PROTECT · Compliance · SOC 2 Type I / Type II

Enterprise buyers demand SOC 2. We deliver the posture that closes deals.

Media Express prepares Chicago-area B2B SaaS, IT/MSPs, cloud providers, and service vendors for SOC 2 Type I or Type II. Trust Services Criteria alignment, trust posture pages, sub-processor disclosures, security policies, and coordinated referral to AICPA-licensed CPA auditors.

⚜ Plain English · Quotable
SOC 2 (Service Organization Control 2) is the de facto trust standard for B2B SaaS and service providers selling to enterprise. Developed by AICPA and audited by licensed CPA firms, a SOC 2 report tells enterprise procurement teams that your controls meet the Trust Services Criteria — Security (mandatory), plus optionally Availability, Processing Integrity, Confidentiality, and Privacy. Media Express prepares Chicago-area service organizations for Type I or Type II reports, so you don't get stuck answering 400-question vendor security questionnaires one prospect at a time.
🔒 Who This Applies To

If you sell to enterprise or regulated buyers — you need SOC 2.

SOC 2 is not government-mandated. It's mandated by the market. Enterprise procurement teams add SOC 2 to their vendor questionnaires almost universally. Without it, you either get disqualified or spend endless hours answering security questions.

Rule of thumb: if your enterprise prospect's security team is involved in the sale, SOC 2 accelerates the deal by months.

🔒 Trust Services Criteria

Five criteria. Pick your scope.

SOC 2 reports cover one or more of five Trust Services Criteria (TSC). Security is mandatory in every SOC 2 report. The other four are optional based on your business and buyer needs.

Mandatory
Security

The common criteria — protection of your systems against unauthorized access, disclosure, and damage. Every SOC 2 covers this.

Optional
Availability

Your systems are available for operation and use as committed or agreed. Includes uptime SLAs, DR, incident handling.

Optional
Processing Integrity

Your system processing is complete, valid, accurate, timely, and authorized. Especially relevant for financial/transactional platforms.

Optional
Confidentiality

Information designated as confidential is protected as committed or agreed. Add this if you handle customer data marked confidential.

Optional
Privacy

Personal information is collected, used, retained, disclosed, and disposed of in conformity with the entity's privacy notice. Add if you handle personal data at scale.

🔒 Report Types

Type I or Type II. Which do you need first?

Type I is a point-in-time snapshot. Type II observes operation of your controls over 6-12 months. Most enterprise buyers ultimately want Type II. Many organizations start with Type I and evolve to Type II within a year.

Report Type
SOC 2 Type I
Point in time · Fastest to obtain
  • Reports on your controls at a specific date
  • Auditor confirms controls are designed effectively
  • Fastest path to a report you can hand a buyer
  • 2-3 months after readiness completion
  • Lower auditor fee
  • Common starting point — graduate to Type II in year 2
⚠️ If You Ignore It

The cost of doing nothing.

SOC 2 isn't legally required. Ignoring it isn't illegal. But it is a business decision to accept slower sales cycles, longer procurement reviews, and lost enterprise deals to competitors who have SOC 2.

⚠️ Real Consequences

Service organizations without SOC 2 face measurable revenue loss in the enterprise segment.

  • Enterprise procurement teams disqualify you at the security-review stage — no SOC 2, no purchase
  • You spend hours answering 300-400 question vendor security questionnaires per prospect
  • Sales cycles stretch from weeks to months waiting on ad-hoc security reviews
  • Competitors with SOC 2 win the deal while you're still filling out questionnaires
  • Insurance underwriters demand higher cyber liability premiums for uncertified vendors
  • Existing enterprise clients threaten non-renewal if you don't add SOC 2
  • Higher-tier account executives can't take you to their top 100 prospects
  • Investors and board question whether you're ready for the enterprise market
⚜ How We Help

The 5-step SOC 2 readiness path.

A structured, phased approach with clear deliverables and fixed pricing. You always know what's next, what it costs, and when it's done.

1
Free Readiness Assessment (15 min)

Take our 15-question quiz. Get an instant PDF report with your SOC 2 readiness score, applicable TSC, and top-priority gaps. This tells us whether Type I or Type II is realistic first and which criteria to include.

2
Scope + Gap Analysis (3-4 weeks)

Fixed-price engagement. We define your report scope (which TSC), map current state against the criteria, identify every gap, and produce a phased roadmap with timelines and costs. Includes OPSEC website audit and trust posture assessment.

3
Documentation + Trust Posture Page (8-12 weeks)

Security policies (16-20 policies covering access control, incident response, change management, vendor management, etc.). Trust posture page on your website. Sub-processor and sub-service organization disclosures. All the artifacts an auditor will look for — ready.

4
Technical Remediation (parallel)

Whatever technical gaps exist — MFA, encryption, audit logging, backup testing, endpoint controls, vulnerability scanning, incident response tabletops. We coordinate the work and verify each control is designed and operating before your audit window.

5
Auditor Referral + Coordination

We introduce you to an AICPA-licensed CPA firm partner. You engage them directly for the formal audit (Media Express does not perform SOC 2 audits — that's a strict AICPA licensing boundary). We stay involved to answer auditor questions and manage the paper trail.

💰 What It Costs

Fixed pricing at every phase. No open-ended consulting.

Trust Posture Package for teams not quite ready for a full audit. Type I Readiness Package for teams that need a report fast. Managed retainer for teams evolving from Type I to Type II.

Foundation
Trust Posture Package
$6,000 – $15,000
One-time, delivered in 6-8 weeks
  • Trust posture page on your website
  • Basic security policies (6-8 policies)
  • Sub-processor disclosure page
  • Privacy notice + terms alignment
  • Capability Statement (SaaS-adapted)
  • Enterprise-ready vendor questionnaire responses
Type II Evolution
Managed Retainer
$2,000 – $8,000/mo
Recurring, month-to-month
  • Ongoing control operation monitoring
  • Evidence collection through observation window
  • Quarterly compliance review calls
  • Policy updates as criteria change
  • Website + trust posture maintenance
  • Employee training refresh
  • Type II audit prep + coordination
  • Compliance-ready hosting included

Type II auditor fees typically $50-150k due to 6-12 month observation window and expanded testing. Actual pricing depends on company size, TSC scope, and existing security posture.

Above are typical Illinois market rates. Media Express pricing is more accessible — we build once and reuse across clients, so you don't pay for someone else's discovery work. Contact us for a personalized quote based on your exact situation.

⚜ Free Consultation →
❓ Common Questions

FAQ.

Type I vs Type II — which do I need?

Type I: point-in-time snapshot. Faster (2-3 months after readiness), cheaper. Type II: 6-12 month observation of your controls in operation. Higher trust, higher cost, longer timeline. Most enterprise buyers want Type II. Start with Type I if you need something to hand a buyer next month; plan for Type II as the eventual goal.

How long does SOC 2 readiness take?

Type I: 3-6 months from scratch. Type II: adds 6-12 month observation window on top. Total cold-start to Type II report: 12-18 months. If you already have solid security operations, Type I readiness in as little as 6-8 weeks.

How much does SOC 2 cost?

Trust Posture Package: $6-15k. Type I Readiness: $20-60k + $30-80k audit fee. Type II: $30-80k + $50-150k audit fee. Managed retainer: $2-8k/mo.

Does Media Express perform the SOC 2 audit?

No. Only AICPA-licensed CPA firms can perform SOC 2 audits. This is a strict AICPA licensing boundary. Media Express prepares you for the audit — trust posture page, policies, sub-processor disclosure, gap remediation — and coordinates the referral to CPA audit partners when you're ready.

Which Trust Services Criteria do I need?

Security is mandatory. Most B2B SaaS start with Security + Availability. Add Confidentiality if you handle customer data marked confidential. Add Privacy if you process personal data at scale. Processing Integrity is niche — usually only for financial/transactional platforms.

Do I actually need SOC 2 to sell to enterprise?

Increasingly, yes. Enterprise procurement teams add SOC 2 to vendor security questionnaires universally. Without it, you get disqualified or spend hours answering questions per prospect. SOC 2 satisfies most enterprise buyer due diligence in one document — dramatically shortening your sales cycle.

Can I share our SOC 2 report publicly?

Typically no. SOC 2 reports are confidential and shared under NDA with actual and prospective customers. What you CAN do publicly: mention that you have SOC 2 Type I or Type II, mention your report period, mention which TSC are covered. We build the trust posture page around what you're allowed to publish.

📚 Related Terms

Also worth understanding.

SOC 2 pairs with several other frameworks. If you want to go deeper on any of them, our wiki covers each in plain English.

Ready to close enterprise deals faster?

Take the free 15-question Compliance Readiness Assessment. Instant PDF report with your SOC 2 status, recommended TSC scope, and top-priority actions.

Media Express LLC · Chicago IL · Est. 1995 · Independent · 31+ years
Media Express LLC prepares service organizations for SOC 2 Type I and Type II reports. Media Express does not perform SOC 2 audits — SOC 2 examinations are conducted exclusively by AICPA-licensed CPA firms. Media Express provides referral to independent CPA audit partners. AICPA and SOC are registered trademarks of the American Institute of Certified Public Accountants.