Attestation

SOC 2

SOC 2 is an attestation, not a certification: a CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report. It is the assurance North American buyers ask for most often, and it is usually the thing standing between a security questionnaire and a signed contract. Complyanz gets you to the examination ready.

What you get

The Trust Services Criteria, ready to work through

62Trust Services Criteria entries with guidance and applicability
5trust services categories: Security, plus Availability, Confidentiality, Processing Integrity and Privacy
1controls applicability matrix, generated from your decisions
0ISO 27001 required — SOC 2 runs standalone in Complyanz
In the platform

How a SOC 2 program runs

Step 1

Scope and system description

Define the system boundary and draft the System Description that anchors the report.

Step 2

Select your criteria

Security is required. Add Availability, Confidentiality, Processing Integrity or Privacy depending on what you commit to customers.

Step 3

Controls and evidence

Map controls to the selected criteria, record applicability, and gather evidence against the audit period.

Step 4

Readiness, then examination

Close the gaps, then engage a CPA firm for the Type I or Type II examination.

Going further

Running SOC 2 and ISO 27001 together

SOC 2 and ISO 27001 are separate programs with separate applicability views, but they ask for overlapping evidence about the same assets, people and processes. In Complyanz that underlying work is done once and referenced by both, so the second program costs far less than the first.

Questions

SOC 2 FAQ

Is SOC 2 a certification?

No. SOC 2 is an attestation. A licensed CPA firm examines your controls and issues a report — there is no certificate and no certification body. Anyone selling you a "SOC 2 certification" has the terminology wrong.

What is the difference between Type I and Type II?

Type I assesses whether controls are suitably designed at a point in time. Type II assesses whether they operated effectively across a period, which is why evidence needs to be collected continuously rather than assembled at the end.

Do you provide the auditor?

No. You engage a CPA firm for the examination. Complyanz prepares the controls, the applicability matrix and the evidence they will ask for.

Do we need ISO 27001 first?

No. SOC 2 is standalone in Complyanz — a SOC 2 organization gets exactly the SOC 2 program, with no ISO management system implied or required.

Get SOC 2 ready

Create an organization, select your trust services categories, and the criteria and evidence tracking are ready to work with.