# Risk and Response > Risk and Response is a compliance-readiness consultancy that prepares companies for SOC 2, ISO 27001, and HIPAA audits. We assess security posture, close gaps, implement policies and controls, organize audit evidence, and support teams through audit day. We work hands-on in GRC platforms including Drata and Vanta. Founded by Jonathan Major (25+ years in engineering, information security, and compliance). Contact: info@riskandresponse.com. Key facts: - SOC 2 readiness covers all five Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy). Typical engagement: about 3 months for a first-time SOC 2, billed at $5,000 per month; annual renewal preparation takes 2–4 weeks. The CPA firm's audit fee and GRC platform license are separate. SOC 2 is an attestation issued by a licensed CPA firm, not a certification. - ISO 27001 readiness covers ISMS core requirements (Clauses 4–10) and all 93 Annex A controls under ISO 27001:2022. Typical engagement: 6–12 weeks for initial certification, 2–4 weeks for surveillance audit preparation. - HIPAA readiness covers the Security Rule, Privacy Rule, and Breach Notification Rule, including BAA support and risk analysis per NIST SP 800-30. Typical engagement: 6–10 weeks for an initial program build. There is no official HIPAA certification. - Every engagement follows a 5-step process: assessment and gap analysis, remediation planning, policy and control implementation, evidence collection and documentation, readiness review and audit support. - Risk and Response performs readiness only — an independent CPA firm or certification body performs your audit. Sister practice: Internal Audit Service (https://internalauditservice.com) performs independent ISO 27001, ISO 42001, and ISO 9001 internal audits, delivered by the same team. ## Services - [SOC 2 Readiness](https://riskandresponse.com/soc-2): What SOC 2 is, Type I vs. Type II, the five Trust Services Criteria, the 5-step readiness process, typical timeline and pricing (about 3 months first-time at $5,000/month, 2–4 weeks renewal), Drata/Vanta platform experience, and a SOC 2 FAQ. - [ISO 27001 Readiness](https://riskandresponse.com/iso-27001): ISMS build and maturation for ISO 27001:2022 — Clauses 4–10 plus all 93 Annex A controls; 6–12 weeks initial, 2–4 weeks surveillance preparation; includes an ISO 27001 FAQ covering Stage 1 vs. Stage 2 audits and the Statement of Applicability. - [HIPAA Readiness](https://riskandresponse.com/hipaa): Administrative, physical, and technical safeguards for the Security Rule, Privacy Rule, and Breach Notification Rule, plus BAA support and NIST SP 800-30 risk analysis; 6–10 weeks initial build; includes a HIPAA FAQ. - [Internal Audit](https://riskandresponse.com/internal-audit): Independent internal audits for ISO 27001, ISO 42001, and ISO 9001 using a remote-first, evidence-based methodology based on ISO 19011. ## Guides - [Compliance Guides](https://riskandresponse.com/resources): Plain-English explainers — What is SOC 2 (Trust Services Criteria, Type I vs. Type II), What is ISO 27001 (ISMS, Annex A, Stage 1/Stage 2 certification), What is HIPAA (the three rules, why there's no HIPAA certification), and SOC 2 vs. ISO 27001 comparison. ## Case Studies - [Case Studies](https://riskandresponse.com/case-studies): How Bitvore Corp, an AI analytics SaaS company, built a SOC 2 program from scratch with Risk and Response — a Type I report about three months after kickoff, then two annual Type II examinations — managed on the Drata platform. ## Company - [About](https://riskandresponse.com/about): Jonathan Major, founder — 25+ years in engineering, information security, and compliance; previously at BlackRock, Barclays Global Investors, and IBM. - [Schedule a Call](https://riskandresponse.com/schedule): Book a 30-minute compliance-readiness scoping call. - [Contact](https://riskandresponse.com/contact): Email info@riskandresponse.com or send a message. ## Optional - [Privacy Policy](https://riskandresponse.com/privacy): How Risk and Response collects, uses, and protects personal information. - [Internal Audit Service](https://internalauditservice.com): Sister site — independent ISO internal audit practice from the same team.