Compliance-Ready Engineering — SOC 2 & ISO 42001
Enterprise deals stall on the security questionnaire. I put the systems, access, and logging into the shape an auditor needs to see, with the evidence produced by the controls themselves — so you pass the audit without freezing delivery for a quarter.
Compliance-ready engineering is the work that happens before an audit: access, logging, change management, and vendor review built so that every control leaves its own trail, plus policies that describe what the systems actually do. Oleg Sotnikov leads the engineering side of it — closing the gaps a SOC 2 compliance audit or an ISO/IEC 42001 assessment will look for and wiring evidence collection into systems that are already running. The certification audits themselves are performed by vetted partner audit firms, introduced during the engagement.
What Readiness Is Made Of
Six work streams. Most teams arrive with half of them running informally and no record that they ran at all.
Gap assessment
A read of where you stand against the framework you are targeting — the SOC 2 trust services criteria, or the ISO/IEC 42001 clauses when AI governance is what buyers ask about. The output is a gap list with owners and effort estimates, not a maturity score.
Access control done right
Roles instead of shared accounts, every grant logged, and access that is genuinely revoked when someone leaves. Offboarding is where audits find the most embarrassing gaps, and it is cheap to fix before anyone looks.
Evidence automation
A control that leaves its own trail costs nothing at audit time. Identity provider logs, CI deploy records, branch protection, ticket history — wired so the evidence exists before it is requested, instead of a quarter of screenshot archaeology.
SDLC controls that don't slow shipping
Code review, CI gates, and change management written the way your team already works, then enforced by the tooling. An auditor needs to see that changes are reviewed and traceable; nobody is asking you to convene a change advisory board.
Vendors and data flows
Which subprocessors touch customer data, what they are contractually on the hook for, and where that data physically sits. Nearly every questionnaire asks this, and most companies answer it from memory.
A named security owner
vCISO-style ownership: one senior name on the security questions in your deals, on the risk register, and on the call about what gets fixed first. Part-time, and for exactly as long as you need it.
From Gap List to Audit
Gap assessment
A structured look at access, logging, infrastructure, SDLC, and vendors against the framework you are targeting. You end with a written gap list, a priority order, and an honest estimate of the work in front of you.
Remediation sprint
Engineering fixes in priority order, with evidence collection wired in as each control lands. Your team does the work with me, or I do it — either way the controls end up inside the systems, not inside a document.
The audit
A vetted partner audit firm runs the certification work; I introduce you during the engagement. My seat is on your side of the table: evidence prepared, questions answered, nothing discovered on the day.
Why Me
- 25+ years building systems that enterprise security teams reviewed before their company would sign anything
- AppMaster runs at 99.99% uptime for users in 190+ countries — the operational discipline auditors look for, in production rather than on a slide
- 45+ professional certifications of my own, so exams, evidence, and independent examiners are familiar ground; an audit is the same ritual, except the company sits the exam
Where to Go Next
Adjacent parts of the same problem.
Frequently Asked Questions
Do you perform the SOC 2 audit yourself?
No. A SOC 2 report is issued by an independent audit firm, and the firm that audits you cannot be the one that built your controls. My part is the engineering: closing gaps, wiring evidence collection, and getting policies to match what the systems do. Vetted partner audit firms handle the certification and are introduced during the engagement — my job is to make the audit boring.
SOC 2 or ISO 42001 — which one do we need?
SOC 2 is a report on how you handle security and customer data, and it is what enterprise buyers in the US put in front of you during procurement. ISO/IEC 42001 is a management-system standard for how a company governs AI, and it surfaces when a model makes decisions inside your product. Selling software to US enterprises usually means SOC 2 first; if AI is the part buyers keep probing, run ISO 42001 alongside it, since the underlying control work overlaps heavily.
What is a vCISO?
A vCISO is a virtual, or fractional, chief information security officer — a senior security owner who works part-time for you. They take the security questions inside your deals, own the risk register, and decide what gets fixed first. It fits companies that need one accountable name and a defensible answer rather than a security department, and it is the mode I work in when the real task is getting the engineering into audit shape.
How long does SOC 2 readiness take?
It is a function of the gap, and any timeline quoted before someone looks is a guess. A team with single sign-on, centralized logging, and enforced code review has weeks of work ahead; a team running on shared credentials with evidence living in screenshots has months. The gap assessment exists to turn that into a date. A Type 2 report also covers an observation window, so calendar time is added after the engineering is finished.
Will compliance slow my engineering team down?
That depends entirely on how the controls are built. Controls that emit their own evidence — access changes logged by the identity provider, deploys recorded by CI, review enforced through branch protection — cost the team almost nothing once they are set up. Controls built as a manual ritual, with someone collecting screenshots every quarter, create permanent overhead and produce weaker evidence. I build the first kind.
Get Ahead of the Security Questionnaire
A call covers what you sell, which framework your buyers keep asking about, and how far your systems sit from it today.
Engineering readiness is my work. Certification audits are run by vetted partner firms, introduced during the engagement.
Related reading
Security controls, audit evidence, and engineering that holds up when someone checks.


