Audit & AssuranceAll States
SOC 2 Examination
Independent attestation that your security controls meet the Trust Services Criteria — often required to close enterprise deals.
Are you a provider?
What it’s worth
Unblocks enterprise/regulated buyers; shortens security review cycles.
How often you need it
Type I is point-in-time; Type II covers a 3–12 month period and is usually renewed annually.
What you provide
Provide policies, system descriptions, and evidence; readiness + audit window spans weeks to months.
Risks to know
Failed/qualified opinion if controls aren't operating; independence conflicts with your current auditor.When it matters: During readiness and the observation window.
Helpful reading
- SOC 2 Type I vs Type II
- Trust Services Criteria explained
- How to prepare for a SOC 2
Ready to start?
Answer a short set of questions and send it anonymously.
Start your RFP →