Compliance · Security and trust
SOC 2, operating, not just designed.
An independent auditor's report on how your security, availability, confidentiality, processing-integrity and privacy controls operated over a period — the report US enterprise buyers ask for.
- 5Trust Services Criteria
- 3–12 moobservation period
- CPAindependent auditor
AICPA System and Organization Controls 2 — Type II report
SOC 2 is an attestation framework from the American Institute of CPAs. A licensed CPA firm examines the controls a service organisation has put in place against the Trust Services Criteria and issues a report. A Type I report describes control design at a point in time; a Type II report tests whether the controls operated effectively across an observation period, usually three to twelve months — which is why customers ask for Type II.
Security — the Common Criteria — is mandatory; Availability, Processing Integrity, Confidentiality and Privacy are added as your service warrants. The criteria are principle-based, so you define the controls that meet them, which gives flexibility and puts the burden on you to prove they ran.
Unlike ISO 27001, SOC 2 is not a certificate: the deliverable is a confidential report shared with customers under NDA, containing the auditor's opinion, a description of your system, the controls tested and any exceptions. A clean Type II report is the fastest way through a US enterprise procurement.
What the framework demands
The obligations an auditor or supervisor will test, in plain language.
Common Criteria — Security (CC1–CC9)
Control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management and risk mitigation.
Logical and physical access (CC6)
Provisioning and de-provisioning tied to HR events, least privilege, MFA, encryption, and protection of facilities and media.
System operations and incident response (CC7)
Vulnerability detection, monitoring and alerting, incident response and recovery — all with evidence that they ran.
Change management (CC8)
Authorised, tested, documented and approved changes across infrastructure and code, with segregation of duties.
Availability criteria (A1)
Capacity planning, backups, environmental protections and recovery testing when you commit to uptime.
Confidentiality and Processing Integrity (C1, PI1)
Identifying, protecting and disposing of confidential information; complete, accurate, timely and authorised processing where you promise it.
Privacy criteria (P1–P8)
Notice, choice and consent, collection, use and retention, access, disclosure, quality and monitoring for personal information — often aligned with GDPR work.
The cost of getting it wrong
- Stalled enterprise deals — many US buyers will not sign without a current Type II report
- Weeks lost to bespoke security questionnaires for every prospect
- Qualified opinions or exceptions in the report that customers read closely
- A report that goes stale — most customers expect one no older than twelve months
From gap to evidence
Assessment, remediation, documentation and audit support — run as one programme.
- 01
Readiness assessment and criteria selection
We pick the Trust Services Criteria that match your commitments, map your controls to them and identify gaps before any auditor sees them.
- 02
Control design and tooling
We implement missing controls — access reviews, change management, monitoring, vendor management — and set up evidence collection so proof accumulates automatically.
- 03
Policies and system description
The policy set and the system description the auditor works from, written to reflect how you actually operate.
- 04
Observation-period management
During the window we run the controls with you, review evidence monthly and fix drift before it becomes an exception.
- 05
Audit coordination
We select and coordinate with the CPA firm, handle sampling requests and walk-throughs, and address any findings before the report is issued.
Deliverables
- Readiness assessment and control-gap report
- Control matrix mapped to the selected Trust Services Criteria
- Policy set and system description
- Evidence-collection process and repository
- Monthly control-health reviews through the observation period
- Audit coordination and findings remediation
- Bridge letter and annual re-examination support
Questions we hear most
Type I or Type II?
Type I proves controls are suitably designed at a date; Type II proves they operated over a period. Buyers ask for Type II. Many companies do a Type I first to unblock deals while the Type II window runs.
How long is the observation period?
Between three and twelve months. A first report often uses three to six months; renewals typically cover a full year so there is no gap between reports.
Is SOC 2 a certification?
No — it is an attestation report with an auditor's opinion, shared under NDA. There is no SOC 2 badge-issuing authority; the value is the independent CPA firm's signature.
Can we reuse our ISO 27001 work?
Largely, yes. The Security criteria overlap heavily with ISO 27001 Annex A. We maintain one control set and one evidence process that feeds both the certificate and the report.
Often pursued together
Ready to Transform Your Business?
Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.