What SOC 2 is
SOC 2 is an attestation report on controls at a service organization. A licensed CPA firm performs the examination under AICPA attestation standards and reports against the Trust Services Criteria. The report covers a defined system: the services you provide and the infrastructure, software, people, procedures and data behind them.
Customers ask for SOC 2 during security reviews and procurement, most often when you store or process their data. A current report lets their vendor risk team review your controls in one document instead of a long questionnaire. SaaS, fintech, healthcare technology and managed service providers are often asked for one.
Trust Services Criteria and report types
Security is always in scope. You add other categories based on what you commit to customers.
Security
Required in every SOC 2 report. Covered by the common criteria: control environment, communication, risk assessment, monitoring, control activities, logical and physical access, system operations, change management and risk mitigation.
Availability
Optional. Covers capacity planning, backups, recovery and the availability commitments you make to customers.
Processing integrity
Optional. Covers whether system processing is complete, valid, accurate, timely and authorized.
Confidentiality
Optional. Covers how information designated as confidential is protected from collection through disposal.
Privacy
Optional. Covers how personal information is collected, used, retained, disclosed and disposed of in line with your privacy commitments.
Type 1
Reports on the description of your system and the suitability of the design of your controls as of a specific date.
Type 2
Adds the operating effectiveness of those controls over a review period. Many customer security reviews ask for a Type 2.
How readiness works with us
We agree the system boundary with your team: products, cloud accounts, applications, data stores, people and key vendors. We help you choose which Trust Services Criteria categories to include based on your customer commitments, and whether to start with a Type 1 or a Type 2. We identify subservice organizations, such as your cloud provider, early because the report must state how their controls are treated.
We compare your current controls with the criteria you selected. We review policies, configurations, access, logs and tickets, and we interview control owners. The result is a gap list ranked by audit impact and effort, with an owner for each item.
We work through the plan with your engineers. That can include configuring SSO and MFA, setting up vulnerability scanning and patch tracking, writing an incident response plan, formalizing change approval or updating policies. Each control ends up with a named owner, a frequency and an evidence source.
Before fieldwork we test a sample of controls the way an auditor would, and we help fix what fails. During the examination we help answer requests, locate evidence and explain technical controls to the auditor. Your management signs the assertion, and the CPA firm issues the report.
What you receive
Each engagement has a fixed scope agreed at the start. These are the outputs your team keeps.
Gap assessment
- System boundary and in-scope components
- Control-by-control status against the selected criteria
- Prioritized remediation plan with owners and target dates
Policies and controls
- Policies updated where gaps exist
- Controls implemented or improved in your environment
- Control matrix mapped to the Trust Services Criteria
Evidence set
- Evidence organized by control for the auditor
- Defined evidence sources and collection frequency
- Setup in your compliance platform if you use one
Testing and audit support
- Pre-audit control testing results
- Fixes for exceptions found in testing
- Help with auditor requests during fieldwork
Control areas we commonly implement
Access control and identity
SSO, MFA, role-based access, joiner, mover and leaver steps, and periodic access reviews. We can deploy identity with Keycloak.
Vulnerability management
Scanning, patch timelines by severity and tracking of findings to closure. We also run application security testing when customers ask for a penetration test.
Logging and monitoring
Centralized logs, alerts on security events and a record that alerts were reviewed. We deploy open-source monitoring such as Wazuh.
Incident response
A written plan, defined roles, a tabletop exercise and records of incidents and follow-up actions.
Change management
Code review, approvals before production changes, separation of duties and deployment records.
Vendor risk
A vendor inventory, risk ratings, review of vendor SOC reports and security terms in contracts.
Backups and recovery
Backup schedules, restore tests and a documented recovery plan.
SOC 2 Type 1 and Type 2 compared
Some teams start with a Type 1 and move to a Type 2 for the next period. Your customers' requests usually decide which comes first.
| Topic | Type 1 | Type 2 |
|---|---|---|
| What the auditor reports on | System description and design of controls | System description, design and operating effectiveness of controls |
| Timing | A single date | A review period agreed with your auditor |
| Evidence | Controls exist and are designed to meet the criteria | Records showing each control operated throughout the period, which the auditor samples |
| Common use | A first report when a customer needs one soon | Ongoing assurance for customers who want to see controls working over time |
| Readiness focus | Control design and documentation | Control design, consistent operation and evidence collection across the period |
Who does what
We prepare your environment and evidence for the examination. We scope, assess, help implement controls, test them and support your team during fieldwork. We do not perform the examination or issue the report.
Your independent CPA firm plans and performs the examination, decides its own procedures, tests your controls and issues the SOC 2 report with its opinion.
Your team owns the system and the controls. Management provides the system description and signs the assertion. Control owners run their controls during the period. One person on your side coordinates with the auditor. We can help draft the system description for management to review.
Common questions
How long does readiness take?
It depends on your scope and how mature your controls are today. During scoping we give you a plan with dates for each phase. For a Type 2, also plan for the review period, because the auditor needs evidence that controls operated across it.
Can you work with our compliance platform?
Yes. If you use Vanta, Drata or a similar platform, we work inside it. We connect integrations, map controls, upload evidence and fix failing checks. If you do not use one, we organize evidence in a folder structure your auditor can follow.
Do you perform the SOC 2 audit?
No. A licensed CPA firm performs the examination and issues the report. We prepare your team for it and support you while it runs.
Can you help after the report is issued?
Yes, through a retainer. We can help address exceptions noted in the report, keep evidence collection on schedule for the next period and prepare for the next examination. If a customer asks about the time between your report period and today, your management can issue a bridge letter, and we can help gather the supporting information.
What do we need to prepare?
A named owner on your side, read access to your cloud accounts, identity provider, code repositories and ticketing system, your current policies if you have any, and a list of key vendors. Security questionnaires you have received from customers are also useful.
Will you sign an NDA?
Yes. We sign an NDA on request before we review your systems or documents.
How to prepare
List the products and services customers expect the report to cover, and the security commitments you have made in contracts and on your website. Note any customer deadlines.
Gather what you already have: policies, a system or asset inventory, a vendor list, an architecture diagram and a description of how people get and lose access. Gaps are expected. The gap assessment exists to find them.
Choose an internal owner with time to coordinate the work, and decide whether you will use a compliance platform. If you have already selected a CPA firm, share their contact so we can align on scope and timing early.

