← All courses
$20

SOC 2 Readiness

Run your own SOC 2 readiness and walk into the audit prepared. Understand what SOC 2 really is, scope it, implement the common controls, collect evidence that holds across the window, close your gaps, and pass the audit — then keep it. For founders, security/compliance leads, and engineers at B2B software companies.

"We're scoped to Security + Availability, we've mapped our controls, and here's our gap-closed readiness plan for a Type II audit"

6 Interactive Sessions

Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.

  1. 1

    What SOC 2 actually is — and what it isn't

    SOC 2 is an independent auditor's report on your controls against the Trust Services Criteria — not a certificate you earn once.

  2. 2

    Scope your SOC 2 — draw the boundary that makes the report worth reading

    Scope covers the system that delivers your service to customers — wide enough to be credible, tight enough to be finishable.

  3. 3

    The controls — where to actually start

    SOC 2 controls aren't hundreds of bespoke items — they're a common baseline that clusters into a handful of families, and a policy only counts once a real control performs it.

  4. 4

    Evidence — what auditors actually want

    Evidence is proof a control actually operated — and for a Type II it has to hold up across the whole audit window, not just one screenshot the night before.

  5. 5

    The gap assessment — find your gaps before the auditor does

    A gap assessment is a self-audit against the criteria before the real audit — you rate each control (in place / partial / missing) and turn the shortfalls into a prioritized remediation roadmap.

  6. 6

    The audit & staying compliant

    SOC 2 is a program, not a project: you pass the audit for a stated window, then keep the controls operating so you pass again next year.

Production patterns you'll master

Trust Services CriteriaType I vs Type IIControl MappingEvidence CollectionGap AssessmentContinuous Compliance

Synthetic data included

  • Trust Services Criteria (5)
  • Control baseline by family
  • Evidence examples (weak vs strong)
  • Gap self-assessment checklist (20 controls)

What you walk away with

Shareable portfolio

A public URL showing your module timeline, patterns mastered, and completion status.

All the code

Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.

Module walkthrough

Each module documented with deliverables and the production pattern you implemented.

Ready to build your soc 2 readiness?

First course free. $20 per course after that.