“A major customer just asked for our SOC 2.”

SOC 2, ISO 27001 & HIPAA from Zero

Most companies meet this problem cold: a major customer or prospect suddenly requires SOC 2, ISO 27001, or HIPAA, nobody in-house has done it before, and the clock is contractual. I have been through that full cycle, starting from zero.

What I've done

  • Built a security and compliance program from zero formal controls to audit-ready in under one year, within budget, without adding headcount.
  • Zero major nonconformities across six annual audit cycles spanning ISO 27001, SOC 2 Type 2, and HIPAA.
  • That capability now supports roughly 68% of the company’s revenue.
  • Consolidated audit windows and evidence collection across frameworks to minimize cost and disruption.

Working through something similar? I'm glad to compare notes. Get in touch