Audit & AssuranceAll States
SOC 2 Examination
Independent attestation that your security controls meet the Trust Services Criteria — often required to close enterprise deals.
Are you a provider?
What it’s worth
Unblocks enterprise/regulated buyers; shortens security review cycles.
How often you need it
Type I is point-in-time; Type II covers a 3–12 month period and is usually renewed annually.
What you provide
Provide policies, system descriptions, and evidence; readiness + audit window spans weeks to months.
Risks to know
Failed/qualified opinion if controls aren't operating; independence conflicts with your current auditor.When it matters: During readiness and the observation window.
Helpful reading
- Your prior SOC 2 report, if this is a renewal
- A system description or architecture diagram of the in-scope environment
- Your existing security policies and procedures
- A list of in-scope systems and key vendors
- A readiness or gap-assessment export from your compliance platform, if you use one
Ready to start?
Answer a short set of questions and send it anonymously.
Start your RFP →