SOC 2 Examinations for SaaS Companies
Licensed CPA firm. Direct partner access. Big 4 and enterprise security background.
Enterprise prospects require SOC 2 before signing contracts. Get a credible, AICPA-standard report from a CPA who actually understands your tech stack — without an enterprise audit bill.
Why Tang Advisory
Most SOC 2 auditors come from one of two backgrounds: CPA firms that bring in IT consultants, or cybersecurity consultancies that partner with CPAs to issue reports. Tang Advisory brings both in one person — a licensed CPA with deep, hands-on cybersecurity expertise.
I've worked in Big 4 audit (PwC), served as lead assessor on SOC 2 examinations at Coalfire for AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Oracle Cloud, and IBM Cloud, and built cloud infrastructure at AWS. My background spans the full stack — from auditing the largest hyperscalers in the world to hands-on cloud security engineering. When I examine your controls, I'm not checking boxes — I'm evaluating your architecture with the same depth as your security team.
You won't spend hours explaining your cloud infrastructure to your auditor. I speak your language.
Credentials
Selected professional credentials across audit, security, cloud, and privacy. Current status is verified during engagement acceptance.
CPA
WA since May 2014; OR since February 2026
CISSP
Cybersecurity
CISM
Security Management
CRISC
Risk & Controls
CCSP
Cloud Security
CIPP/US
Privacy Law
CIPM
Privacy Management
HITRUST CCSPP
Healthcare Security
AWS Security Specialty
Cloud Security
AWS SA Professional
Architecture
SC-100
Microsoft Cybersecurity Architect
AZ-500
Azure Security Engineer
How It Works
A clear, predictable process from initial call to signed report.
Step 1: Preliminary Scope Discussion
Free, 30 minWe discuss intended report users, the system boundary, applicable Trust Services Categories, report type, and timing. Any engagement remains subject to formal client acceptance, independence, competence, staffing, quality-review, and firm-readiness gates.
Step 2: Readiness Gap Assessment
Separately scoped, if appropriateA separately scoped assessment can identify factual gaps against agreed criteria. Management retains responsibility for all decisions and for designing, implementing, and operating controls. Before Tang Advisory performs both readiness and an examination, the firm evaluates whether the services are permissible and whether independence safeguards are sufficient.
Step 3: Examination
Scheduled only after required gates are completeFormal SOC 2 examination — walkthroughs, evidence review, control testing. You work directly with me throughout.
Step 4: Report Delivery
Signed SOC 2 Type I or Type II report, ready to share with enterprise prospects and procurement teams.
Type I vs. Type II
Type I
A Type I examination evaluates whether controls were suitably designed and implemented as of a specified date. Timing depends on scope, evidence readiness, identified matters, and completion of the firm's required quality gates.
Best for:
- Closing an enterprise deal quickly
- Establishing initial SOC 2 compliance
Type II
Controls tested over a 3-12 month observation period. Higher assurance. Some buyers accept a shorter 3-month first window, but many enterprise security teams require 6-12 months — confirm with your buyer before locking the window.
Best for:
- Fortune 500 procurement requirements
- Regulated industries
- Demonstrating sustained security posture
Most companies start with Type I and graduate to Type II.
Who I Work With
I work primarily with SaaS companies from seed stage through Series C, and bootstrapped B2B software companies selling to enterprise customers.
Built for High-Growth SaaS
Large audit firms do excellent work — for companies that need enterprise pricing and rotating teams. If you're a 20-200 person SaaS company that needs a credible, AICPA-standard SOC 2 report with direct partner access and a CPA who understands your infrastructure, you're in the right place.
Frequently Asked Questions
Licensure & Verification
Tang Advisory is the trade name of Tang Enterprises LLC, a Washington-registered CPA firm (WA firm license #59422). George Tang is a licensed CPA in Washington (#32532; original issue date May 13, 2014) and was granted Oregon license #17555 on February 2, 2026. Verify current license status at CPAVerify or the Washington State Board of Accountancy.
Based in the Pacific Northwest. Serving SaaS companies nationally.
Ready to discuss a SOC 2 examination?
Schedule a free 30-minute preliminary scope discussion. Formal scope, timing, and fees are established only after the firm completes its required acceptance and quality gates.