SOC 2 examinations with rigorous testing and modern delivery.
A SOC 2 examination reports on controls relevant to Security, Availability, Processing Integrity, Confidentiality, and/or Privacy.
What is a SOC 2 examination?
A SOC 2 examination is an attestation report under AICPA standards (SSAE 18) that evaluates a service organization's controls against the Trust Services Criteria. It's designed for SaaS providers, cloud services, and any organization that processes sensitive customer data.
Stakeholders use SOC 2 reports for customer assurance, vendor risk reviews, and regulatory compliance evidence. We work alongside your compliance platform to streamline evidence collection, so you're not starting from scratch.
Type I vs. Type II
Type I
Evaluates the design and implementation of controls at a specific point in time. Often used as a first step.
Type II
Evaluates both design and operating effectiveness of controls over a period (typically six months or more). The standard for enterprise procurement.
What to expect
- 1
Planning & preparation
Define scope, select criteria, align on timeline.
- 2
Evidence request and collection
Structured evidence requests mapped to controls.
- 3
Testing
Control testing with documented results and exception handling.
- 4
Reporting
Clear attestation report with findings and recommendations.