AWS Logging & Audit Foundation
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
The AWS half of a SOC 2 readiness effort, built so the evidence generates itself.
From $1,399
Typically $1,399–$3,999, fixed in writing before anything starts.
What moves it up
SOC 2 is not a technical standard, and treating it as one is what makes the first audit expensive. A Type II report is an auditor observing that your controls operated over a period — typically three to twelve months — so a control implemented the week before fieldwork has no evidence behind it and does not count. The specific thing that goes wrong on the AWS side is that everything is configured correctly and nothing records that it stayed configured correctly. Access reviews happened in a conversation, change approvals live in someone's memory, and the auditor asks for a quarter of screenshots nobody took.
aws configservice describe-config-rules — whether compliance is continuously evaluated or periodically rememberedaws securityhub get-findings against the AWS Foundational Security Best Practices standardaws iam generate-credential-report as the access review artefact, dated and stored rather than read and discardedChange history in CloudTrail correlated to approvals, which is the pairing auditors ask for firstNo. Only a licensed CPA firm can issue a SOC 2 report, and I am not one. What I can do is build and evidence the AWS technical controls so that the auditor's infrastructure questions have real answers, which is usually the part engineering teams are least ready for.
Before the observation period starts, not before fieldwork. A Type II report observes controls operating over months, so anything implemented the week before is a control with no history — and that is the single most common and most expensive scheduling mistake.
They are genuinely useful for policies, training, vendor management and chasing people. They also raise alerts that need real infrastructure work to clear, which is where this fits. A platform on its own produces a list of things nobody has done.
Security in full on the infrastructure side, and most of Availability and Confidentiality. Processing Integrity and Privacy are largely about your application and your business processes rather than your cloud, and the gap list says so explicitly rather than implying coverage that is not there.
A record of who did what, kept long enough to be useful and somewhere it cannot be edited.
From $299 2–4 days
The technical controls a HIPAA workload needs on AWS, built and documented. Not a certification.
From $1,149 7–15 days
Tell me what you are running and I will come back with a fixed price and a date. If it turns out you do not need this, I will say that instead.
Prefer to talk? Book a free call ↗ · Or hire me on Upwork ↗ · Typical reply within one business day.
Sunday to Thursday, 09:00–18:00 EET. Outside that I will still look, but I will not promise a time.
One person, one time zone. If round-the-clock cover is what you need, you need a team, and I will say so rather than sell you a plan that cannot deliver it.
You pay Amazon directly and you keep control of the account. Nothing here resells your infrastructure or sits between you and your own billing.
Every service page lists exactly what pushes a quote above it, before you ask. You get a fixed number in writing before any work begins.