SOC 2

System and Organization Controls 2

The AICPA framework and audit report on security, availability, and confidentiality controls, the gold standard for SaaS trust.

What It Is

SOC 2 is an attestation framework developed by the AICPA and evaluated against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

An independent CPA firm issues a Type I report, which evaluates controls at a single point in time, or a Type II report, which evaluates operating effectiveness over a period, typically three to twelve months. SOC 2 Type II is widely required by enterprise customers evaluating SaaS and technology vendors.

Who It Applies To

SaaS companies, technology vendors, and service providers that need to demonstrate trustworthy security practices to enterprise customers and prospects during vendor security reviews.

How We Help

  • Scope the right Trust Services Criteria for your business

  • Implement and document required controls across people, process, and technology

  • Run a readiness assessment ahead of a Type I or Type II audit

  • Coordinate with your independent CPA auditor

  • Maintain continuous control monitoring between audit periods

Ready to close your compliance gaps?

Get a free security assessment, no obligation.