Who it applies to
▸SaaS companies and service providers, especially those selling to US customers
▸Vendors for which the report is a condition in procurement
▸Organizations deciding between a Type 1 and a Type 2 report
What it requires
The obligations, clearly explained.
01
Trust Services Criteria
Controls mapped to security and, where needed, availability, confidentiality, processing integrity, and privacy.
02
Type 1 or Type 2
An assessment of control design at a point in time (Type 1) or of operating effectiveness over a period (Type 2).
03
Evidence
Continuous collection of evidence that the controls operate as described.
04
CPA examination
An independent CPA firm performs the examination and issues the report.
How Raptoric helps
We do the engineering work, not just the documentation.
Readiness assessment
We identify the gaps before the audit and define the appropriate criteria.
Control implementation
We implement the technical and process controls the report is based on.
Evidence collection
We set up the evidence collection process that makes a Type 2 report sustainable.
Audit support
We work with your CPA firm throughout the examination.
We prepare the organization and validate the controls. The report is issued by an independent CPA firm.
Services that deliver it
FAQ
Questions, answered
What is a SOC 2 report?
An attestation by an independent auditor that the organization has security controls in place and adheres to them. Type 1 assesses control design at a point in time; Type 2 assesses operating effectiveness over a period.
Does a SOC 2 report mean we are secure?
The report confirms that the controls exist and operate as described. Resilience against real attacks is validated through testing, which is why we implement controls primarily for security, with the report as their formal confirmation.
How do you help with SOC 2?
We map your controls to the Trust Services Criteria, close the identified gaps, and set up evidence collection, while the attestation is performed by your auditor.
SOC 2 or ISO 27001 first?
It depends on the market you operate in. SOC 2 is most often required by North American customers, ISO 27001 by European and global ones. Controls can be implemented to cover both frameworks without duplicate work.
Further reading