Compliance · Security and trust

SOC 2, operating, not just designed.

An independent auditor's report on how your security, availability, confidentiality, processing-integrity and privacy controls operated over a period — the report US enterprise buyers ask for.

  • 5Trust Services Criteria
  • 3–12 moobservation period
  • CPAindependent auditor
What it is

AICPA System and Organization Controls 2 — Type II report

SOC 2 is an attestation framework from the American Institute of CPAs. A licensed CPA firm examines the controls a service organisation has put in place against the Trust Services Criteria and issues a report. A Type I report describes control design at a point in time; a Type II report tests whether the controls operated effectively across an observation period, usually three to twelve months — which is why customers ask for Type II.

Security — the Common Criteria — is mandatory; Availability, Processing Integrity, Confidentiality and Privacy are added as your service warrants. The criteria are principle-based, so you define the controls that meet them, which gives flexibility and puts the burden on you to prove they ran.

Unlike ISO 27001, SOC 2 is not a certificate: the deliverable is a confidential report shared with customers under NDA, containing the auditor's opinion, a description of your system, the controls tested and any exceptions. A clean Type II report is the fastest way through a US enterprise procurement.

The requirements

What the framework demands

The obligations an auditor or supervisor will test, in plain language.

Common Criteria — Security (CC1–CC9)

Control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management and risk mitigation.

Logical and physical access (CC6)

Provisioning and de-provisioning tied to HR events, least privilege, MFA, encryption, and protection of facilities and media.

System operations and incident response (CC7)

Vulnerability detection, monitoring and alerting, incident response and recovery — all with evidence that they ran.

Change management (CC8)

Authorised, tested, documented and approved changes across infrastructure and code, with segregation of duties.

Availability criteria (A1)

Capacity planning, backups, environmental protections and recovery testing when you commit to uptime.

Confidentiality and Processing Integrity (C1, PI1)

Identifying, protecting and disposing of confidential information; complete, accurate, timely and authorised processing where you promise it.

Privacy criteria (P1–P8)

Notice, choice and consent, collection, use and retention, access, disclosure, quality and monitoring for personal information — often aligned with GDPR work.

What's at stake

The cost of getting it wrong

  • Stalled enterprise deals — many US buyers will not sign without a current Type II report
  • Weeks lost to bespoke security questionnaires for every prospect
  • Qualified opinions or exceptions in the report that customers read closely
  • A report that goes stale — most customers expect one no older than twelve months
Typical timeline2–3 months of readiness, then a 3–12 month observation period before the Type II report
How we help

From gap to evidence

Assessment, remediation, documentation and audit support — run as one programme.

  1. 01

    Readiness assessment and criteria selection

    We pick the Trust Services Criteria that match your commitments, map your controls to them and identify gaps before any auditor sees them.

  2. 02

    Control design and tooling

    We implement missing controls — access reviews, change management, monitoring, vendor management — and set up evidence collection so proof accumulates automatically.

  3. 03

    Policies and system description

    The policy set and the system description the auditor works from, written to reflect how you actually operate.

  4. 04

    Observation-period management

    During the window we run the controls with you, review evidence monthly and fix drift before it becomes an exception.

  5. 05

    Audit coordination

    We select and coordinate with the CPA firm, handle sampling requests and walk-throughs, and address any findings before the report is issued.

What you get

Deliverables

  • Readiness assessment and control-gap report
  • Control matrix mapped to the selected Trust Services Criteria
  • Policy set and system description
  • Evidence-collection process and repository
  • Monthly control-health reviews through the observation period
  • Audit coordination and findings remediation
  • Bridge letter and annual re-examination support
FAQ

Questions we hear most

Type I or Type II?

Type I proves controls are suitably designed at a date; Type II proves they operated over a period. Buyers ask for Type II. Many companies do a Type I first to unblock deals while the Type II window runs.

How long is the observation period?

Between three and twelve months. A first report often uses three to six months; renewals typically cover a full year so there is no gap between reports.

Is SOC 2 a certification?

No — it is an attestation report with an auditor's opinion, shared under NDA. There is no SOC 2 badge-issuing authority; the value is the independent CPA firm's signature.

Can we reuse our ISO 27001 work?

Largely, yes. The Security criteria overlap heavily with ISO 27001 Annex A. We maintain one control set and one evidence process that feeds both the certificate and the report.

Get Started

Ready to Transform Your Business?

Let's discuss how our expertise in IT security, development, and DevOps can help you achieve your goals.