The attestation North American buyers ask for. SOC 2 reports on how your organisation safeguards customer data against the AICPA's Trust Services Criteria — and is often the fastest way to unblock a stalled enterprise deal.
SOC 2 is an attestation report issued by a licensed CPA firm, not a certification. It evaluates your controls against up to five Trust Services Criteria: Security (always required), plus Availability, Processing Integrity, Confidentiality, and Privacy as relevant to your service.
It comes in two forms. Type I assesses whether controls are suitably designed at a single point in time. Type II assesses whether they operated effectively across a defined observation window — typically three to twelve months — and is the version most enterprise customers expect.
Because the framework maps closely to ISO 27001, organisations pursuing both can reuse much of the same control work across the two.
The default trust signal in the US market, and increasingly a prerequisite to closing mid-market and enterprise deals.
Demonstrates continuous, audited control of the data you process on customers' behalf.
Any vendor whose buyers send a security questionnaire before they sign.
We run the full programme — scoping, control build, and audit readiness — and coordinate the CPA firm. A Type I report can move quickly; a Type II report is gated by its observation window, so the timeline reflects the period your controls must demonstrably operate, not the effort to build them.
We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.
A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.
We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.
The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.
We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.
If a deal needs proof fast, a Type I gives you a report at a point in time while the Type II observation window runs in parallel. If you can wait, many companies go straight to Type II. We'll advise based on your sales pressure and starting maturity.
No — it's an attestation report signed by a licensed CPA firm. There's no certificate or pass/fail mark; the report describes your controls and the auditor's findings, which you then share with customers under NDA.
Book a free advisory session and we'll map your fastest credible route to compliance.
Book a free advisory session