SOC 2 · ISO 27001 · GDPR · Cyber Essentials

SOC 2 for Ukrainian tech companies: from readiness to report

We prepare SaaS products, outsourcing companies and fintechs for SOC 2 Type 1 and Type 2 — and issue the report through the BALTUM group's US-registered CPA firm. Optionally together with ISO 27001, GDPR, Cyber Essentials and NIS2 in one project, or each service on its own.

  • Our own US CPA firm and licensed CPA auditors
  • Accredited ISO 27001 certification body and Cyber Essentials certification body
  • One control set for every standard — no duplicate work
  • Ukrainian team, contract with an EU company
CPAfirm registered in the USA
ISO 27001accredited certification body
CECyber Essentials certification body
3–6months typical to Type 1
Our accreditations and licences
CPA

US CPA firm

The BALTUM group's CPA firm registered in the USA with licensed CPA auditors. Issues SOC 1, SOC 2 and SOC 3 reports under AICPA standards (SSAE 18).

ISO

ISO/IEC 27001 certification body

Accredited certification body for information security management systems. Certificates are recognised internationally.

CE

Cyber Essentials certification body

We assess and issue Cyber Essentials and Cyber Essentials Plus certificates under the UK NCSC scheme.

UA

Compliance consulting

Ukrainian consulting team: SOC 2 readiness, ISO 27001 implementation, GDPR and NIS2. Separate from the auditors — to keep the assessment independent.

SOC 2

What SOC 2 is and why a Ukrainian company needs it

SOC 2 (System and Organization Controls 2) is an independent auditor's report on how a company protects customer data. It was developed by the American Institute of CPAs (AICPA) and it is what US and Canadian buyers ask for from SaaS vendors, cloud services, software outsourcing and data-processing providers.

For a Ukrainian IT company SOC 2 is the ticket to enterprise customers: without a report the deal is often blocked by the buyer's security team at due diligence. The report shows that your controls operate across the five Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.

An important detail: SOC 2 is not a certificate you can buy. Only a licensed CPA firm can sign the report. The BALTUM group includes a US-registered CPA firm with licensed CPA auditors — so you get readiness and the report in one place, with a fixed price before you start. Readiness and the audit are performed by separate teams, as AICPA independence rules require.

Who needs SOC 2

  • SaaS and cloud products selling into the US and Canada
  • Outsourcing and outstaffing companies with access to client data
  • Fintech, healthtech, HR-tech and platforms handling personal data
  • Start-ups moving upmarket or preparing for a funding round
  • Data centres, MSPs and managed-service providers

Read more: what is SOC 2 →

Service packages

Four packages for different customer requirements

Every package includes SOC 2 readiness and the audit by the BALTUM group's CPA firm. Choose based on the markets you sell to. Each service can also be ordered separately.

SOC 2
Type 1 or Type 2
  • Scoping and a fixed audit quote from the CPA firm
  • Gap analysis against the selected TSC
  • Policy and procedure set
  • Cloud technical-control configuration
  • Control and evidence matrix, System Description
Pricing on request
Type 1: 3–5 months · Type 2: 6–15 months
Choose package →
Most popular
SOC 2 + ISO 27001
two markets — one project
  • Everything in the SOC 2 package
  • ISMS scope, risk assessment and treatment
  • Statement of Applicability across 93 ISO 27001:2022 controls
  • Single TSC ↔ Annex A mapping matrix
  • Internal audit and management review
Pricing on request
5–8 months to both documents (Type 2 per its observation period)
Choose package →
SOC 2 + ISO 27001 + GDPR + Cyber Essentials
full coverage US · EU · UK
  • Everything in SOC 2 + ISO 27001
  • Records of processing, DPA/SCC, GDPR policies and procedures
  • Data-subject rights and breach-response procedures
  • Device inventory and alignment to the 5 Cyber Essentials controls
  • Self-assessment and Cyber Essentials verification support (Plus if needed)
Pricing on request
6–9 months to the full set
Choose package →
SOC 2 + ISO 27001 + GDPR + Cyber Essentials + NIS2
maximum: US · EU · UK · critical infrastructure
  • Everything in SOC 2 + ISO 27001 + GDPR + Cyber Essentials
  • NIS2 applicability and supply-chain role assessment
  • Mapping of the 10 Art. 21 NIS2 measures to ISO 27001 / SOC 2 controls
  • Incident notification procedures (24 h / 72 h / 1 month)
  • Supply-chain security and vendor assessment
Pricing on request
7–10 months to the full set
Choose package →

Every service is also available on its own

How the project runs

How a SOC 2 project with BALTUM runs

Scoping and quote

We define the system, TSC categories and report type. Our CPA auditors quote a fixed audit fee from five inputs.

Gap analysis

We compare current processes to the TSC and produce a remediation plan with owners and deadlines.

Control implementation

Policies, procedures, cloud configuration, access management, logging, incident and vendor management.

Evidence collection

We set up evidence collection (manually or via an automation platform) and run an internal readiness review.

CPA audit

The independent audit team of the group's US CPA firm performs the examination; consultants help with the System Description and auditor requests.

Report and support

You receive the SOC 2 report. For Type 2 we maintain controls through the observation period and prepare the bridge letter.

BALTUM

Why BALTUM

We don't sell a 'certificate' — we build a system

We work to the AICPA TSC and ISO 27001. Controls are designed to actually operate in your infrastructure, not just on paper.

Our own US CPA firm

SOC 2 reports are issued by the BALTUM group's US-registered CPA firm with licensed CPA auditors. No intermediaries: you know the audit fee before signing, and the report is accepted in the US and Canada.

One system — several standards

SOC 2, ISO 27001, GDPR and Cyber Essentials share a common control core. We map requirements to each other so your team never does the same work twice.

Accredited certification body

The group includes an internationally accredited ISO/IEC 27001 certification body and a Cyber Essentials certification body. Certificates accepted in Europe and the UK — from one source.

Your language, your time zone

Project team in Ukraine, contract with Baltum Büroo OÜ (Estonia). Telegram, online meetings, documents in Ukrainian or English.

Support after the report

A SOC 2 report lives 12 months. We keep controls healthy, prepare the annual Type 2 and help answer customer security questionnaires.

Frequently asked questions

How long does a SOC 2 project take?
Type 1 usually takes 3–6 months from kick-off to report depending on process maturity. Type 2 adds an observation period of 3–12 months (most often 6) during which controls must operate continuously.
How much does SOC 2 cost in Ukraine?
Two components: readiness (BALTUM) and the audit (CPA firm). The audit fee is fixed from five inputs: headcount, nature of the service, infrastructure, data types, report type and TSC categories. As a guide, a Type 1 audit for a small company ranges from a few thousand to ~20k USD; Type 2 is higher. Fill in the form for an exact figure.
Who issues the SOC 2 report?
Only a licensed CPA firm (USA). The BALTUM group has its own US-registered CPA firm with licensed CPA auditors — it performs the examination and signs the report. Readiness is delivered by a separate consulting team to preserve auditor independence.
Can we go straight to Type 2 and skip Type 1?
Yes. If controls have been operating for several months you can go straight to Type 2. Many companies get Type 1 first to close a deal and Type 2 six months later.
Can we order only ISO 27001, GDPR or NIS2 without SOC 2?
Yes. Every service is available separately: ISO 27001 certification by the accredited body, a GDPR package, Cyber Essentials or NIS2 compliance. Packages simply save time and budget through shared controls.
Do we need SOC 2 if we have ISO 27001?
It depends on your customers. US buyers usually ask for SOC 2, European ones for ISO 27001. The standards overlap by roughly 70–80 %, so the second one is much cheaper than the first.
Which clouds do you work with?
AWS, Google Cloud, Azure, Hetzner, DigitalOcean, plus hybrid and on-prem environments. Inherited cloud-provider controls are reflected in the responsibility matrix.

All questions →

Blog

Blog: SOC 2, ISO 27001 and compliance for Ukrainian tech

2026-08-18

SOC 2 Trust Services Criteria Explained: The Five Criteria and How to Scope Them

The TSC are the foundation of every SOC 2 report. We explain what each of the five criteria means, which controls sit behind them and how to define your audit scope.

Read more →
2026-08-10

After the SOC 2 Report: Bridge Letters, Observation Periods and Continuous Compliance

A SOC 2 report has a shelf life. We explain what a bridge letter is, how to plan your next observation period and what to do monthly, quarterly and annually so the next audit has no surprises.

Read more →
2026-08-08

SOC 2 vs ISO 27001: A Practical Comparison for IT and SaaS Companies

SOC 2 is an attestation report for the US market; ISO 27001 is an international certificate. We compare structure, cost and timelines and explain when to do both.

Read more →

All articles →

SOC 2

Get a fixed-fee SOC 2 quote

Five fields — exactly what our CPA auditors need to quote a fixed audit fee. We reply within one business day.

By submitting you agree to our privacy policy.