Security · AICPA
SOC 2 (AICPA Trust Services Criteria)
The report enterprise and government buyers ask for before they sign. Type II proves controls ran all year.
Who it applies to
The businesses that carry SOC 2, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
SOC 2 Readiness: Type 1 and Type 2
SaaS, AI and technology companies of 5 to 300 people, and professional firms whose clients require it
Mock Audit Package: SOC 2, HIPAA or CMMC
Organizations within 90 days of a SOC 2 audit, an OCR inquiry or a C3PAO assessment, and any leadership team that wants to know before it counts
What it asks for
In plain English, what SOC 2 expects you to have in place.
- Scoped Trust Services CriteriaSecurity always; Availability, Confidentiality, Processing Integrity and Privacy when your customers require them.
- Controls designed and describedA system description and a control list an auditor can test, mapped to the criteria.
- Evidence that controls operateAccess reviews, change tickets, vendor reviews, incident records and monitoring output, collected as they happen.
- Policies adopted, not draftedA policy set your team has read and follows, with acknowledgements on file.
- Risk and vendor managementA risk register reviewed on a schedule and a vendor list with the evidence you asked them for.
- A licensed auditorOnly a licensed CPA firm can issue the report. We prepare you and sit in the audit with you.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Questions we get about SOC 2
Do you certify SOC 2 compliance?
Where do we start with SOC 2?
We also need other frameworks. Do we do SOC 2 separately?
Also in security: NIST CSF 2.0 · ISO 27001 · CIS Controls · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for SOC 2.
Book the demo and see how one control set carries SOC 2 and everything else you owe. Or leave your details and an engineer replies within one business day.