and comments
    • Discuss any revisions needed to the system description or control language

Final Report Delivery

Once management approves the draft and open items are resolved, we finalize the report. The finished document is issued as a secured PDF, ready to share with customers, prospects, and their auditors, typically under NDA.

Typical duration: 1 to 2 weeks after management approval

  • Final Report Contents
    • Our auditor opinion letter on the design and effectiveness of your controls
    • The management assertion describing the system and controls
    • The finalized system description (Section 3)
    • A detailed list of the controls tested and our independent results of that testing
  • Distribution and Use
    • The final report is a restricted-use document: it can be shared with User Entities, your customers, and their auditors, typically under NDA
AICPA SOC for Service Organizations seal

Common Questions

Frequently Asked Questions

A SOC 1 Report addresses controls relevant to clients' financial reporting. A SOC 2 Report assesses security, availability, processing integrity, confidentiality, and privacy under the AICPA Trust Services Criteria. The right report depends on the type of services you provide and what your customers require.

A Type I report evaluates whether your controls are suitably designed at a specific point in time. A Type II report assesses both design and operating effectiveness over a period, typically 6 to 12 months. Enterprise customers generally require a Type II report.

A SOC 2 Type I typically takes one to two months from kickoff to report issuance. A SOC 2 Type II depends on your examination period (6 to 12 months), with a draft report within two weeks of fieldwork completion and the final report within five to seven weeks of period end. Including an optional readiness assessment adds 4 to 8 weeks, or 1 to 6 months with remediation. SOC 1 timelines are similar. The duration depends on environment complexity, how quickly evidence can be gathered, and client readiness.

We start with a planning session to understand your environment before generating evidence requests. Once scope is defined, we provide a customized evidence list specific to your control set. Typical starting documents include your information security policy, risk assessment, and vendor management inventory.

A bridge letter is a management representation that covers the gap between your audit period end date and the date a customer needs to see current coverage. This is common when renewing annually and a customer needs assurance before your next report is issued. We assist clients with bridge letters as part of ongoing engagements.

We raise potential gaps with your team directly before finalizing any results. Most issues surface during the readiness phase or early fieldwork, giving time to remediate. We do not design or implement controls, but we clearly explain what we found and what evidence or documentation would address it.

Yes. We accept evidence in any format, including exports, screenshots, and reports from GRC platforms. We evaluate that evidence independently rather than accepting a platform's assertion of compliance. Using a GRC tool does not change our testing procedures.

Partner-level involvement throughout the engagement is how we operate. You work directly with a partner from scoping through report delivery. You are not handed off to junior staff after kickoff. The same partner who plans the engagement reviews the testing and signs the final report.

Jordan Novak, Managing Partner

Behind Sage Audits

I'm Jordan Novak, Managing Partner at Sage Audits LLP, with a background in Big Four public accounting and internal IT audit leadership. As independent auditors, we provide objective opinions on control design and operating effectiveness, with clear reporting, open communication, and a collaborative approach aligned to your business.

Learn more about our firm

Transparent Pricing

Get Your 
Custom Quote

Our pricing is structured and fixed-fee. What drives it is the complexity of your environment, the key vendors that support your system, and the commitments you have made to customers, along with how you want those aligned to the Trust Services Categories you put in scope. Share a few details about your situation and we will follow up personally, usually with a quick call, to walk through scope and get you a clear fixed quote you can plan around.