Get SOC 2 done. Keep shipping.

Your enterprise deal needs an audit report. Your engineers have a product to build.

I manage your SOC 2 program, from the initial assessment to auditor coordination. Give security a dedicated owner while your CTO keeps the product moving.

What the engagement costs

You want the job done right, but you also need to control the budget. We're transparent. Here are the numbers.

Auditor & gap analysis

I bring an independent auditor I work well with, so we can get straight to preparing your team.

Gap analysis
$10,000
Audit
$30,000

Reuben’s time

50–100 hours of hands-on security leadership, covering the custom services below.

Hourly rate
$250/hr
Estimated fees
$12,500–$25,000

Penetration testing

A penetration tester for multiple engagements, with time to address findings and test again.

Multiple engagements
$5,000

Your SOC 2 program, managed end to end.

A 12-month roadmap and one person coordinating the details. I tailor the security program to your business and agree priorities and responsibilities with your team up front.

Readiness & roadmap

Start with your existing systems and practices. Identify the gaps and put the priorities in order.

  • SOC 2 readiness assessment
  • 12-month plan for your Type 2 audit
  • Quarterly reviews and adjustments

Policies & risk

Build policies your team can follow, based on how your business actually operates.

  • Review of existing policies
  • Policy design and writing
  • Comprehensive risk assessment

Testing & audit partners

I bring an auditor I work well with and coordinate testing and follow-up.

  • Multiple penetration testing engagements
  • Gap analysis and follow-up
  • Independent SOC 2 Type 2 auditor

Team training

Make security part of day-to-day engineering, with clear expectations and practical training.

  • Policy rollout and training
  • Security awareness sessions
  • Software development process improvements

Audit management

I handle auditor coordination and keep the evidence requests moving.

  • Representation throughout the audit
  • Evidence and meeting coordination
  • Meeting recordings available to your team

Handover & ongoing support

Keep your security program running after the audit, with clear ownership and practical guidance.

  • Staff guidance on maintaining the program
  • Responsibilities and recurring tasks documented
  • Ongoing fractional CISO support available

Your fractional CISO: Reuben Firmin.

I’ve managed security while leading engineering teams. At ExecVision, I owned the SOC 2 program alongside architecture and product delivery, taking the company from prototype through acquisition.

I understand what an audit asks of a small team. I handle the coordination, turn broad requirements into specific tasks, and keep you involved in the decisions that need your input.

See my experience and background
Reuben Firmin

Security leadership, in clients’ words.

Client experiences from SOC 2 programs and broader security engagements.

Francois Huet

Francois Huet

Head of Engineering, Cadence OneFive

"We maintained laser focus on product delivery without compromising our compliance requirements."

"Navigating SOC 2 certification is a complex and time-consuming process that diverts critical technical resources from core product development. Reuben transformed this challenge by strategically managing the certification journey, streamlining mundane tasks, and identifying cost-effective solutions while minimizing team disruption. Thanks to his expertise, we maintained laser focus on product delivery without compromising our compliance requirements."

David Stillman

David Stillman

CEO, ExecVision

"Reuben ran our SOC 2 compliance program for 5 years in a row. We always had a clean audit."

"At ExecVision, Reuben ran our SOC 2 compliance program for 5 years in a row. We always had a clean audit. Our security posture was reliably strong enough that our Fortune 100 Fintech clients were satisfied that we were compliant with their requirements."

Lucas Gray

Lucas Gray

Head of Engineering, Alloy Health

"We now feel more secure and better prepared thanks to his guidance."

"We had an excellent experience working with Reuben on our company's security initiatives. He provided a comprehensive list of security recommendations tailored to our needs. His expertise helped us formulate and implement security best practices, and his security awareness presentation to our team was engaging and highly informative. We now feel more secure and better prepared thanks to his guidance. I highly recommend Reuben for any organization looking to strengthen their cybersecurity posture."

Questions about SOC 2

What does the engagement include?

An independent auditor I work well with: $10,000 for gap analysis and $30,000 for the SOC 2 Type 2 audit. My time is $250 per hour, with 50–100 hours anticipated ($12,500–$25,000). Multiple penetration testing engagements cost $5,000.

My time covers the custom readiness planning, policies, risk assessment, training, and audit coordination listed above. We agree the scope and responsibilities before starting.

How does the 12-month roadmap work?

We start with a gap analysis, establish the policies and controls, and coordinate testing, evidence collection, and the Type 2 audit.

The roadmap is planned over 12 months. We confirm the audit period and schedule with you and the auditor, taking your starting point and any remediation into account.

How much does my engineering team need to do?

Your team still owns the systems and implements technical changes. I manage the security program, policies, training, and auditor coordination, and bring specific requests to the people who need to act on them.

We agree responsibilities at the start so security tasks can be planned alongside product delivery.

Do you issue the SOC 2 report?

No. An independent CPA firm performs the examination and issues the report. I prepare and manage your security program and coordinate with the auditor throughout the engagement.

What happens after the first audit?

Keep the controls operating and evidence up to date for subsequent audits. During the engagement, I show your staff how to maintain the program.

You can take over in-house or retain me as your fractional CISO. The ongoing scope and cost depend on the support you need.

What’s standing between you and SOC 2?

Tell me what your customer is asking for, your target date, and what you already have in place. We can scope the steps, responsibilities, and cost.

Book an introductory call [email protected]