SOC 2 compliance without the scramble

Vanta shows you the gaps. We close them: cloud controls, policies, evidence and the operational discipline to stay audit-ready through the observation window and beyond.

SOC 2 remediation services

SOC 2 readiness and remediation, delivered in Vanta

Most companies start SOC 2 the same way: a large customer asks for the report, you sign up to Vanta, connect your cloud accounts and identity provider, and a dashboard lights up with dozens of failing tests. The platform is doing its job. The problem is that every one of those tests is a piece of engineering or process work that someone now has to own, and your team already has a full-time job.

Orbit3 takes ownership of the remediation. We work inside your Vanta workspace, rank the failing tests by audit risk and effort, fix the technical controls in your AWS, Azure or Google Cloud environment through infrastructure as code, run the organisational controls with you, and keep everything green through the observation window and the audit itself. If you are not on Vanta, the same approach works with Drata, Secureframe and similar platforms.

  • Gap triage in VantaEvery failing test ranked by risk, effort and which Trust Services Criteria it affects.
  • Technical remediationMFA, logging, encryption, network exposure, patching, backups and change control fixed in code.
  • Organisational controlsPolicies, risk assessment, vendor reviews, access reviews and training run with you, not left in a template.
  • Audit-ready evidenceContinuous, automated evidence in Vanta, plus the manual artefacts an auditor will still ask for.
  • Stay green after the auditUnder managed services, the controls are operated and monitored every month.
At a glance
PlatformVanta (also Drata, Secureframe)
ScopeSecurity criteria first, then Availability and Confidentiality if needed
Typical pathGap triage → remediation → Type I → observation → Type II
AfterwardsControls kept green under managed services
Who it's for

For teams that bought Vanta and hit the wall of red

Compliance automation removes the spreadsheet. It does not remove the work. These are the situations we are usually called into.

SaaS vendors with a deal waiting on the report

Procurement has asked for SOC 2 and the sales cycle is on hold. You need a credible readiness date and a team that can hit it.

Startups with Vanta connected and nobody assigned

The integrations are live and the dashboard is red. Engineers are picking off tests between sprints, and the date keeps slipping.

Companies that passed Type I and drifted

The point-in-time report went fine. Six months later, tests are failing again and the Type II observation window is at risk.

What's included

Every failing test owned, fixed and evidenced

Vanta tells you what is failing. Someone still has to fix it, prove it, and keep it fixed through the observation window. That is the part we take ownership of.

  • Scoping and criteria selectionWhich systems are in scope, which Trust Services Criteria you need (Security is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are optional), and what your customers actually asked for.
  • Vanta workspace reviewIntegrations connected correctly, in-scope resources tagged, test ownership assigned, and the failing tests triaged into a ranked backlog.
  • Cloud control remediationIdentity and MFA, audit logging, encryption at rest and in transit, network exposure, vulnerability management and patching, backup and recovery testing, fixed through Terraform or native templates so they do not drift.
  • Change management and SDLC controlsBranch protection, peer review, CI checks, separation of environments and deployment approvals, evidenced automatically from your code host and pipeline.
  • Policy setVanta's policy templates adapted to how your company actually operates, reviewed with you, approved and accepted by staff in the platform.
  • Risk assessment and vendor managementA risk register that reflects your real business, and vendor reviews for the SaaS tools that hold your data.
  • People controlsOnboarding and offboarding checklists, security awareness training, background checks where required, and quarterly access reviews set up as recurring tasks.
  • Evidence and auditor liaisonManual evidence collected and organised, auditor access to Vanta configured, and questions from the audit firm answered with your team.
  • Post-audit operationsMonitoring of Vanta tests, recurring tasks completed on schedule and control drift fixed as part of managed services, so Type II renewals are routine.
How we deliver it

Triage, remediate, evidence, sustain

SOC 2 projects stall in remediation, not in the audit. We run remediation as an engineering project with an owner, a ranked backlog and a date.

Triage

We review the scope, the Vanta integrations and every failing test, and produce a ranked remediation plan with owners and a realistic readiness date. You get this whether or not you continue.

Remediate

We fix the technical controls in your cloud environment through infrastructure as code and run the organisational controls with you: policies, risk assessment, vendor and access reviews, training.

Evidence and audit

With the tests green, we collect the remaining manual evidence, set up auditor access and support your team through the Type I report and the Type II observation window.

Platforms

AWS, Azure and Google Cloud

Most of Vanta's infrastructure tests map to native platform services. Configured correctly and in code, they stay green without anyone touching them.

Amazon Web Services

IAM and Identity Center for MFA and least privilege, CloudTrail and Config for audit logging and configuration history, GuardDuty and Security Hub for detection, KMS and default encryption, AWS Backup with tested restores. Vanta reads all of these directly.

Microsoft Azure

Entra ID Conditional Access and Privileged Identity Management, Defender for Cloud, Azure Policy for enforced configuration, Monitor and Log Analytics for retained logs, Key Vault, and Azure Backup with recovery tests.

Google Cloud

Organisation policies and IAM with enforced 2-step verification, Cloud Audit Logs with retention, Security Command Center, CMEK where required, and Backup and DR Service with scheduled restore tests.

Why Vanta

How we use Vanta

Vanta is a compliance automation platform. It connects to your cloud accounts, identity provider, code host, HR and device-management tools, runs automated tests against the SOC 2 criteria continuously, and gives your auditor a single place to review evidence. It replaces the spreadsheet and the screenshot folder.

What it cannot do is change your infrastructure or run your processes. That is where we come in. We treat the Vanta dashboard as the shared backlog: every failing test gets an owner, a fix and a date, and the tests stay green because the fixes are made in code and the tasks are operated, not just ticked.

Read our guide: SOC 2 remediation: how to close the gaps Vanta finds.

  • Integrations done rightEvery in-scope account connected, resources tagged, tests assigned.
  • Tests fixed at the sourceCloud controls changed in Terraform so the fix cannot drift.
  • Policies that match realityTemplates adapted to how you actually work, then approved and accepted.
  • Recurring tasks operatedAccess reviews, restore tests, vendor reviews and training on schedule.
  • Auditor-ready evidenceAutomated evidence plus the manual artefacts organised in one place.
  • Continuous monitoringFailing tests caught and fixed as part of managed operations.
Questions we get asked

Frequently asked questions

What is SOC 2 remediation?

Remediation is the work between the gap assessment and the audit: fixing the technical controls (MFA, logging, encryption, network exposure, patching, backups, change control), putting the organisational controls in place (policies, risk assessment, vendor management, access reviews, training), and collecting evidence that they operate. In Vanta it shows up as turning failing tests green and completing the assigned tasks.

Do we need Vanta to work with you?

No, but it helps. Vanta automates most of the evidence collection and gives both of us one view of what is outstanding. We work the same way in Drata, Secureframe and similar platforms, and we can run a SOC 2 programme without a platform if you already have one under way.

How long does SOC 2 remediation take?

For a typical cloud-native company with a single production environment, remediation to a Type I-ready state takes weeks rather than months once someone owns it full time. A Type II report then needs an observation window, commonly three to twelve months, during which the controls have to keep operating. The triage step gives you a realistic date for your situation.

Type I or Type II?

Type I reports on the design of your controls at a point in time; Type II reports on whether they operated effectively over a period. Most enterprise customers ultimately want Type II. A common path is to remediate, obtain a Type I to unblock deals, and start the Type II observation window immediately afterwards.

Can you work with our auditor?

Yes. We set up auditor access in Vanta, organise the evidence the way audit firms expect, and join the calls where technical questions come up. We do not perform the audit itself; that has to be an independent CPA firm.

What happens after the report?

SOC 2 is annual, and controls drift the moment nobody is watching. Under our managed service the Vanta tests are monitored, recurring tasks such as access reviews and restore tests happen on schedule, and drift is fixed as it appears, so the next observation window is uneventful.

Get started

Staring at a red Vanta dashboard?

Book a free 30-minute call. Share your screen, and we'll tell you which failing tests matter, which are quick, and how long a realistic remediation would take.