United States · Adopted by choice
SOC 2 compliance
Service Organization Control 2
Nobody by law. It is an attestation US buyers ask for, issued by a licensed CPA firm rather than a certification body.
The context
What it actually asks of you
SOC 2 is what US enterprise buyers ask for. It is an attestation report issued by a licensed CPA firm against the AICPA's Trust Services Criteria, rather than a certification against a published standard.
The Security category is mandatory; Availability, Confidentiality, Processing Integrity and Privacy are added based on what you actually contract for. Adding categories you do not need is one of the more common ways teams inflate cost and effort for no commercial return.
The failure pattern is specific to Type II. Controls get written to sound impressive, nobody operates them consistently, and the observation window closes with exceptions the auditor has to qualify. Designing controls you can genuinely run every month matters far more than designing impressive ones.
The common mistake
What teams get wrong.
Type I says your controls are designed well on one day. Type II says they actually operated over months. Teams write impressive controls, never run them, and get a qualified opinion at the end of the observation window.
Our scope
What we do for SOC 2.
- 01Trust Services Criteria scoping
- 02Control design with owners, frequencies and evidence sources
- 03Readiness assessment before the CPA firm looks
- 04Evidence pipeline for the observation window
- 05Auditor selection and coordination
innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.
Questions
SOC 2 FAQ
Type I is a reasonable first milestone. It is a point-in-time opinion on control design and can unblock a deal while the Type II window runs. Most enterprise buyers ultimately want Type II, so plan the observation window from the start rather than treating Type I as the destination.
Typically three to twelve months. Three months is the usual minimum for a first Type II; twelve is standard once you are in an annual cycle. Shorter windows are cheaper but some buyers discount them.
Whichever your buyers are asking for, SOC 2 for US enterprise, ISO 27001 for most other markets. If both are on the roadmap within a year, run them as one programme; the control overlap is roughly 80%.
Find out whether SOC 2 binds you.
Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.
No sales sequence. A scoping call and a written proposal cost nothing.