Control and Function

SOC 2 Readiness · Fractional IT Leadership

Audit-ready in 12 to 16 weeks.

We don't sell platforms. We earn audits.

A Denver-based readiness practice for SaaS companies, 50 to 300 employees. Lean engagements. Fixed scope. Fixed price.

SOC 2
Type I and Type II readiness
HIPAA
For HealthTech SaaS
ISO 27001
Dual-framework engagements
Fractional CISO
Embedded delivery
Lean engagements · Platform-neutral · Fixed scope, fixed price · Audit firm referral partners · No outside MSP required

About the practice

Built around solo SOC 2 experience. Applied to your audit.

How we engage

  • 01 Lean engagements. No junior associates padding the bill.
  • 02 Platform-neutral. We do not earn referral fees from compliance vendors.
  • 03 Modern tooling and AI workflows in our own delivery.
  • 04 Audit firm referral relationships included for the attestation itself.

Control and Function is a Denver-based readiness and fractional IT leadership practice. We work with SaaS companies between 50 and 300 employees who are preparing for their first SOC 2 audit, a Type II renewal, or expanding into HIPAA, ISO 27001, or fractional CISO support.

Our positioning is operational, not advisory. We have run a SOC 2 Type II program end to end with no outside MSP and no compliance platform. That experience shapes every engagement we take. We know what an auditor will care about, what they will not, and where most companies waste cycles.

We are platform-neutral by design. Vanta, Drata, Secureframe, or no platform at all is the customer's call. We use AI and modern automation in our own delivery so engagements stay lean, scopes stay fixed, and the timeline holds.

Services

Four ways to engage

Pick the depth that fits your team and budget. All engagements are remote, fixed-scope, and platform-neutral.

Coaching

SOC 2 Readiness Coaching

From $8K

4 to 8 weeks · for early-stage SaaS

Your team drives the program. We provide office hours, document review, control implementation guidance, and auditor liaison support. Best when the founders want to own the work.

Most Popular

Full SOC 2 Readiness

From $15K

12 to 16 weeks · for Series A and Series B SaaS

We drive the program end to end. Policies, controls, evidence collection, vendor reviews, pre-audit walkthrough. Your team approves and executes. Audit firm referral included.

Embedded

Hands-On Implementation

From $25K

16 to 24 weeks · fractional CISO

Embedded delivery. We implement controls in your environment alongside your engineers, drive incident response runbooks, and stand up access management discipline. Pairs with SOC 2 readiness or runs standalone.

Retainer

Ongoing Compliance

$2 to $5K / mo

Rolling · post-audit maintenance

Keep your program ready for renewal. Change control reviews, vendor SOC 2 collection, evidence refresh, monthly security check-ins. Your team handles execution. We handle the discipline that fades after the first audit.

Engagement Timeline

What 12 to 16 weeks actually looks like.

Full SOC 2 Readiness engagements run on a four-phase cadence. Each phase has explicit deliverables and an end-of-phase checkpoint. No floating timeline, no scope creep.

01

Weeks 1 to 3

Discovery and scoping

  • · Trust Services Criteria scoping
  • · System boundary definition
  • · Existing-controls inventory
  • · Audit firm selection support
02

Weeks 4 to 7

Controls designed and built

  • · Policy and procedure drafts
  • · Identity and access framework
  • · Vendor risk management
  • · Incident response runbook
03

Weeks 8 to 12

Evidence collected and tested

  • · Control operation evidence
  • · Sample population review
  • · Gap remediation
  • · Internal walkthrough rehearsal
04

Weeks 13 to 16

Auditor handoff

  • · Pre-audit walkthrough
  • · Auditor question response
  • · Final evidence package
  • · Clean attestation

"Audit dates are deadlines, not aspirations. We treat them that way."

Why Control and Function

Most readiness firms write policies. We deliver audits.

01

Operational, not advisory

Our practice was built on running a SOC 2 Type II program end to end with no outside MSP and no compliance platform. We know what an auditor will press on, what they will not, and where most companies waste cycles.

02

IT, security, and compliance under one roof

Most readiness firms are pure GRC writers who cannot configure SSO or speak to engineers in their own language. We can. That means faster engagements, fewer escalations, and a delivery cadence engineering teams actually respect.

03

Dual-framework engagements

SaaS companies serving regulated buyers usually need SOC 2 plus another framework. We run dual-framework engagements (SOC 2 + HIPAA, SOC 2 + ISO 27001) without bringing in a second firm.

04

Platform-neutral by design

Vanta, Drata, Secureframe, or no platform at all. We do not earn referral fees from compliance platform vendors. Our recommendation is based on your situation, not our economics.

05

Audit firm referral relationships

We work alongside trusted CPA audit firms. Once you are ready, we hand you off cleanly for the attestation. We never perform the audit ourselves. That separation is by design.

06

AI-native delivery

We use AI workflows and modern automation in our own delivery. If you want AI integrated into your compliance program, we already operate that way ourselves.

Contact

Start the conversation.

A 30-minute discovery call costs nothing and clarifies whether SOC 2 readiness is the right next move for your company. No sales pressure. If we are not the right fit, we will say so and refer you to someone who is.

Denver, Colorado · Available for engagements across the United States