Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

Comparisons

  • ISO 42001 vs EU AI Act
  • GDPR vs LGPD
  • TISAX vs ISO 27001
  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • ISO 42001 vs NIST AI RMF
  • BCP vs DRP
  • Pentest vs Vulnerability Assessment
  • CIS Controls vs ISO 27001
  • CSA STAR vs ISO 27001
  • SOC 2 Type 1 vs Type 2
  • NIS2 vs ISO 27001
  • ISO 27701 vs LGPD

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

Technology and service companies

The SOC 2 certification that unlocks your enterprise contracts

Your largest customers ask for SOC 2, an independent report on how secure your systems are, before they sign. DM11 gets your company ready to reach the audit with controls working and proof on hand, and to walk away with the report that closes the deal.

Scope my proposalTake the self-assessment

DM11 prepares your company. The SOC 2 report is issued by an independent CPA firm (a licensed public accountant in the United States) that you hire directly. A rule of independence stops whoever builds the controls from auditing the same client.

Who runs the preparation

  • 17 years in governance, risk and compliance
  • In-house checklist mapping 288 controls
  • Data protection and privacy specialists
  • Experience with bank and Big Four audits

How it actually works

What you get when you “certify” your company under SOC 2

You get a document that answers your customers' security questions on its own: a report with your controls tested one by one by an independent auditor. The market calls it a certification and we understand the request, but the technical name is different, and it explains the format. It is an attestation report, issued under the standards of the American Institute of Certified Public Accountants (the accountants' body in the United States, the AICPA) by a licensed CPA firm. Knowing that changes what you hire, from whom, and what you can expect to receive at the end.

It is a report, and people read it

The result is a document with five sections. Among them are the system description, written by your company, and the auditor's test results, control by control. Your customer will read it, especially the part that shows the problems found. It is not a one-page PDF with a logo.

A CPA firm signs it

A consultancy does not sign SOC 2 reports, and neither do we. The audit firm is hired separately, by you. The AICPA rule of independence explains why: whoever built the controls cannot audit the same client. In practice that means two contracts and two budgets, and it is better to know while planning than to find out midway.

Type II looks at a period

The report most often requested does not assess how your company looks today: it assesses how it worked over months. Which means preparation does not end when a control is built, but when it has produced consistent proof across the whole period observed.

Without organised preparation

  • Contracts stuck in the customer's review, waiting on a report that takes months
  • Controls built in a rush, with no proof from the period the auditor will test
  • Scope guessed at, paying for categories the customer never asked for
  • Problems in the report nobody saw coming, showing up in front of the customer
  • Finding out late that the audit firm's fee is a separate contract

With the house in order

  • Scope sized to what your customer actually needs
  • Proof being produced from the first day of the period observed
  • Problems caught by us, and fixed before the auditor arrives
  • A report that answers customers' security questionnaires on its own
  • The next cycle already prepared, with no uncovered gap between reports

The first decision

Type I and Type II

This choice sets cost, timeline and what you can actually show a customer. It is also where the market's most expensive misunderstanding circulates.

Type IA specific date

How the controls are designed

Checks whether the controls are well designed and in place on a given date. It is a snapshot. It shows you are serious quickly and often unblocks a contract while Type II is still under way. It says nothing about the controls having worked over time, and experienced buyers know that.

Type IIAn observation period

How they were designed and how they worked

Checks whether the controls were well designed and whether they actually worked over a period. It is the report most large customers require. The period is agreed between you and the auditor, and the market tends to treat three months as the minimum, with six to twelve months most accepted by demanding buyers.

The idea gets around that Type I is a prerequisite for Type II. It is not. Your company can go straight to Type II, and many do, to save time and a whole project. Doing Type I first is a commercial decision, and a good one: when a contract is waiting and you cannot sit out the observation period, it unlocks the signature.

Scope

One category is mandatory. You choose the other four.

Security, the group of common criteria, is in every SOC 2. The other four are eligible add-ons: you choose them based on what you already promise in contracts and what the market you sell to will demand. Eligible does not mean skippable. It is your call, and the call has an expiry date, because every category included later needs its own observation period. That is why the cheapest moment to include one is now, alongside the rest.

CategoryEligibilityWhy it is worth including
SecurityMandatoryThe group of common criteria, organised into nine blocks that run from the control environment to vendor management. It is the backbone of any SOC 2 report, and on its own already meets much of what customers ask for.
AvailabilityEligibleYou already promise availability in your contracts: the service level agreement (the SLA) is signed with or without SOC 2. This category is what proves the promise holds, covering capacity, recovery and testing of the plan. Leaving it out tends to last until the first renewal with a large account, which asks for exactly this.
ConfidentialityEligibleWorth it whenever a customer marks some information as confidential and expects to see it protected by agreement, which in practice is almost every enterprise contract. It covers identifying, keeping and disposing of that information. It is the category with the least extra effort for anyone who has done Security, because it reuses much of the same set of controls.
Processing integrityEligibleNeeded when your service processes a transaction or calculation on the customer's behalf and the result has to be complete, accurate and authorised. In payments, payroll, billing and logistics, it answers the question the customer really has: is the number coming out of here correct? Security alone does not answer that.
PrivacyEligibleIt comes in when you handle personal data, and buyers ask for it more and more as privacy law tightens. It covers part of what the law requires and does not replace a privacy programme, but it shows the customer, backed by a third party, exactly the part they push hardest on when reviewing you.

The calculation people usually get wrong: adding a category in the next cycle does not cost a little more, it costs a whole observation period just for it, and until then you tell the customer it is not covered. It is worth asking the customer, in writing, what they expect to receive, and deciding the scope while also looking at the contracts you want to win over the next two years.

The real timeline

From the decision to the report in hand

The total timeline is almost never published, and it is exactly the one that matters when a contract is waiting. The phases below happen one after another, and it is the sum of them that you need to agree with your customer.

  1. 01

    Diagnosis and scope definition

    Comparing your situation with the criteria, defining categories, systems and environments, and the choice between Type I and Type II. It ends with a plan and the scope on paper.

  2. 02

    Fixes

    The phase with the least predictable length, and the biggest risk of blowing the timeline. It depends entirely on how much already exists. A company with governance in place moves fast; one that never formalised anything has groundwork to do.

  3. 03

    Observation period

    It only exists in Type II, and it is calendar time you cannot shorten. The controls have to work and produce proof across the whole period agreed with the auditor.

  4. 04

    Auditor fieldwork

    The CPA firm tests the controls, examines the proof and talks to the team. This is where the difference shows up between the process on paper and the one done for real.

  5. 05

    Report delivery

    Writing, your company's response to any problems found, and delivery. The document comes out in English when the firm is American, which is usually the case.

We do not publish a standard timeline because it would be a guess: the fixes vary too much from one company to another, and the observation period is a scope choice. What can be said with confidence is that a Type II does not come out in weeks, because the observation period is calendar time you cannot shorten. After the diagnosis, we can put dates on your case precisely enough for you to commit to the customer.

Who does what

The split of roles, stated before you hire

A SOC 2 project involves four parties, each signing something different. We make the split clear before the proposal so there is no surprise about scope or fees later.

Your company
Writes the system description, a section of the report that management takes formal responsibility for, and signs the management assertion. It also hires the audit firm.
DM11
Prepares. Defines scope, runs the diagnosis against the criteria, builds controls, writes policies, sets up the proof routine, trains the team and runs the rehearsal before the audit. We do not sign the report and we are not an audit firm.
The CPA firm
Signs the report. It is hired by you, separately, and its fee is a contract apart from ours. For independence, it cannot have built the controls it is going to test.
Your customer
Defines what they need to receive: which type of report, which categories and how often. It is worth getting that in writing before sizing anything.

Self-assessment

How close your company is to holding up under an audit

Eighteen questions across the control groups the report examines. The full result appears on screen, with a score per group and what closes the biggest gaps. We do not ask for your email to show it.

Control environmentQuestion 1 of 18

Is there a code of conduct communicated, with proof the team accepted it?

The report starts with the control environment, where the audit tests culture with a document in hand.

How we run it

From scope definition to the delivered report

Every phase ends with something delivered. You know what you get before you start.

  1. 01

    Define the scope

    We turn your customer's requirement into a report type, categories, systems and period. It is the decision that moves cost and timeline the most, and the one most often rushed.

    You get

    • Scope on paper with categories and systems
    • Type I or Type II decision with the reasons
    • Formal questions to send your customer
  2. 02

    Diagnosis against the criteria

    We assess where you stand today control by control, using the same checklist we use in audits, to show the real distance rather than an impression.

    You get

    • Diagnosis per control group
    • Gap report in order of priority
    • Effort estimate per front
  3. 03

    Fix

    We put in place, together with your team, what is missing: policies, access processes, changes, monitoring, incident response and vendor management.

    You get

    • Approved policies and procedures
    • Controls in place and working
    • Training for the areas involved
  4. 04

    Set up the proof routine

    In Type II the auditor tests the whole period, so the proof has to come out of day-to-day work. We define what is produced, by whom and how often, before the period starts.

    You get

    • Proof map per control
    • Routine with owners and a frequency
    • Repository organised for the audit
  5. 05

    Write the system description

    We help write the section of the report that is your company's responsibility, including the system boundaries, the commitments made and the role of the partners.

    You get

    • System description written
    • Boundaries and partners defined
    • Controls expected from the customer
  6. 06

    Rehearse and support

    We simulate the audit with the same rigour as the auditor before they arrive, and we support the CPA firm's fieldwork, including your company's response if there is any problem.

    You get

    • Readiness report with what was found
    • Fixes made before the audit
    • Support during the fieldwork

Stories

Four situations we have already solved

We hide the clients' names with the same confidentiality that will protect your company later. The names change, and the pattern of the problems repeats.

Software as a service

The contract that could not wait for the period

Situation
A corporate customer made signing conditional on a SOC 2, with a two month deadline. The company had nothing formalised, and the most requested report needs an observation period that did not fit that window.
What we did
We went to the customer together with the company and proposed a two-step path: Type I on the date that was possible, with a dated commitment to Type II right after. At the same time, the fixes began, already producing proof for the next period.
Outcome
The contract was signed on the Type I. The Type II observation period started with the controls already working, instead of starting from zero later.
Fintech

Good technology and no trail

Situation
Engineering was mature: code review, separated environments, monitoring. But none of it left a record that could hold up in an audit test. Changes went to production with verbal approval in chat.
What we did
Rather than creating a new process, we adjusted what the team already used so the trail came about on its own: approval recorded in the development tool itself and access proof pulled automatically.
Outcome
The team did not change its routine and the audit got something to test. The internal argument about bureaucracy, which usually stalls these projects, never even happened.
Data platform

Chose scope by whichever customer was asking

Situation
The company was about to hire only Security, because that was what the customer who prompted the project had asked for. Its own contract, though, promised availability with a service level agreement, and half the pipeline was large accounts that audit their vendors.
What we did
We read the signed contracts before settling the scope, and not just that one customer's request. Availability went into the same observation period, alongside Security. Processing integrity stayed out with a written justification, because the company does not process calculations on anyone's behalf.
Outcome
The report came out covering what the contract already promised. When the availability requirement came up in a later negotiation, the answer was already ready, instead of costing a new observation period just for that category.
Infrastructure provider

Found out about the problems in front of the customer

Situation
In the first cycle, with no rehearsal beforehand, the report came out with problems the company had not expected, including active access for people who had already left. The document went to the customer with those problems on display.
What we did
In the next cycle we added a rehearsal run with the same rigour as the auditor, months before the fieldwork. The problems appeared to us first, with time to fix them and to produce proof of the fix.
Outcome
The next report came out without the earlier problems. The lesson that stuck was a different one: a problem is not a catastrophe, but finding out about it together with the customer is avoidable.

Scoping

Build the scope of your proposal

Twelve questions about what sets the size of a SOC 2 project. At the end you review your answers, correct anything you want, and get a proposal built on that, without needing a meeting just to find out the basics.

ReportQuestion 1 of 12

Which report did your customer ask for?

If the request does not say, it is worth confirming before pricing.

Frequently asked

What people ask before deciding

Answers based on the standards of the AICPA (the accountants' body in the United States). Where no official figure exists, we say so.

You can, and almost everyone does. When your customer asks for a SOC 2 certification, we know exactly what they want. The technical name, though, is an attestation report, issued under the standards of the American Institute of Certified Public Accountants (the accountants' body in the United States), and the difference matters on three practical points. Who signs it: only a licensed CPA firm, never a consultancy. What you receive: a report of several sections that the customer will read, including the tests control by control, and not a one-page certificate. And the timeline: because the most requested report covers a period of working, it does not shorten the way a traditional certification audit does. Knowing this changes what you hire and from whom.

More questions? Talk to DM11

Your SOC 2 certification, sized to what the customer actually requires

A thirty minute conversation is usually enough to settle report type, categories and a rough idea of the effort involved. No obligation.

Talk to a specialistBuild the scope