SOC 2 examinations with rigorous testing and modern delivery.

A SOC 2 examination reports on controls relevant to Security, Availability, Processing Integrity, Confidentiality, and/or Privacy.

What is a SOC 2 examination?

A SOC 2 examination is an attestation report under AICPA standards (SSAE 18) that evaluates a service organization's controls against the Trust Services Criteria. It's designed for SaaS providers, cloud services, and any organization that processes sensitive customer data.

Stakeholders use SOC 2 reports for customer assurance, vendor risk reviews, and regulatory compliance evidence. We work alongside your compliance platform to streamline evidence collection, so you're not starting from scratch.

Type I vs. Type II

Type I

Evaluates the design and implementation of controls at a specific point in time. Often used as a first step.

Type II

Evaluates both design and operating effectiveness of controls over a period (typically six months or more). The standard for enterprise procurement.

What to expect

  1. 1

    Planning & preparation

    Define scope, select criteria, align on timeline.

  2. 2

    Evidence request and collection

    Structured evidence requests mapped to controls.

  3. 3

    Testing

    Control testing with documented results and exception handling.

  4. 4

    Reporting

    Clear attestation report with findings and recommendations.

Frequently asked questions