Viktor Culjak | SOC 2 readiness consulting

SOC 2 without the scramble.

I help companies get audit ready on the first pass, so a security review stops being the reason a deal sits still.

Formerly KPMG IT Advisory  ·  Diligent  ·  Galvanize

Viktor Culjak

15+

Years in audit, risk and compliance

4.5

Years at KPMG in IT advisory

The situation

The deal is waiting on a report you don't have.

SOC 2 rarely shows up on a roadmap. It shows up in a procurement email, with a date attached.

Enterprise buyers are asking for it.

A security questionnaire landed mid deal. Now the close date depends on a report nobody internally has been through before.

Nobody owns compliance yet.

There is no security lead, and the work quietly lands on engineering, who already have a roadmap they are behind on.

You started and it stalled.

A tool got bought, some policies got written, and the gap between that and an actual audit turned out to be wider than expected.

The engagement

Three phases, one outcome.

A defined scope with a defined end. You come out of it audit ready, with the evidence already in place.

PHASE 01

Readiness assessment

We map your current state against the Trust Services Criteria and agree the scope. You get a gap list that is ranked by what an auditor will actually flag, not a generic checklist.

PHASE 02

Remediation, side by side

Policies, controls and process, built to fit how your team already works. I write what needs writing and sit with your engineers on the rest, so nothing gets designed that nobody will follow.

PHASE 03

Audit handoff

Evidence organised, walkthroughs rehearsed, auditor questions anticipated. I stay in the room through fieldwork so requests do not pile up on your team.

One thing worth saying plainly. I am not your auditor, and that is deliberate. An independent CPA firm issues the report. My job is to make sure that when they arrive, there is nothing left to find.

Who this is for

A good fit if...

  • You are going through SOC 2 for the first time and want it done once, properly.
  • A named enterprise deal is waiting on the report and the timeline is real.
  • You want your engineers building product, not learning control frameworks.
  • You would rather hear what is actually broken than be told it will be fine.

About

Viktor Culjak

Viktor Culjak

I have spent about fifteen years on the inside of audit and controls work, most of it looking at the same question from different chairs.

I started at KPMG in IT advisory, running information systems audits and testing controls across SAP, Oracle and PeopleSoft environments, including SOC engagements. From there I moved into risk and controls at a public company, then spent seven years at GRC software companies helping compliance teams actually run the programs they had bought tools for.

What that adds up to is a fairly unglamorous kind of usefulness. I know what auditors ask for, I know what they do with the answer, and I know which controls look tidy on paper and fall apart in fieldwork.

I went independent in 2025 and work with a small number of companies at a time, out of Vancouver, across North America.

Based inVancouver, serving clients across the US and Canada
BackgroundKPMG IT Advisory, Diligent, Galvanize

Contact

Start with ashort conversation.

Twenty minutes. Tell me where you are, what is forcing the timeline, and I will tell you honestly whether I am the right person for it.

Vancouver, BC  ·  Remote across North America

© 2026 VJC Advisory. All rights reserved. LinkedIn