Sample deliverable
Sample SOC 2 Gap Assessment Report
See exactly what a gap assessment client receives — readiness scorecard, severity-rated
findings mapped to the Trust Services Criteria, and a wave-sequenced remediation roadmap,
prepared for an illustrative SaaS company.
- Readiness scorecard across ten control domains
- Six full findings — technical and governance — mapped to SOC 2 criteria and CIS Controls v8
- Executive summary and remediation waves
Read the sample report
Guide · PDF
What a CMMC assessment actually asks you to show
Most CMMC effort goes into deciding what to implement. Assessments turn on something
narrower — whether you can produce evidence that it runs.
- The three states a control can be in, and why only one survives an assessment
- What evidence looks like for AU, SI, IR, IA and AT
- Why the interview is part of the assessment, and what it catches
- Five ways good programmes still go wrong, and a thirty-day list
Download the guide (PDF)
Free, no email required
Analysis
What the 2026 Threat Data Says About the Defense Industrial Base
Huntress analysed 4.6 million endpoints during 2025. Three findings land on small
defense suppliers, and all three describe attacks that look like authorized activity.
- Attacks on manufacturing rose 88% year over year
- Abuse of remote monitoring and management tooling rose 277%
- Why adversary-in-the-middle defeats a correctly implemented MFA control
Read the analysis
Federal update
CMMC Phase 2 Suspended: What Contractors Should Do Now
On July 13, 2026 the DoD suspended the CMMC Phase 2 rollout and launched a 60-day
reform review. What was suspended, what still applies, and what to do about it.
- The November 10, 2026 third-party assessment deadline is on hold
- Phase 1 self-assessments, DFARS 252.204-7012, and NIST 800-171 still apply
- A no-regrets action list that holds up under any reform outcome
Read the analysis
Published guide
SOC 2 Readiness Checklist for SaaS
A practical, no-fluff checklist covering scoping, control implementation, and evidence
collection — read it now, no email required.
- How to define your SOC 2 scope before you start
- The control areas auditors focus on most
- What evidence to collect and how to keep it organized
Read the checklist
Founders
SOC 2 for your first enterprise deal
A practical walkthrough of what founders and growing teams should actually focus on for SOC 2,
and what can safely wait until later.
- How SOC 2 impacts sales conversations and deal timelines
- What auditors look for versus what customers usually ask
- How to prepare without overbuilding your program
Download the guide (PDF)
Free, no email required · Spanish version (PDF)
Go-to-market
Answering security questionnaires faster
Tips for using your existing compliance data to respond to customer security reviews
with less stress and fewer ad-hoc spreadsheets.
- Where to find trustworthy evidence in your compliance platform
- How to keep answers consistent across customers and deals
- When to involve engineering, IT, or leadership in the process
Download the guide (PDF)
Free, no email required · Spanish version (PDF)
Growing teams
Planning your path from SOC 2 to ISO 27001
Guidance for teams that have completed SOC 2 and are now thinking about ISO 27001,
including realistic timelines and scope decisions.
- Key differences between SOC 2 and ISO 27001
- How to reuse the work you have already done
- Which controls are most likely to need extra attention
Download the guide (PDF)
Free, no email required · Spanish version (PDF)