SOC 2 Add-on

Add SOC 2 to ISO 27001. Same evidence. +$150/mo.

Add SOC 2 (AICPA Trust Services Criteria) to the ISO 27001 ISMS you already run. Same risk register, same evidence, same controls. +$150/mo. Core is $500/mo.

14-day trial · no card required · Core $500/mo + SOC 2 +$150/mo

What SOC 2 is

SOC 2 (AICPA Trust Services Criteria) is a report issued by a CPA firm that examines your controls. The five Trust Services Categories are Security, Availability, Confidentiality, Processing Integrity, and Privacy.

GapLedger supports Security, Availability, Confidentiality, and Processing Integrity. Privacy is NOT included, because Privacy TSC overlaps with ISO 27701 and requires separate consideration.

Same evidence, two frameworks

SOC 2 reuses the ISO 27001 evidence you already collect. Your risk register, Statement of Applicability, CAPA log, audit history, and evidence index all count for both frameworks. One piece of proof, two reports.

GapLedger maps the Trust Services Criteria to ISO 27001 Annex A controls. You maintain one management system, and the crosswalk shows you what covers what.

Not a SOC 2-only product

SOC 2 is an add-on, not a standalone SKU. You need Core (ISO 27001) first, then add SOC 2 for +$150/mo. If you only want SOC 2 and do not want ISO 27001, compare Vanta or Drata instead.

The audit pack is not a SOC 2 report

GapLedger exports an audit pack: your risk register, Statement of Applicability, CAPA log, audit history, and evidence index in a single PDF. The audit pack is not a SOC 2 report. A CPA firm issues the SOC 2 report after they examine your controls.

GapLedger is not a CPA firm, and does not issue SOC 2 reports. Certification decisions rest with your CPA firm.

Type I or Type II

Type I examines your controls at a point in time. Type II examines operating effectiveness over a period (typically 3, 6, or 12 months). Your CPA firm decides the type and timing. GapLedger does not make date promises, and does not have preferred CPA partners.

Core $500/mo + SOC 2 +$150/mo = $650/mo

Or annual billing and save 10%. Unlimited users, cancel anytime.

Frequently asked questions

Can I add SOC 2 later?

Yes. Start with Core (ISO 27001), then add SOC 2 whenever you are ready. +$150/mo, and it reuses your ISO 27001 evidence.

Do I need ISO 27001 to use SOC 2?

Yes. SOC 2 is an add-on, not a standalone product. You need Core (ISO 27001) first, then add SOC 2 for +$150/mo.

Does GapLedger issue SOC 2 reports?

No. GapLedger is compliance management software, not a CPA firm. A CPA firm issues the SOC 2 report after they examine your controls.

What about Privacy TSC?

Privacy TSC is NOT included in the SOC 2 add-on. Privacy overlaps with ISO 27701 (the privacy extension to ISO 27001) and requires separate consideration. If you need privacy, see ISO 27701 on the pricing page.

How long does SOC 2 take?

Type I examines controls at a point in time. Type II examines operating effectiveness over a period (typically 3, 6, or 12 months). Your CPA firm decides the type and timing. GapLedger does not make date promises.