Attest the design and operating effectiveness of your security, availability and confidentiality controls against the Trust Services Criteria from the AICPA. Built for SaaS, cloud and service providers.
SOC 2 (System and Organization Controls 2) is an audit framework defined by the AICPA. It evaluates an organisation's controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.
A Type I report attests the design of your controls at a point in time, while a Type II report attests their operating effectiveness across an observation period — a mark of trust for your customers and partners.
We address the Trust Services Criteria that apply to your service scope.
Protecting systems and data against unauthorised access and compromise.
Keeping services available in line with your contractual commitments.
Processing that is complete, accurate, authorised and delivered on time.
Protecting confidential information throughout its entire lifecycle.
Collecting, using and retaining personal data in line with your commitments.
Establishing durable controls and continuous monitoring to sustain compliance.
An end-to-end approach, from gap analysis to your SOC 2 Type II report.
Gap analysis against the selected Trust Services Criteria.
Prioritised remediation plan and implementation of missing controls.
Observing the operating effectiveness of controls across the chosen window.
Issuing the report and sustaining continuous controls over time.
Payment, banking and systems security — we cover the full spectrum.
A gap analysis and a roadmap all the way to your SOC 2 Type II report. Leave us your details and an expert will get back to you.