SOC 1 & SOC 2 Compliance

SOC attestation, explained and executed without the runaround.

There's no such thing as a "SOC certificate" — a CPA attests that your systems and controls are in place. We do the preparation work so that attestation goes smoothly the first time.

SOC 1 & SOC 2 Compliance

We prepare you; a CPA attests.

Controls & policy handbook

We build the policies and procedures your SOC attestation actually requires, in a handbook your team can follow.

Type 1 to Type 2

We get you through your initial Type 1 attestation, then manage the roughly 6-month period of adherence needed for Type 2.

Trusted CPA pairing

We pair you with a CPA we know and trust, and tell you exactly what they'll expect from you going in.

What's included

What SOC auditors actually want to see.

  • Device monitoring & EDR
  • Documented staff training & policy handbook
  • Breach controls in place
  • Extra protection for PII, financial & customer data
  • A disaster recovery plan
  • Alerting for signs of a breach
Why it matters

A SOC 2 attestation is essentially a cybersecurity audit.

Vendors and partners ask for SOC compliance because it proves your security controls are real, not just claimed. We know what auditors look for and build straight toward it — realistic deadlines, managed start to finish, without the overkill some firms sell you.

What our clients say

Real businesses, real relationships.

“When Joe assigned Ivan as our lead, we felt like we finally had IT solved. Ivan has been with us 24×7 and the team behind him makes sure nothing falls through the cracks.”

David Schuelke
David Schuelke
CEO, Spring Bank Wisconsin

“We’ve been using LME Services for our business IT support, and the experience has been fantastic. Their cybersecurity expertise, responsiveness, and ability to explain complex tech in plain English really set them apart.”

Jason Bergen
Jason Bergen
Google review
Frequently asked

Common questions

What's the difference between SOC Type 1 and Type 2?

Type 1 is a one-time attestation of your policies and controls at a point in time. Type 2 requires you to adhere to those controls for roughly 6 months before a CPA can attest to that ongoing performance — you need Type 1 before you can pursue Type 2.

Is there a SOC certificate we can just get?

No — a SOC report is an attestation performed by an AICPA-certified CPA, not a certificate issued after a scan. We prepare your controls and documentation, then connect you with a CPA we trust to perform the attestation.

How long does the whole process take?

Type 1 can move relatively quickly once your controls are documented. Type 2 requires roughly 6 months of adherence before the CPA can attest — the earlier you start, the more time you have to fix issues before they show up in the report.

Do you perform the SOC audit yourselves?

No — an independent CPA performs the attestation, as required. We build the controls, policies, and evidence beforehand so that attestation goes smoothly.

Let's talk about your IT.