One of our clients is demanding that we complete a SOC 2 Type II audit. There is no way we will meet the standard, and, considering we only handle publicly available data, it is ridiculous that they are asking for one. We're talking about 6-8 Excel files per year that represent a very small but critical part of our business. Unfortunately, we have no choice but to comply.
I am looking for some guidance on how to bring our systems up to standard. I handle our internal IT via google search, most of our services are cloud-based, and we contract for support as needed on our internal server.
We need someone to manage the changes and documentation of our systems for the auditors. The company we contract with for IT support wants no part of this. We can't hire a full-time IT person, but we could hire a contract employee to carry us through this process.
Would it be better to hire an individual on a contract basis, or to contract with an IT company? Where would I even find a company to handle this sort of thing? Any help is greatly appreciated.