SOC 2
SOC 2 is an attestation, not a certification: a CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report. It is the assurance North American buyers ask for most often, and it is usually the thing standing between a security questionnaire and a signed contract. Complyanz gets you to the examination ready.
The Trust Services Criteria, ready to work through
How a SOC 2 program runs
Scope and system description
Define the system boundary and draft the System Description that anchors the report.
Select your criteria
Security is required. Add Availability, Confidentiality, Processing Integrity or Privacy depending on what you commit to customers.
Controls and evidence
Map controls to the selected criteria, record applicability, and gather evidence against the audit period.
Readiness, then examination
Close the gaps, then engage a CPA firm for the Type I or Type II examination.
Running SOC 2 and ISO 27001 together
SOC 2 and ISO 27001 are separate programs with separate applicability views, but they ask for overlapping evidence about the same assets, people and processes. In Complyanz that underlying work is done once and referenced by both, so the second program costs far less than the first.
SOC 2 FAQ
Is SOC 2 a certification?
No. SOC 2 is an attestation. A licensed CPA firm examines your controls and issues a report — there is no certificate and no certification body. Anyone selling you a "SOC 2 certification" has the terminology wrong.
What is the difference between Type I and Type II?
Type I assesses whether controls are suitably designed at a point in time. Type II assesses whether they operated effectively across a period, which is why evidence needs to be collected continuously rather than assembled at the end.
Do you provide the auditor?
No. You engage a CPA firm for the examination. Complyanz prepares the controls, the applicability matrix and the evidence they will ask for.
Do we need ISO 27001 first?
No. SOC 2 is standalone in Complyanz — a SOC 2 organization gets exactly the SOC 2 program, with no ISO management system implied or required.
Get SOC 2 ready
Create an organization, select your trust services categories, and the criteria and evidence tracking are ready to work with.