SOC 2 compliance without the scramble
Vanta shows you the gaps. We close them: cloud controls, policies, evidence and the operational discipline to stay audit-ready through the observation window and beyond.
SOC 2 readiness and remediation, delivered in Vanta
Most companies start SOC 2 the same way: a large customer asks for the report, you sign up to Vanta, connect your cloud accounts and identity provider, and a dashboard lights up with dozens of failing tests. The platform is doing its job. The problem is that every one of those tests is a piece of engineering or process work that someone now has to own, and your team already has a full-time job.
Orbit3 takes ownership of the remediation. We work inside your Vanta workspace, rank the failing tests by audit risk and effort, fix the technical controls in your AWS, Azure or Google Cloud environment through infrastructure as code, run the organisational controls with you, and keep everything green through the observation window and the audit itself. If you are not on Vanta, the same approach works with Drata, Secureframe and similar platforms.
- Gap triage in VantaEvery failing test ranked by risk, effort and which Trust Services Criteria it affects.
- Technical remediationMFA, logging, encryption, network exposure, patching, backups and change control fixed in code.
- Organisational controlsPolicies, risk assessment, vendor reviews, access reviews and training run with you, not left in a template.
- Audit-ready evidenceContinuous, automated evidence in Vanta, plus the manual artefacts an auditor will still ask for.
- Stay green after the auditUnder managed services, the controls are operated and monitored every month.
For teams that bought Vanta and hit the wall of red
Compliance automation removes the spreadsheet. It does not remove the work. These are the situations we are usually called into.
SaaS vendors with a deal waiting on the report
Procurement has asked for SOC 2 and the sales cycle is on hold. You need a credible readiness date and a team that can hit it.
Startups with Vanta connected and nobody assigned
The integrations are live and the dashboard is red. Engineers are picking off tests between sprints, and the date keeps slipping.
Companies that passed Type I and drifted
The point-in-time report went fine. Six months later, tests are failing again and the Type II observation window is at risk.
Every failing test owned, fixed and evidenced
Vanta tells you what is failing. Someone still has to fix it, prove it, and keep it fixed through the observation window. That is the part we take ownership of.
- Scoping and criteria selectionWhich systems are in scope, which Trust Services Criteria you need (Security is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are optional), and what your customers actually asked for.
- Vanta workspace reviewIntegrations connected correctly, in-scope resources tagged, test ownership assigned, and the failing tests triaged into a ranked backlog.
- Cloud control remediationIdentity and MFA, audit logging, encryption at rest and in transit, network exposure, vulnerability management and patching, backup and recovery testing, fixed through Terraform or native templates so they do not drift.
- Change management and SDLC controlsBranch protection, peer review, CI checks, separation of environments and deployment approvals, evidenced automatically from your code host and pipeline.
- Policy setVanta's policy templates adapted to how your company actually operates, reviewed with you, approved and accepted by staff in the platform.
- Risk assessment and vendor managementA risk register that reflects your real business, and vendor reviews for the SaaS tools that hold your data.
- People controlsOnboarding and offboarding checklists, security awareness training, background checks where required, and quarterly access reviews set up as recurring tasks.
- Evidence and auditor liaisonManual evidence collected and organised, auditor access to Vanta configured, and questions from the audit firm answered with your team.
- Post-audit operationsMonitoring of Vanta tests, recurring tasks completed on schedule and control drift fixed as part of managed services, so Type II renewals are routine.
Triage, remediate, evidence, sustain
SOC 2 projects stall in remediation, not in the audit. We run remediation as an engineering project with an owner, a ranked backlog and a date.
Triage
We review the scope, the Vanta integrations and every failing test, and produce a ranked remediation plan with owners and a realistic readiness date. You get this whether or not you continue.
Remediate
We fix the technical controls in your cloud environment through infrastructure as code and run the organisational controls with you: policies, risk assessment, vendor and access reviews, training.
Evidence and audit
With the tests green, we collect the remaining manual evidence, set up auditor access and support your team through the Type I report and the Type II observation window.
AWS, Azure and Google Cloud
Most of Vanta's infrastructure tests map to native platform services. Configured correctly and in code, they stay green without anyone touching them.
Amazon Web Services
IAM and Identity Center for MFA and least privilege, CloudTrail and Config for audit logging and configuration history, GuardDuty and Security Hub for detection, KMS and default encryption, AWS Backup with tested restores. Vanta reads all of these directly.
Microsoft Azure
Entra ID Conditional Access and Privileged Identity Management, Defender for Cloud, Azure Policy for enforced configuration, Monitor and Log Analytics for retained logs, Key Vault, and Azure Backup with recovery tests.
Google Cloud
Organisation policies and IAM with enforced 2-step verification, Cloud Audit Logs with retention, Security Command Center, CMEK where required, and Backup and DR Service with scheduled restore tests.
How we use Vanta
Vanta is a compliance automation platform. It connects to your cloud accounts, identity provider, code host, HR and device-management tools, runs automated tests against the SOC 2 criteria continuously, and gives your auditor a single place to review evidence. It replaces the spreadsheet and the screenshot folder.
What it cannot do is change your infrastructure or run your processes. That is where we come in. We treat the Vanta dashboard as the shared backlog: every failing test gets an owner, a fix and a date, and the tests stay green because the fixes are made in code and the tasks are operated, not just ticked.
Read our guide: SOC 2 remediation: how to close the gaps Vanta finds.
- Integrations done rightEvery in-scope account connected, resources tagged, tests assigned.
- Tests fixed at the sourceCloud controls changed in Terraform so the fix cannot drift.
- Policies that match realityTemplates adapted to how you actually work, then approved and accepted.
- Recurring tasks operatedAccess reviews, restore tests, vendor reviews and training on schedule.
- Auditor-ready evidenceAutomated evidence plus the manual artefacts organised in one place.
- Continuous monitoringFailing tests caught and fixed as part of managed operations.
Frequently asked questions
What is SOC 2 remediation?
Remediation is the work between the gap assessment and the audit: fixing the technical controls (MFA, logging, encryption, network exposure, patching, backups, change control), putting the organisational controls in place (policies, risk assessment, vendor management, access reviews, training), and collecting evidence that they operate. In Vanta it shows up as turning failing tests green and completing the assigned tasks.
Do we need Vanta to work with you?
No, but it helps. Vanta automates most of the evidence collection and gives both of us one view of what is outstanding. We work the same way in Drata, Secureframe and similar platforms, and we can run a SOC 2 programme without a platform if you already have one under way.
How long does SOC 2 remediation take?
For a typical cloud-native company with a single production environment, remediation to a Type I-ready state takes weeks rather than months once someone owns it full time. A Type II report then needs an observation window, commonly three to twelve months, during which the controls have to keep operating. The triage step gives you a realistic date for your situation.
Type I or Type II?
Type I reports on the design of your controls at a point in time; Type II reports on whether they operated effectively over a period. Most enterprise customers ultimately want Type II. A common path is to remediate, obtain a Type I to unblock deals, and start the Type II observation window immediately afterwards.
Can you work with our auditor?
Yes. We set up auditor access in Vanta, organise the evidence the way audit firms expect, and join the calls where technical questions come up. We do not perform the audit itself; that has to be an independent CPA firm.
What happens after the report?
SOC 2 is annual, and controls drift the moment nobody is watching. Under our managed service the Vanta tests are monitored, recurring tasks such as access reviews and restore tests happen on schedule, and drift is fixed as it appears, so the next observation window is uneventful.
Often combined with this
SOC 2 controls are mostly good operations written down. These are the services that make the controls true rather than just documented.
Cloud Security
Security reviews, risk assessments and hardened target-state controls mapped to the standards you need to meet.
Learn moreCloudOps Managed Services
24/7 monitoring, patching, security and cost control for your AWS, Azure or Google Cloud environment, run by us.
Learn moreCloud Backup
Backup and disaster recovery designed around your recovery objectives, and tested so restores are routine.
Learn moreStaring at a red Vanta dashboard?
Book a free 30-minute call. Share your screen, and we'll tell you which failing tests matter, which are quick, and how long a realistic remediation would take.