SOC 2 Examinations for SaaS Companies

Licensed CPA firm. Direct partner access. Big 4 and enterprise security background.

Enterprise prospects require SOC 2 before signing contracts. Get a credible, AICPA-standard report from a CPA who actually understands your tech stack — without an enterprise audit bill.

Why Tang Advisory

Most SOC 2 auditors come from one of two backgrounds: CPA firms that bring in IT consultants, or cybersecurity consultancies that partner with CPAs to issue reports. Tang Advisory brings both in one person — a licensed CPA with deep, hands-on cybersecurity expertise.

I've worked in Big 4 audit (PwC), served as lead assessor on SOC 2 examinations at Coalfire for AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Oracle Cloud, and IBM Cloud, and built cloud infrastructure at AWS. My background spans the full stack — from auditing the largest hyperscalers in the world to hands-on cloud security engineering. When I examine your controls, I'm not checking boxes — I'm evaluating your architecture with the same depth as your security team.

You won't spend hours explaining your cloud infrastructure to your auditor. I speak your language.

Credentials

Selected professional credentials across audit, security, cloud, and privacy. Current status is verified during engagement acceptance.

CPA

WA since May 2014; OR since February 2026

CISSP

Cybersecurity

CISM

Security Management

CRISC

Risk & Controls

CCSP

Cloud Security

CIPP/US

Privacy Law

CIPM

Privacy Management

HITRUST CCSPP

Healthcare Security

AWS Security Specialty

Cloud Security

AWS SA Professional

Architecture

SC-100

Microsoft Cybersecurity Architect

AZ-500

Azure Security Engineer

How It Works

A clear, predictable process from initial call to signed report.

Step 1: Preliminary Scope Discussion

Free, 30 min

We discuss intended report users, the system boundary, applicable Trust Services Categories, report type, and timing. Any engagement remains subject to formal client acceptance, independence, competence, staffing, quality-review, and firm-readiness gates.

Step 2: Readiness Gap Assessment

Separately scoped, if appropriate

A separately scoped assessment can identify factual gaps against agreed criteria. Management retains responsibility for all decisions and for designing, implementing, and operating controls. Before Tang Advisory performs both readiness and an examination, the firm evaluates whether the services are permissible and whether independence safeguards are sufficient.

Step 3: Examination

Scheduled only after required gates are complete

Formal SOC 2 examination — walkthroughs, evidence review, control testing. You work directly with me throughout.

Step 4: Report Delivery

Signed SOC 2 Type I or Type II report, ready to share with enterprise prospects and procurement teams.

Type I vs. Type II

Type I

A Type I examination evaluates whether controls were suitably designed and implemented as of a specified date. Timing depends on scope, evidence readiness, identified matters, and completion of the firm's required quality gates.

Best for:

  • Closing an enterprise deal quickly
  • Establishing initial SOC 2 compliance

Type II

Controls tested over a 3-12 month observation period. Higher assurance. Some buyers accept a shorter 3-month first window, but many enterprise security teams require 6-12 months — confirm with your buyer before locking the window.

Best for:

  • Fortune 500 procurement requirements
  • Regulated industries
  • Demonstrating sustained security posture

Most companies start with Type I and graduate to Type II.

Who I Work With

I work primarily with SaaS companies from seed stage through Series C, and bootstrapped B2B software companies selling to enterprise customers.

SaaSFintechHealthtechAI/ML PlatformsDeveloper ToolsData Infrastructure

Built for High-Growth SaaS

Large audit firms do excellent work — for companies that need enterprise pricing and rotating teams. If you're a 20-200 person SaaS company that needs a credible, AICPA-standard SOC 2 report with direct partner access and a CPA who understands your infrastructure, you're in the right place.

Frequently Asked Questions

Licensure & Verification

Tang Advisory is the trade name of Tang Enterprises LLC, a Washington-registered CPA firm (WA firm license #59422). George Tang is a licensed CPA in Washington (#32532; original issue date May 13, 2014) and was granted Oregon license #17555 on February 2, 2026. Verify current license status at CPAVerify or the Washington State Board of Accountancy.

Based in the Pacific Northwest. Serving SaaS companies nationally.

Ready to discuss a SOC 2 examination?

Schedule a free 30-minute preliminary scope discussion. Formal scope, timing, and fees are established only after the firm completes its required acceptance and quality gates.