How GetComply works

A practical SOC 2 process for teams that need help running the work, not just tracking it.

The model

A shared workspace with a real advisor in it

The shared workspace keeps the messy parts in one place: scope, controls, evidence, risks, blockers, and next steps. Your advisor works there with your team, so SOC 2 does not live across Slack threads, spreadsheets, email, and someone's memory.

Your advisor stays involved, the workspace keeps the work visible, and the process keeps moving.

01

Set the scope

We map out which systems, services, vendors, and people are in scope. We ask about your sales pressure or audit timeline so we can sequence the work accordingly. This avoids collecting evidence for things that do not matter.

You leave with

Defined scope, workspace set up, baseline documented
02

Find the gaps

Your advisor reviews what controls, policies, and evidence already exist. We flag what is missing, what is weak, and what can be reused. Then we prioritize based on what the auditor will actually focus on.

You leave with

Gap review findings and a prioritized plan
03

Work the next steps

Instead of dumping a 50-item task list on your team, we assign focused work each week. Every week, you see what changed, what is blocked, and what needs attention before it becomes a blocker. Your advisor keeps an eye on the overall state so you do not have to.

You leave with

Weekly updates and tracked next steps
04

Review the evidence

We check evidence before it goes to the CPA firm. If a screenshot is missing the date, system name, user scope, or proof that the control actually ran, we explain what is missing and why it matters. A file upload is not the finish line.

You leave with

Reviewed evidence, ready for the CPA firm
05

Prepare the CPA package

When the work is in good shape, we organize the evidence, controls, risks, and context into a package the CPA firm can navigate. We do not perform the audit. We make sure the auditor is not starting from scratch.

You leave with

Organized evidence and context for the CPA firm
06

Keep it from drifting

After the first SOC 2 push, controls still have to run. Teams change. Vendors get added. Policies go stale. Access reviews get missed. Ongoing GRC Support keeps the governance work on track through regular check-ins, reviews, and reminders.

You leave with

Ongoing governance on a schedule, not an afterthought

The shared workspace

What active SOC 2 work looks like

Your team and advisor use the same workspace. Tasks, evidence, controls, risks, and blockers are visible to everyone involved. Nothing lives in a separate spreadsheet or email thread.

GetComply
|
Alex S.

Next Actions

8

2 in progress

Controls

47/63

12 in progress

Blockers

1

high priority

Evidence Items

38

4 pending review

Blocker: Vendor Access Review Overdue

Last completed 47 days ago. Required quarterly. Overdue by 17 days.

Readiness by Trust Criteria

Security (CC)82%
Availability (A)68%
Confidentiality (C)74%

Recent Activity

CC6.1 logical access control policy — evidence reviewed and approved2h ago
Next action assigned: complete vendor access review (due Mar 20)Yesterday
Blocker flagged: vendor access review cadence overdue2 days ago
Weekly readiness brief delivered — 3 next actions, 1 blockerMar 1

Sample program data. All company details and figures are illustrative.

Who does what

A shared model with clear responsibility

Your team

  • Confirm internal facts and ownership
  • Provide access to systems, information, and evidence
  • Approve policy and process decisions
  • Make the internal changes only your team can make
  • Show up for key review checkpoints

GetComply

  • Keep the work moving week to week
  • Maintain the shared workspace
  • Flag blockers before they stall the work
  • Review evidence before it goes to the CPA firm
  • Draft policies and refine materials
  • Organize the CPA package when the work is ready
  • Keep SOC 2 from becoming a full-time side job for your CTO

Want to see how this would work for your team?

Schedule an intro call. We'll look at where you are, what is creating pressure, and what a reasonable starting point looks like.