GRC & Compliance · SOC 2 Type I & Type II

SOC 2 Compliance: prove your controls are under control.

Attest the design and operating effectiveness of your security, availability and confidentiality controls against the Trust Services Criteria from the AICPA. Built for SaaS, cloud and service providers.

Our approach — a continuous cycle
1 · Assess 2 · Protect 3 · Comply 4 · Monitor 5 · Evolve Our approach
Certifications & accreditations
What it is

Demonstrate the effectiveness of your controls.

SOC 2 (System and Organization Controls 2) is an audit framework defined by the AICPA. It evaluates an organisation's controls against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy.

A Type I report attests the design of your controls at a point in time, while a Type II report attests their operating effectiveness across an observation period — a mark of trust for your customers and partners.

  • Scope: SaaS, cloud and service providers
  • Selecting the applicable criteria (Trust Services Criteria)
  • Gap analysis, remediation and audit readiness
  • SOC 2 Type I and Type II reports across an observation period
The criteria (Trust Services Criteria)

The five criteria, under control.

We address the Trust Services Criteria that apply to your service scope.

Our method

From gap analysis to the SOC 2 report.

An end-to-end approach, from gap analysis to your SOC 2 Type II report.

  1. 1

    Readiness

    Gap analysis against the selected Trust Services Criteria.

  2. 2

    Remediate

    Prioritised remediation plan and implementation of missing controls.

  3. 3

    Audit over a period

    Observing the operating effectiveness of controls across the chosen window.

  4. 4

    SOC 2 Type II report

    Issuing the report and sustaining continuous controls over time.

GRC & Compliance

Other frameworks.

Payment, banking and systems security — we cover the full spectrum.

Ready to obtain your SOC 2 Type II report?

A gap analysis and a roadmap all the way to your SOC 2 Type II report. Leave us your details and an expert will get back to you.