Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTTalk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

Technology and service companies

Your customer asked for SOC 2. And no, nobody issues that in thirty days.

SOC 2 is not a badge you buy: it is a report on how your controls operated over a period. DM11 prepares your company to reach the audit with controls working and evidence ready, without discovering gaps once the auditor is already inside.

Scope my proposalTake the self-assessment

DM11 prepares your company. The SOC 2 report is issued by an independent CPA firm you contract directly, and whoever implements the controls is barred by independence from auditing the same client.

Who runs the preparation

  • 17 years in governance, risk and compliance
  • In-house checklist mapping 288 controls
  • Data protection and privacy specialists
  • Experience with bank and Big Four audits

Start with what almost everyone gets wrong

SOC 2 is not a certification

There is no SOC 2 certificate, no seal and no certification body. What exists is an attestation report, issued under the standards of the American Institute of Certified Public Accountants by a licensed CPA firm. Anyone selling a certificate is describing something that does not exist, and usually gets the rest wrong too.

It is a report, and people read it

The output is a document with five sections, among them the system description written by your own company and the auditor's test results control by control. Your customer will read it, especially the part listing exceptions. It is not a one-page PDF with a logo.

A CPA firm issues it

Consultancies do not issue SOC 2 reports, and neither do we. The audit firm is contracted separately, by you. More than that: whoever implemented the controls is barred by independence from auditing the same client. Be wary of anyone offering both.

Type II is about a period

The report most often requested does not assess how your company looks today: it assesses how it operated over months. Which means preparation does not end when a control is implemented, but when it has produced consistent evidence across the whole observation period.

Without structured preparation

  • Contracts stalled in due diligence, waiting on a report that takes months
  • Controls rushed into place, with no evidence from the period the auditor will test
  • Scope guessed at, paying for categories the customer never asked for
  • Exceptions in the report nobody anticipated, surfacing in front of the customer
  • Late discovery that the audit firm's fee is a separate contract

With the house in order

  • Scope sized to what your customer actually requires
  • Evidence produced from the first day of the observation period
  • Findings caught by us, and fixed before the auditor arrives
  • A report that answers customers' security questionnaires on its own
  • The next cycle prepared, with no uncovered gap between reports

The first decision

Type I and Type II

This choice sets cost, timeline and what you can actually show a customer. It is also where the market's most expensive misconception circulates.

Type IA specific date

Design of controls

Assesses whether controls are suitably designed and implemented on a given date. It is a snapshot. It demonstrates seriousness quickly and often unblocks a contract while Type II is still under way. It says nothing about controls having worked over time, and experienced buyers know that.

Type IIAn observation period

Design and operation

Assesses whether controls were suitably designed and operated effectively over a period. This is the report most corporate customers require. The period is agreed between you and the auditor, and the market tends to treat three months as the floor, with six to twelve most accepted by demanding buyers.

It is often claimed that Type I is a prerequisite for Type II. It is not. Your company can go straight to Type II, and many do, saving time and an entire project. Doing Type I first is a commercial decision, for when a contract is waiting and you cannot sit out the observation period. Anyone presenting Type I as mandatory is selling you an extra stage.

Scope

Only one of the five categories is mandatory

This is the project's biggest lever on cost and timeline, and almost no page in the market mentions it. Security, the common criteria, is mandatory in any SOC 2. The other four are elective, depending on what your customer requires and what your service commits to contractually.

CategoryIncluded?When it makes sense
SecurityMandatoryThe common criteria, organised into nine groups running from the control environment to vendor management. It is the backbone of any SOC 2 report, and on its own already satisfies much of what customers ask for.
AvailabilityOptionalWhen you commit to availability contractually. Covers capacity, recovery and plan testing. In practice near-mandatory for anyone selling software as a service with a service level agreement.
ConfidentialityOptionalWhen you handle information the customer classifies as confidential and expects to see protected by agreement. Covers identification and disposal of that information.
Processing integrityOptionalWhen your service processes transactions or calculations on the customer's behalf and the output must be complete, accurate and authorised. Common in payments, payroll, billing and logistics.
PrivacyOptionalWhen you process personal data and the customer wants it covered. Note: it covers a subset of what privacy law requires, and does not replace a privacy programme.

Including a category nobody asked for is the most common way to inflate a SOC 2 project with no commercial gain. Before defining scope, it pays to ask your customer in writing which report they expect and with which categories.

The real timeline

From the decision to the report in hand

Nobody publishes the summed timeline, which is why so many promise impossible dates. The phases below run in sequence, and the sum is what matters when a contract is waiting.

  1. 01

    Diagnosis and scope definition

    Assessment against the criteria, definition of categories, systems and environments, and the choice between Type I and Type II. Ends with a plan and the scope in writing.

  2. 02

    Remediation

    The most variable phase, and the biggest schedule risk. It depends entirely on what already exists. A company with governance in place moves fast; one that never formalised anything has foundation work to do.

  3. 03

    Observation period

    Exists only in Type II, and it is calendar time that cannot be compressed. Controls have to operate and produce evidence across the whole period agreed with the auditor.

  4. 04

    Auditor fieldwork

    The CPA firm tests controls, examines evidence and conducts interviews. This is where the gap between the written process and the practised one appears.

  5. 05

    Report issuance

    Drafting, management's response to any exceptions, and issuance. The document comes out in English when the firm is American, which is usually the case.

We do not publish a standard timeline because it would be guesswork: remediation varies enormously between companies and the observation period is a scoping choice. What can be said with confidence is that a Type II does not come out in weeks, and that anyone promising that is describing something else. After the diagnosis, we can put dates on your case.

Who does what

The boundary, stated before you hire anyone

In this market people promise a certificate that does not exist and sell an audit that whoever implemented the controls cannot perform. We would rather be clear from the start about who signs what.

Your company
Writes the system description, a section of the report for which management takes formal responsibility, and signs management's assertion. You also contract the audit firm.
DM11
Prepares. Defines scope, runs the gap analysis against the criteria, implements controls, writes policies, builds the evidence regime, trains the team and runs the dry run before the audit. We do not issue reports and we are not an audit firm.
The CPA firm
Issues the report. Contracted by you, separately, and their fee is a contract apart from ours. By independence, they cannot have implemented the controls they will test.
Your customer
Defines what they need to receive: which report type, which categories and how often. Worth getting that in writing before sizing anything.

Self-assessment

How close your company is to sustaining an audit

Eighteen questions across the control categories the report examines. The full result appears on screen, with a score per category and what closes the most critical gaps. We do not ask for your email to show it.

Control environmentQuestion 1 of 18

Is there a code of conduct communicated, with evidence of acceptance by the team?

The report starts with the control environment, where the audit tests culture through documents.

How we run it

From scope definition to the issued report

Every phase ends with a deliverable. You know what you get before you start.

  1. 01

    Define the scope

    We translate your customer's requirement into report type, categories, systems and period. This decision moves cost and timeline most, and is the one most often rushed.

    You get

    • Written scope with categories and systems
    • Type I or Type II decision with rationale
    • Formal questions to send your customer
  2. 02

    Gap analysis against the criteria

    We assess your current position control by control, using the same checklist we use in audit work, showing real distance rather than an impression.

    You get

    • Diagnosis per control category
    • Prioritised gap report
    • Effort sizing per workstream
  3. 03

    Remediate

    We implement what is missing alongside your team: policies, access processes, change management, monitoring, incident response and vendor management.

    You get

    • Approved policies and procedures
    • Controls implemented and operating
    • Training for the areas involved
  4. 04

    Build the evidence regime

    In Type II the auditor tests the whole period, so evidence has to come out of the operation. We define what is produced, by whom and how often, before the period starts.

    You get

    • Evidence matrix per control
    • Routine with owners and frequency
    • Repository organised for the audit
  5. 05

    Write the system description

    We support drafting the section of the report that is your company's responsibility, including system boundaries, commitments made and the treatment of subservice organisations.

    You get

    • System description drafted
    • Boundaries and subservice organisations defined
    • Complementary controls expected from customers
  6. 06

    Dry run and support

    We simulate the audit with the auditor's rigour before they arrive, and support the CPA firm's fieldwork, including management's response if there are exceptions.

    You get

    • Readiness report with findings
    • Corrections made before the audit
    • Support during fieldwork

Stories

Four situations we have already solved

We anonymise our clients with the same confidentiality that will protect your company later. The names change, and the pattern of the problems repeats.

Software as a service

The contract that could not wait for the period

Situation
A corporate customer made signing conditional on a SOC 2, with a two month deadline. The company had nothing formalised, and the most requested report requires an observation period that did not fit the window.
What we did
We went to the customer with the company and proposed a two-step path: Type I on the achievable date, with a dated commitment to Type II after. In parallel, remediation began already producing evidence for the following period.
Outcome
The contract was signed on the Type I. The Type II observation period started with controls already operating, instead of starting from zero afterwards.
Fintech

Good technology and no trail

Situation
Engineering was mature: code review, separated environments, monitoring. But none of it left records that could sustain an audit test. Changes went to production with verbal approval in chat.
What we did
Rather than creating a new process, we adjusted what the team already used so the trail appeared by itself: approval recorded in the development tooling and access evidence extracted automatically.
Outcome
The team did not change its routine and the audit gained something to test. The internal argument about bureaucracy, which usually stalls these projects, never happened.
Data platform

Paid for a scope nobody asked for

Situation
The company bought a project covering all five categories, on the assumption that broader was better. The customer who prompted it wanted Security and Availability, and nothing beyond that.
What we did
We cut the scope to what was actually required, with written confirmation from the customer. The remaining categories were left as a future decision, for when concrete demand appeared.
Outcome
The project shrank substantially and the timeline came down with it. The company also started asking for requirements in writing before sizing any report.
Infrastructure provider

Found out about the exceptions in front of the customer

Situation
In the first cycle, with no dry run, the report came out with exceptions the company had not expected, including active accounts belonging to people who had left. The document went to the customer with those findings visible.
What we did
In the following cycle we added a dry run run with the same rigour as the auditor, months before fieldwork. The findings surfaced for us first, with time to fix them and to produce evidence of the fix.
Outcome
The next report came out without the earlier exceptions. The lesson that stuck was a different one: an exception is not a catastrophe, but discovering it alongside your customer is avoidable.

Scoping

Build the scope of your proposal

Twelve questions about what determines the size of a SOC 2 project. At the end you review your answers, correct anything you want, and receive a proposal built on that, without a meeting just to discover the basics.

ReportQuestion 1 of 12

Which report did your customer ask for?

If the request does not specify, it is worth confirming before pricing.

Frequently asked

What people ask before deciding

Answers anchored in AICPA standards. Where no official figure exists, we say so.

No. It is an attestation report issued under the standards of the American Institute of Certified Public Accountants. There is no certificate, no seal and no certification body. The distinction is not pedantry: those who treat SOC 2 as a certification usually get the timeline, the scope and who can issue the document wrong too. If you find someone offering a SOC 2 certificate, the rest of the proposal deserves scrutiny.

More questions? Talk to DM11

Start by sizing what your customer actually asked for

A thirty minute conversation is usually enough to settle report type, categories and an order of magnitude for effort. No obligation.

Talk to a specialistBuild the scope