- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Information Security & Privacy
SOC 2
SOC 2 is the AICPA's examination of a service organization's controls against the Trust Services Criteria for security (required in every report), availability, processing integrity, confidentiality and privacy. The current criteria are the 2017 Trust Services Criteria with revised points of focus issued in 2022.
A licensed CPA firm examines the organization's system description and controls and issues a report that is restricted to customers, prospects under NDA and their advisers. It has become the default assurance document for SaaS and cloud vendors selling to businesses.
A Type 1 report covers the design of controls at a point in time; a Type 2 report covers design and operating effectiveness over a period, commonly three to twelve months.
To get either, the organization must produce a system description that meets the AICPA description criteria, a management assertion, and a set of written policies and control activities mapped to each criterion in scope.
The auditor tests against those documents, so policies for access, change management, vendor management, incident response, risk assessment, business continuity and data handling need to exist and be followed.
Who has to comply
Voluntary and contractual. Technology and outsourced service providers obtain SOC 2 because customer security reviews, procurement policies and contracts require it; there is no legal mandate.
What the assessor asks to see
System description and management assertion; trust services categories in scope; policy set (information security, access control, change management, incident response, vendor management, business continuity, data classification and retention, acceptable use); risk assessment; control matrix mapped to criteria; populations and samples for user access, changes, incidents, vendors and hires; monitoring evidence (vulnerability scans, logging, backups, availability metrics); subservice organization reports; board or management oversight records.
Where the requirement sits: CC1.1 (integrity/ethics - code of conduct acknowledgment); CC1.4 (competence); CC2.2, CC2.3 (internal/external communication of policies); CC5.3 (policies and procedures)
Type 1 versus Type 2
Type 1 reports on whether controls are suitably designed and implemented at a single date. Type 2 reports on whether they also operated effectively throughout a period, with sample testing across that period. Buyers increasingly ask for Type 2, and many organizations skip Type 1 or use it only as a first milestone.
What AllyMatter does here
The policy and acknowledgment layer inside SOC 2 (CC1.1, CC2.2, CC5.3).
AllyMatter publishes this site.
Assessors
Who assesses SOC 2
A licensed CPA firm (independent certified public accountants) performing the examination under the AICPA attestation standards and issuing the service auditor's report. Accredited by State board CPA licensure and the AICPA peer review program; no scheme-level accreditor and no public registry of SOC auditors.
No firm has claimed a SOC 2 assessor listing yet. Claim yours →
Consultants
Who helps with SOC 2
A very large ecosystem: compliance automation platforms, readiness consultancies and the advisory arms of CPA firms. They scope trust services categories, write policies, map controls, collect evidence and run mock audits. Typical shape is a readiness phase, a Type 1 or a short first Type 2 period, then annual Type 2 reports.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- Full-service GRC + vCISO
- Who they help
- Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Securis360 is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- vCISO.com is a vCISO / ISO 27001 consultancy based in Pittsburgh, PA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 / SOC 2
- Who they help
- Isecurion is an ISO 27001 / SOC 2 based in Bangalore, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- Pentest + SOC 2 readiness
- Who they help
- Illume Intelligence is a pentest + SOC 2 readiness based in Calicut, Kerala, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- ISO 27001 + CREST pentest
- Who they help
- Precursor Security is an ISO 27001 + CREST pentest based in Leeds, UK. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for SOC 2
Tools that name this framework in their own material.
Related reading
- AICPA revises guidance on applying its Trust Services Criteria and SOC 2 description criteriaA Big Four summary of what the revised AICPA guidance changes for practitioners and for the description management writes.EY
- SOC 2 Trust Services Criteria (TSC) explainedAn audit firm walks through each trust services category and the control expectations behind it, in the auditor's own words.Schellman
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for SOC 2
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of SOC 2 in AllyMatter
Approve the policies SOC 2 asks for, keep every version, and record a named acknowledgment from each person who has to read them.