Report an Incident Become a Partner Careers Contact
Book a Demo
Risk & compliance · SOC 2

Your customer will not sign
without it.

SOC 2 is rarely something a company wants. It is something an enterprise customer demands before they will close, usually with a deadline attached. We get you ready for the audit, hold the evidence, and sit with you through it.

Type II windowmonth 7 of 12
SCOPESecurity + confidentiality criteriaagreed
GAPReadiness assessment, 14 findingsclosed
SOCIncidents investigated and recordeddated
ACCESSQuarterly reviews, evidencedon file
DRIFTControl stopped producing evidenceflagged
CPAReport issued by a licensed CPA firmnot us
What SOC 2 actually is

An attestation,
not a certificate.

Worth getting the vocabulary right early, because the difference decides who you need and what you are buying.

SOC 2 is a report produced under AICPA standards in which an independent licensed CPA firm gives an opinion on whether your controls meet the Trust Services Criteria. Security is always in scope; availability, processing integrity, confidentiality and privacy are added depending on what you do and what your customers ask for.

People commonly call it SOC 2 certification. There is no such thing, and it matters: a certificate is awarded against a standard, whereas an attestation is somebody qualified giving a professional opinion on evidence. Nobody can sell you a SOC 2 certificate, and anybody offering one is worth a second look.

  • Type I: an opinion on whether the controls are designed properly, at a point in time.
  • Type II: an opinion on whether they actually operated, across a defined window.
  • Security is mandatory. The other four criteria are scoped to your business.
  • The report is issued by a licensed CPA firm, independent of whoever built the controls.
  • Most enterprise buyers want Type II. Type I is a staging post, not a destination.
Where SOC 2 programmes fail

Type II is not a snapshot.
It is a period.

Type I asks whether the controls are designed well. Type II asks whether they ran, every day, for three to twelve months. Almost everything that goes wrong goes wrong there.

The trap is that you cannot retrofit an observation window. When the auditor asks for evidence that access reviews happened quarterly, that incidents were investigated and closed, that monitoring was actually running, they want records from across the period. If nobody was operating anything, that evidence has to be assembled after the fact, and assembled evidence is exactly what an experienced auditor is trained to notice.

Where we run your SOC, that record already exists. Investigation timelines, incident closure statements, response actions, detection coverage and tuning history are produced because the work happened, not because somebody went looking for proof in month eleven. That is the difference between a clean Type II and an uncomfortable one.

How the SOC produces it

Evidence with a date on it
Records generated as the work happened, across the whole window, rather than exported the week the auditor asked.
Incident and response history
What fired, what was investigated, what was done and when it closed. That answers a whole family of criteria directly.
Monitoring you can prove
Coverage, detections and tuning history, which is the difference between saying you monitor and showing it.
Supplier oversight
The vendor criteria are answered by a supplier register, tiering rationale and assessment records rather than by a policy document.
How it runs

Scoped, closed,
observed, attested.

A programme with a shape and an end, rather than an open-ended engagement that bills monthly until the auditor turns up.

  1. 01

    Scope it

    Which Trust Services Criteria apply, which systems are in scope, and Type I or Type II. Getting this wrong is the most expensive mistake available, because scope drives everything after it.

  2. 02

    Find the gaps

    A readiness assessment against the criteria, producing a gap list with an order of work rather than a list of everything that is imperfect.

  3. 03

    Close them

    Controls built and documented, with our consultants on the judgement calls. Where we run your SOC, several of the operational criteria are already satisfied.

  4. 04

    Run the window

    For Type II, the observation period, with evidence collected continuously rather than gathered at the end. This is the part that cannot be rushed or backdated.

  5. 05

    Face the auditor

    We work alongside the CPA firm through fieldwork, produce the artefacts and answer the questions. The opinion is theirs; the preparation is ours.

What drives the cost and the timeline

Nobody can quote you
without the scope.

It is the first question everybody asks and the one most suppliers answer with a number that stops meaning anything the moment scope is agreed.

Type I or Type II
Type I is a design opinion and is quicker. Type II requires an observation window, which sets a floor on the timeline that no amount of budget shortens.
How many criteria
Security alone is a considerably smaller exercise than security plus availability, confidentiality and privacy. Add what your customers actually ask for, not everything.
The observation window
Typically three to twelve months. Shorter windows are cheaper and some enterprise buyers will not accept them, so this is a commercial decision rather than a technical one.
Where you are starting
An organisation already running monitoring, access reviews and incident response is a long way in. One starting from nothing is doing the security work and the compliance work at once.
The audit itself
Billed by the CPA firm, separately from us. We will tell you roughly what to expect and introduce you to firms we have worked with, and you appoint them.

We scope it, then quote it. A number offered before that is a guess dressed up as a proposal.

Questions

SOC 2, answered.

Can you do our SOC 2 audit?

No, and neither can any other security provider. A SOC 2 report is issued by an independent licensed CPA firm, and the firm attesting your controls must not be the one that built them. We get you audit-ready, hold the evidence and sit with you through fieldwork.

Is SOC 2 a certification?

No. It is an attestation report giving a qualified opinion on evidence, not a certificate awarded against a standard. The distinction matters commercially: nobody can sell you a SOC 2 certificate, so an offer of one tells you something about the supplier.

What is the difference between Type I and Type II?

Type I says the controls were designed properly on a given date. Type II says they actually operated across a window, usually three to twelve months. Most enterprise customers want Type II, and Type I is best treated as a staging post rather than the destination.

How long does SOC 2 take?

Readiness commonly takes two to four months depending on the starting point, then the Type II observation window runs three to twelve months, then fieldwork and the report. The window is the part no budget can shorten, which is why scoping early matters.

How much does it cost?

It depends on scope: Type I or II, how many Trust Services Criteria, the length of the window and how much already exists. The CPA firm bills separately for the audit. We scope it before quoting, because a number without a scope behind it is guesswork.

We already have ISO 27001. Does that help?

Considerably. The control sets overlap heavily, so it becomes a gap exercise rather than a second programme. The usual difference is evidence: SOC 2 Type II wants proof of operation across a period, which ISO certification does not demand in the same form.

Which Trust Services Criteria do we need?

Security always. Beyond that, take what your customers actually ask for. Availability suits anyone selling uptime, confidentiality anyone handling customer data under contract, privacy anyone handling personal information. Adding all five because they exist makes the audit larger and slower for no commercial gain.

Do we need you to run our SOC as well?

No, and the readiness work stands alone. It is materially easier where we do, because Type II evidence is then produced by the service across the window rather than collected by your team. We will be clear about which version you are buying.

Where to start

Tell us the deadline
and which customer set it.

Type II has an observation window that no budget shortens, so the earlier we scope it the more options you have. If the date is not achievable we will say so rather than take the work.