Risk Refine

Framework Overview

SOC 2

Trust Services Criteria for service organizations

SOC 2 reports evaluate how a service organization manages data based on AICPA Trust Services Criteria—security, availability, processing integrity, confidentiality, and privacy. Type I assesses design; Type II assesses operating effectiveness over time.

Who it's for: B2B SaaS, fintech, healthtech, and any vendor handling customer data where enterprise procurement requires a SOC 2 report.

De facto standard for US B2B SaaSFlexible TSC selectionType I and Type II pathwaysIntegrates with Drata and Vanta

Key Domains

How SOC 2 breaks down across the program lifecycle.

Scope icon

01

Scope & Criteria

Define system boundaries, in-scope services, and which Trust Services Criteria (TSC) apply to your product and customer commitments.

Design icon

02

Control Design

Map policies, procedures, and technical controls to TSC requirements—access, change management, monitoring, and vendor management.

Evidence icon

03

Evidence Collection

Establish continuous evidence collection through GRC automation and operational workflows your team can sustain.

Type I icon

04

Type I Readiness

Validate control design at a point in time before pursuing a full Type II observation period.

Type II icon

05

Type II Observation

Operate controls consistently over a 3–12 month period with ongoing monitoring and remediation.

Auditor icon

06

Auditor Engagement

Coordinate with your CPA firm, respond to requests, and manage findings through report issuance.

Program Snapshot

A visual overview of how we typically structure a SOC 2 engagement—from discovery through audit-ready operations.

1
Scope & Criteria
2
Control Design
3
Evidence Collection
4
Type I Readiness
5
Type II Observation
6
Auditor Engagement

How We Help

  • Gap assessment against framework requirements
  • Prioritized roadmap with clear owners and timelines
  • Policy, control, and evidence design
  • GRC automation setup (Drata / Vanta)
  • Mock audit and auditor liaison support

FAQs

Should we start with Type I or Type II?

Type I is faster and proves control design. Type II is what most enterprise buyers want. Many teams do Type I first, then begin the observation period for Type II.

How long is a Type II observation period?

Typically 3–12 months. Six months is common for first-time audits; some buyers accept shorter periods depending on contract urgency.

Can automation tools replace SOC 2 work?

Tools like Drata and Vanta accelerate evidence collection and monitoring, but you still need sound policies, ownership, and operational discipline—we help design programs your team can run.

Ready To Talk?

Book a free scoping call—we'll map your compliance goals, recommend the right engagement tier, and outline a clear path forward.