Compliance Roadmap

SOC 2-aligned readiness roadmap

The path SmartQuotes is following toward a formal audit, without implying completion. SmartQuotes starts with Security as the baseline Trust Services Criteria category and adds others as they match customer commitments and product scope.

  1. 1

    Now

    Publish the Trust Center, executive security summary, responsible disclosure, and security contact.

  2. 2

    Next

    Complete core policies: Access Control, Incident Response, Secure SDLC, Change Management, Vendor Management, Data Retention, and Business Continuity.

  3. 3

    Then

    Build evidence collection: access reviews, change logs, vulnerability reviews, backup tests, incident tabletop exercises, and a vendor inventory.

  4. 4

    Audit prep

    Engage a SOC 2 readiness advisor or CPA firm for a gap assessment and Type I scoping.

  5. 5

    Formal audit

    Proceed to SOC 2 Type I and later Type II when operations and evidence are mature enough for examination.

The SOC 2 Trust Services Criteria categories commonly discussed in SOC 2 readiness are Security, Availability, Processing Integrity, Confidentiality, and Privacy. SmartQuotes treats these as alignment guidance until a licensed auditor scopes an actual engagement.

For enterprise review

Highlights for review

  • SOC 2-aligned readiness language only
  • No completed SOC 2 report claimed
  • Evidence collection framed as internal preparation
  • Future independent examination framed as a planned path
SmartQuotes is building its security and operational practices in alignment with SOC 2 Trust Services Criteria. SmartQuotes has not completed a SOC 2 Type I or Type II audit, and nothing on these pages is a certification, attestation, or audit report. Status labels reflect current readiness, not completed controls.