Who this is for
B2B SaaS and managed-service teams in the UAE, KSA and India targeting their first SOC 2 Type 2 with a 6 or 12-month observation window.
The 12-week plan
Weeks 1-2 — Scope and design
- Decide trust-services criteria: Security is mandatory; add Availability, Confidentiality, Processing Integrity or Privacy based on customer contracts.
- Document the service description and system boundaries.
- Map every TSC criterion to a control, an owner, and an evidence source.
Weeks 3-4 — Foundational controls
- HR: background checks, onboarding/offboarding tickets, confidentiality agreements.
- Access: SSO/MFA on production, quarterly access reviews, JML automation.
- Change: branch protection, code review, deployment approvals.
Weeks 5-6 — Operational controls
- Vulnerability management: scanner output, SLA-tracked remediation.
- Logging and monitoring: SIEM coverage, alert runbooks, on-call rota.
- Vendor management: register, risk tiering, annual reviews.
Weeks 7-8 — Resilience and incident response
- Backup configuration and restore test evidence.
- BCP/DR plan with last tabletop minutes.
- Incident response runbook with severity matrix.
Weeks 9-10 — Internal evidence dry-run
- Sample 25 changes, 25 access requests, 4 quarters of reviews.
- Confirm every control owner can produce evidence within 24 hours.
Weeks 11-12 — Observation window opens
- Freeze control design.
- Brief the auditor on scope, exceptions and remediation plan.
- Run a weekly evidence-collection cadence for the full window.
Common Type 2 exceptions to pre-empt
- Terminated user retained access beyond 24 hours
- Production change deployed without approver evidence
- Backup restore test missed in the period
- Vendor review overdue at year-end
- Vulnerability past SLA without documented risk acceptance
Next step
MAST runs SOC 2 readiness sprints as a fixed-fee 12-week programme. Talk to the practice lead.