Case study · MSP / IT Services · Toronto, Canada
A Toronto MSP kept losing enterprise deals at the security-review stage. ITSECOPS ran its SOC 2 Type II readiness programme end to end — scoping, policies, evidence automation and observation-period support — so the CPA audit became a formality, not a fire drill.
The client
A managed service provider in Toronto serving finance and legal clients, with strong engineering but no formalized control environment.
The challenge
Enterprise prospects demanded a SOC 2 Type II report. The MSP had tooling everywhere but evidence nowhere — and a Type II audit measures months of operating effectiveness, so every week of delay extended the timeline.
What we did
- Scoped Trust Services Criteria to Security and Availability — resisting the temptation to boil the ocean with all five.
- Wrote the control set and policies around how the MSP actually works: PSA tickets, RMM changes, on-call rotations.
- Automated evidence collection so screenshots died: exports scheduled from the PSA, RMM, IdP and cloud consoles.
- Ran a readiness assessment, remediated gaps, then supported the observation window and CPA auditor liaison. (Readiness is our work; the audit opinion itself belongs to a licensed CPA firm.)
Results
- Clean Type II observation period; report delivered to three waiting prospects.
- Evidence collection now runs on autopilot — next year’s audit inherits it.
- Security review stage went from deal-killer to differentiator.
FAQ
How long does SOC 2 Type II take for an MSP?
Readiness typically 2–3 months, then a 3–12 month observation window. Starting readiness early is the only way to compress the calendar.
Readiness consultant vs auditor — what is the difference?
The auditor (a CPA firm) issues the opinion and cannot build your controls. The readiness partner builds and operationalizes them. Using one firm for both is a conflict.
Does SOC 2 help an MSP win business?
Directly — it answers the security questionnaire before it is asked. See our white-label MSP support if you also need the operational depth behind it.