Skip to main content
Image coming soon

Become the go to SOC 2 practitioner at CGI

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Become the go to SOC 2 practitioner at CGI

Position yourself as the internal expert on SOC 2 assessments and lead engagements with confidence

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior technical practitioner transitioning from active architecture role, maintaining influence through advisory and compliance leadership

Who this is not for

Junior auditors, entry-level compliance staff, or practitioners outside of enterprise IT services

What you walk away with

  • Lead internal SOC 2 scoping sessions with authority
  • Map technical controls to Trust Services Criteria without external consultants
  • Produce evidence packages that pass reviewer scrutiny on first submission
  • Mentor junior staff on control implementation and testing
  • Be proactively consulted on new client requirements involving SOC 2

The 12 modules (with all 144 chapters)

Module 1. SOC 2 fundamentals in current practice
Understand how SOC 2 is applied today in firms like CGI, with emphasis on real-world control interpretation over textbook definitions.
12 chapters in this module
  1. What SOC 2 proves today
  2. Types I and II differences
  3. Trust Services Criteria breakdown
  4. Common missteps in scoping
  5. Auditor expectations now
  6. Client demand drivers
  7. Reporting package components
  8. Management assertion structure
  9. System description essentials
  10. Control design vs operation
  11. Evidence types by criteria
  12. First steps for practitioners
Module 2. Scoping systems and boundaries
Learn how to define what's in and out of a SOC 2 report with precision, avoiding overinclusion and control sprawl.
12 chapters in this module
  1. Identifying in scope systems
  2. Network perimeter definition
  3. Third party dependencies
  4. Cloud service considerations
  5. User access boundaries
  6. Data flow mapping
  7. In scope personnel
  8. Legacy system handling
  9. Change management scope
  10. Shared responsibility models
  11. Documentation standards
  12. Finalizing scope statement
Module 3. Control mapping to technical architecture
Bridge technical design to SOC 2 requirements by aligning existing systems to control objectives.
12 chapters in this module
  1. Mapping access controls
  2. Logging and monitoring alignment
  3. Change approval workflows
  4. Backup verification design
  5. Encryption in transit mapping
  6. Data retention compliance
  7. Vendor risk integration
  8. Incident response linkage
  9. BCDR plan alignment
  10. Physical security controls
  11. Configuration management
  12. Control ownership assignment
Module 4. Designing effective policies
Create enforceable, auditor-friendly policies that reflect actual operations and meet compliance expectations.
12 chapters in this module
  1. Acceptable use policy drafting
  2. Password policy standards
  3. Remote access rules
  4. Data handling classifications
  5. Incident response planning
  6. Vendor due diligence policy
  7. Backup retention schedule
  8. Change control procedure
  9. Physical access rules
  10. Encryption standards
  11. Audit logging policy
  12. Policy review cycle
Module 5. Evidence collection strategies
Build a repeatable process for gathering clean, time-stamped evidence that satisfies reviewer requirements.
12 chapters in this module
  1. Sample size guidelines
  2. Access log collection
  3. Change ticket review
  4. User provisioning proof
  5. Role-based access demo
  6. Pen test documentation
  7. Vulnerability scan results
  8. Backup success reports
  9. Incident logs
  10. Policy acknowledgment records
  11. Training completion proof
  12. Automated evidence tools
Module 6. Working with auditors
Navigate the audit process confidently by understanding reviewer expectations and communication norms.
12 chapters in this module
  1. Auditor selection criteria
  2. Pre audit briefing
  3. Request list handling
  4. Evidence submission format
  5. Follow up responses
  6. Deficiency remediation
  7. Management letter items
  8. Audit timeline expectations
  9. In person walkthroughs
  10. Remote audit logistics
  11. Report review process
  12. Final sign off steps
Module 7. System descriptions that stand up
Write clear, accurate, and auditor-approved system descriptions that minimize back and forth.
12 chapters in this module
  1. System overview drafting
  2. Infrastructure components
  3. Software and platforms
  4. Data flows
  5. Third party services
  6. Security controls summary
  7. Availability mechanisms
  8. Processing integrity notes
  9. Confidentiality safeguards
  10. Privacy commitments
  11. Change history
  12. Version control
Module 8. Control testing execution
Apply consistent testing methods to verify control operation over time without overextending resources.
12 chapters in this module
  1. Testing frequency rules
  2. Sample selection method
  3. Walkthrough technique
  4. Documentation review
  5. Observation methods
  6. Re performance testing
  7. Automated control checks
  8. Exception handling
  9. Remediation tracking
  10. Testing evidence packaging
  11. Reviewer feedback loop
  12. Continuous monitoring setup
Module 9. Managing exceptions and gaps
Address control failures proactively and maintain report integrity without panic or overcorrection.
12 chapters in this module
  1. Exception identification
  2. Risk assessment of gaps
  3. Remediation planning
  4. Compensating controls
  5. Management override logs
  6. Documentation accuracy
  7. Timeline for fixes
  8. Auditor notification
  9. Interim evidence
  10. Status tracking
  11. Follow up testing
  12. Closure verification
Module 10. Stakeholder communication plan
Keep leadership and teams informed without overloading them, ensuring alignment throughout the engagement.
12 chapters in this module
  1. Executive update rhythm
  2. Technical team briefings
  3. Legal department sync
  4. Client communication rules
  5. Status reporting format
  6. Escalation protocol
  7. Training rollout plan
  8. Change impact notices
  9. Audit progress updates
  10. Remediation tracking visibility
  11. Post audit review meeting
  12. Lessons learned session
Module 11. Building internal capability
Develop repeatable processes and mentorship frameworks to elevate team-wide SOC 2 readiness.
12 chapters in this module
  1. Training new staff
  2. Playbook creation
  3. Control ownership model
  4. Knowledge transfer sessions
  5. Internal audit prep
  6. Cross team collaboration
  7. Succession planning
  8. Tool standardization
  9. Policy maintenance
  10. Change control integration
  11. Compliance calendar
  12. Annual review cycle
Module 12. Ownership of the SOC 2 lifecycle
Take full responsibility for the end-to-end process, from planning to renewal, as the recognized internal expert.
12 chapters in this module
  1. Annual planning cycle
  2. Scope refresh triggers
  3. Team readiness check
  4. Auditor retention
  5. Internal prep schedule
  6. Evidence collection start
  7. Draft review cycle
  8. Management sign off
  9. Report distribution
  10. Client Q&A readiness
  11. Lessons learned capture
  12. Next cycle improvements

How this maps to your situation

  • When starting a new SOC 2 engagement
  • When responding to auditor requests
  • When onboarding new team members
  • When updating system descriptions

Before vs. after

Before
Reliant on external consultants for SOC 2 guidance and frequent clarification
After
Recognized internally as the go to person for SOC 2 design, evidence, and audit success

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3-4 hours per module, designed for completion over 6-8 weeks with flexibility to pause and resume.

If nothing changes
Without clear internal leadership on SOC 2, teams default to inconsistent practices, evidence collection becomes reactive, and audit cycles drag, eroding trust in internal capability.

How this compares to the alternatives

Unlike generic compliance courses, this focuses exclusively on SOC 2 execution in enterprise IT services firms, with templates and examples tailored for organizations like CGI. No other course combines technical depth with practical lifecycle ownership.

Frequently asked

Is this relevant if I'm retired but still advising?
Yes. The course is designed for experienced practitioners who influence outcomes without holding formal titles.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Does it cover both SOC 2 Type I and Type II?
Yes. The full lifecycle, including ongoing control operation for Type II, is covered in depth.
$199 one-time. Approximately 3-4 hours per module, designed for completion over 6-8 weeks with flexibility to pause and resume..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours