What SOC 2 actually is
SOC 2 is an attestation report issued by an independent CPA firm against the AICPA's Trust Services Criteria. A Type I report says your controls are designed properly at a point in time. A Type II report says they actually operated over a period — usually three to twelve months. Type II is what most buyers mean when they ask for SOC 2.
Who needs it
B2B software companies selling to enterprises, and anyone whose deals keep stalling in a security review. It is the most requested framework in North America and it is usually the first one a company is asked for.
How long it takes
Type II requires an observation window, and that window cannot be shortened — not by us, not by your auditor, not by paying more. If you need a report quickly, the honest route is a Type I now and a Type II observation period starting immediately after. We will tell you that on the first call rather than after you have paid.
What we do for your SOC 2 program
- Scope the report — which Trust Services Criteria apply, and which controls genuinely don't, each with a written rationale your auditor can read
- Draft the policy set against your actual stack, not a template with your name dropped in
- Connect your cloud, source control and identity systems and test them daily
- Chase your team only for the things a person genuinely has to do — the pen test, the background checks, the risk assessment
- Answer your auditor's information requests from verified artifacts, and hand over a package where every file is hashed
SOC 2 questions we get asked
- How long does SOC 2 Type II take?
- It depends on how much is already in place, plus a mandatory observation window that cannot be compressed. Most companies starting from nothing need several weeks of preparation before the window even opens. We give you a specific date after scoping your program, and we do not shorten it to win the engagement.
- Do you issue the SOC 2 report?
- No, and nobody who does the preparation can. A SOC 2 report must be issued by an independent CPA firm that you engage separately. We prepare you, deal with the auditor's requests, and hand over the evidence package. We take no referral fee from any auditor.
- What is the difference between Type I and Type II?
- Type I assesses whether your controls are suitably designed at a single point in time. Type II assesses whether they operated effectively across an observation period. Type II is materially more work and is what enterprise buyers usually require.
- Do you need to install agents on our servers?
- No. We read your cloud, code and identity systems through scoped, read-only connections. Nothing is installed on your infrastructure.
