Skip to content
SecuriFii

Attestation

SOC 2 Type 2 Readiness

A Type 2 tests whether your controls actually operated across a window of months. It is the stronger claim and the harder one, and it is won or lost long before fieldwork — in how the evidence gets produced during the ordinary working week.

Standard
AICPA Trust Services Criteria
Report covers
Design + effectiveness
Observation window
3–12 months
Common choice
6 months

What a Type 2 actually says

A SOC 2 examination is performed under AICPA standards against the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality and Privacy. Security — delivered through the common criteria — is required in every SOC 2; the other four are included only when a commitment you have made to customers calls for one.

A Type 2 reports on design AND operating effectiveness across an observation period, typically three to twelve months, with six months the common choice. The auditor samples across the window: if a quarterly access review happened three times out of four, that is an exception, and exceptions appear in the report a customer reads.

The scope is yours to define, and that is the decision with the longest consequences. Every criterion you include becomes controls you must evidence continuously — not reconstruct in the final fortnight. Most Type 2 engagements that go badly went wrong at scoping.

What it will ask of you

The difference between a Type 1 and a Type 2 is not the examination — it is the months in between, and what your organisation does during them.

  • A system description

    A written account of the service being examined, its boundaries, and the commitments you have made to customers about it. The auditor tests against this, so an optimistic description is a trap you set for yourself.

  • Evidence across the whole window

    Each control must be shown to have operated throughout the observation period. A control that ran for ten of twelve months is an exception, and it is visible to every customer who reads the report.

  • Operational discipline, not a project

    Access reviews, change management, onboarding and offboarding, monitoring — done on their stated cadence, by the people who own them, while everyone is busy with something else.

  • Subservice organisations, named

    Which providers you rely on, whether they are carved out or included, and which complementary user entity controls your own customers are expected to run.

Why organisations pursue it

  • It is what enterprise and North American procurement generally mean by "your SOC 2".
  • Evidence that controls ran for months is a materially stronger claim than a point-in-time one.
  • It replaces repeated bespoke security questionnaires with one report you hand over.
  • The control work overlaps heavily with ISO/IEC 27001, so running both is far cheaper than running each alone.

Where we come in, and where we stop

A SOC 2 report can only be issued by an independent licensed CPA firm. We are not one, and no amount of preparation changes who signs.

Ours

  • Scoping the Trust Services Criteria, and arguing against the ones you do not need
  • Readiness assessment and the remediation plan
  • Making evidence a by-product of how you already work, before the window opens
  • Monitoring the observation period so a lapse is caught while it is still fixable
  • Drafting the system description and running the auditor’s request list from your side

An independent licensed CPA firm

  • Performing the examination across the observation period
  • Sampling and testing the controls, and forming an opinion
  • Issuing the SOC 2 Type 2 report

How we get you there

The examination itself is performed by an independent licensed CPA firm. We prepare you for it and we do not perform it.

  1. 01Scoping the criteriaWhich Trust Services Criteria your customer commitments actually require, and which to leave out. Every extra category is months of evidence, not a paragraph.
  2. 02Readiness assessmentA control-by-control gap assessment against the criteria in scope, covering the system description, subservice organisations and complementary user entity controls.
  3. 03Control design and remediationControls designed to be evidenced repeatably, implemented with your engineering and people teams.
  4. 04Evidence instrumentationBefore the window opens, we make evidence a by-product of how you already work — access reviews, change management, monitoring, onboarding and offboarding — rather than a quarterly fire drill.
  5. 05The observation periodControls run and are evidenced continuously across the window. We monitor it with you and catch a lapse while it is still fixable rather than after the auditor finds it.
  6. 06Auditor selection and liaisonWe help you select a licensed CPA firm, prepare the system description, and act as your counterpart through fieldwork and the request list.

What you get from us

  • A scoping decision with the reasoning written down, criterion by criterion
  • Readiness assessment and remediation plan
  • Controls whose evidence is produced by the work itself, not reconstructed
  • A drafted system description ready for the auditor
  • Monitoring across the observation window, with lapses raised while they are fixable
  • Support through fieldwork to a signed Type 2 report

Common questions

How long should the observation period be?

Three months is the shortest that is usually accepted and six is the common choice; twelve suits an organisation on an annual reporting rhythm. Shorter windows get you a report sooner and give a thinner claim. Some buyers state a minimum, so check contracts before choosing.

Should we do a Type 1 first?

If a contract is blocked right now, yes — it proves design and buys time, and everything built for it carries over. If there is no immediate deadline, going straight to a Type 2 avoids paying for two examinations.

Which Trust Services Criteria do we need?

Security always. Add Availability if you have committed to uptime, Confidentiality if you have committed to handling customer data under defined restrictions, Processing Integrity if you process transactions on a customer’s behalf, Privacy if you handle personal information under a stated notice. Include nothing out of ambition.

What happens if a control lapses mid-window?

It becomes an exception in the report, with management’s response beside it. That is survivable and common; what is not survivable is discovering it during fieldwork rather than in the month it happened, which is why the window is monitored.

We are doing ISO 27001 as well. Is that duplicated effort?

Much less than you would expect. The underlying controls overlap heavily and most evidence serves both. The frameworks differ mainly in how they are assessed and what the output is called.

Related insights