Eye On Bits
Compliance · SOC 2

SOC 2 Type I & Type II Readiness

SOC 2 is the report enterprise customers ask for before they'll sign. We get your controls designed, operating and evidenced - so the audit is a formality, not a scramble.

What is SOC 2?

SOC 2 (System and Organization Controls 2) is an attestation report, not a certificate, issued by an independent CPA firm based on the AICPA's Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.

A Type I report assesses whether your controls are suitably designed at a single point in time. A Type II report goes further, assessing whether those controls actually operated effectively over an observation period - typically 3 to 12 months - which is what most enterprise buyers actually require.

What's included

Scoping Trust Criteria

Scoping - selecting the Trust Services Criteria relevant to your business.

Gap Assessment

Gap assessment against your chosen criteria.

Control Design & Implementation

Control design and implementation, including policies and technical controls.

Evidence Collection

Evidence collection process for the observation period.

Readiness Assessment

Readiness assessment ahead of the formal audit.

Auditor Coordination

Coordination with your independent CPA auditor through Type I or Type II.

Our approach - Plan, Do, Check, Act

The same continuous-improvement cycle behind every compliance programme we run.

Plan

Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.

Do

Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.

Check

Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.

Act

Run the audit, then keep improving through continual, corrective and preventive action.

Other compliance frameworks

ISO 27001

International standard for an Information Security Management System (ISMS).

Learn more →

GDPR

EU regulation governing the processing of personal data.

Learn more →

PCI DSS

Security standard for organisations handling cardholder data.

Learn more →

HIPAA

US standard for protecting patient health information.

Learn more →

Questions we get asked first

Do you issue the SOC 2 report?

No - SOC 2 reports are issued only by a licensed, independent CPA firm. We get your organisation ready and manage the evidence collection; the CPA firm performs the actual attestation.

Type I or Type II - which do we need?

Type I is faster and proves your controls are designed correctly; Type II proves they worked over time and is what most enterprise customers and procurement teams expect. Many organisations start with Type I and move to Type II.

How long is the Type II observation period?

Typically 3 to 12 months, set by your auditor based on your industry and customer requirements - we help you prepare evidence collection so that period runs cleanly.

Ready to get audit-ready for SOC 2?

Tell us where you're starting from and we'll come back with a scoped proposal within two working days.