Attestation · Trust Services Criteria

SOC 2

SOC 2 is an attestation against the AICPA Trust Services Criteria. The report is issued by a licensed CPA firm and is most often required in procurement by customers in the North American market.

Who it applies to

SaaS companies and service providers, especially those selling to US customers
Vendors for which the report is a condition in procurement
Organizations deciding between a Type 1 and a Type 2 report
What it requires

The obligations, clearly explained.

01
Trust Services Criteria
Controls mapped to security and, where needed, availability, confidentiality, processing integrity, and privacy.
02
Type 1 or Type 2
An assessment of control design at a point in time (Type 1) or of operating effectiveness over a period (Type 2).
03
Evidence
Continuous collection of evidence that the controls operate as described.
04
CPA examination
An independent CPA firm performs the examination and issues the report.
How Raptoric helps

We do the engineering work, not just the documentation.

Readiness assessment
We identify the gaps before the audit and define the appropriate criteria.
Control implementation
We implement the technical and process controls the report is based on.
Evidence collection
We set up the evidence collection process that makes a Type 2 report sustainable.
Audit support
We work with your CPA firm throughout the examination.
We prepare the organization and validate the controls. The report is issued by an independent CPA firm.
FAQ

Questions, answered

What is a SOC 2 report?
An attestation by an independent auditor that the organization has security controls in place and adheres to them. Type 1 assesses control design at a point in time; Type 2 assesses operating effectiveness over a period.
Does a SOC 2 report mean we are secure?
The report confirms that the controls exist and operate as described. Resilience against real attacks is validated through testing, which is why we implement controls primarily for security, with the report as their formal confirmation.
How do you help with SOC 2?
We map your controls to the Trust Services Criteria, close the identified gaps, and set up evidence collection, while the attestation is performed by your auditor.
SOC 2 or ISO 27001 first?
It depends on the market you operate in. SOC 2 is most often required by North American customers, ISO 27001 by European and global ones. Controls can be implemented to cover both frameworks without duplicate work.

Need to be ready for SOC 2?

Our team will define the scope of work with you on a 30-minute call.
Book a scoping call or email contact@raptoric.com