Advisory

SOC 2 Readiness

Scoping, gap assessment, control design and evidence, so you are ready when your auditor starts the SOC 2 examination.

Ready for the auditor before the audit begins.

A SOC 2 report gives your customers independent assurance about the controls in the systems you use to serve them. The report is issued by an independent CPA firm after it examines your controls against the AICPA Trust Services Criteria. Vectra does the work that comes before and around that examination. We help you set the scope, find the gaps, design the controls and collect the evidence. We then work alongside your chosen auditor so the examination runs on a clear, well-prepared footing.

SOC 2 Readiness

Five categories. You choose the ones that apply.

The AICPA Trust Services Criteria sit behind every SOC 2 report. They cover five categories. The security criteria, known as the common criteria, apply in every report.

You add the other categories that match the commitments you make to customers.

  • Security

    Information and systems are protected against unauthorised access, disclosure and damage.

  • Availability

    Systems are available to operate and be used as committed or agreed.

  • Processing integrity

    System processing is complete, valid, accurate, timely and authorised.

  • Confidentiality

    Information marked as confidential is protected as committed or agreed.

  • Privacy

    Personal information is collected, used, kept, disclosed and disposed of as committed or agreed.

Type 1 or Type 2.

Both types describe your system. They differ in what the auditor tests, and over what time.

Type 1

Control design at a point in time

  • Reports on your system as of a specific date.
  • Tests whether controls are suitably designed.
  • Often a first step for a new program.
Type 2

Design and operation over a period

  • Reports on your system over a period of time.
  • Tests whether controls are suitably designed and operated effectively throughout the period.
  • Often what customers ask for once a program is running.

Prepare with a platform, or without one.

Vectra is a Vanta partner. We can set up Vanta to monitor your controls and collect evidence, then help you run the program around it.

The path to a SOC 2 examination.

We prepare you and support you. The CPA firm performs the examination and issues the report.

  1. Step 1: Scope

    Agree the services, systems, locations, people and third parties in scope, and which Trust Services Criteria categories your customers need.

  2. Step 2: Gap assessment

    Compare your current controls and evidence with the criteria you chose. Rank each gap by risk and effort.

  3. Step 3: Control design

    Design or improve the policies, processes and technical controls that close each gap, with a named owner for every control.

  4. Step 4: Evidence

    Set up how evidence is collected, stored and kept current, by hand or through a compliance platform such as Vanta.

  5. Step 5: Readiness check

    Review controls and evidence as an auditor would, before the examination starts, and fix what the review finds.

  6. Step 6: Audit support

    Work alongside your CPA firm during the examination. Answer requests, supply evidence and help close any exceptions.

SOC 2 readiness services.

Scoping workshop

A clear boundary for the report, and the choice of criteria categories that match what your customers ask for.

Readiness and gap assessment

A control-by-control view of where you stand against the Trust Services Criteria, with a ranked plan to close the gaps.

Policy and control design

Policies, procedures and technical controls written for how your business actually runs, not copied from a template.

Evidence and platform set-up

Evidence collection built into daily work, by hand or on a compliance platform such as Vanta.

Auditor liaison

Support while you choose a CPA firm, plan the examination and respond to its requests.

Ongoing compliance

Help between reports to keep controls running and evidence current for the next examination period.

What you have at the end.

  • A defined scope and a clear set of Trust Services Criteria categories.

  • Controls designed for your systems, each with an owner.

  • Evidence organised the way an auditor expects to see it.

  • Fewer surprises when the CPA firm starts its examination.

  • Controls and evidence you can reuse for ISO/IEC 27001 and customer questionnaires.

SOC 2 questions.

Does Vectra issue SOC 2 reports?

No. Only an independent CPA firm can perform a SOC 2 examination and issue the report. Vectra prepares you for the examination and works alongside the auditor you appoint.

Who asks for a SOC 2 report?

Customers and business partners of service organisations ask for it. They use it to understand and manage the risk of relying on your service, often as part of vendor due diligence.

Should we start with Type 1 or Type 2?

Many organisations start with a Type 1 report to confirm their control design, then move to Type 2. Your customers' needs and how long your controls have been running shape the choice. We help you decide during scoping.

Do we need Vanta?

No. SOC 2 does not require any particular platform. Vanta can save effort by automating evidence collection and tracking controls. We can run your program with or without it.

How does SOC 2 relate to ISO/IEC 27001?

They overlap a lot. ISO/IEC 27001 leads to a certificate for an information security management system. SOC 2 leads to an attestation report on the controls of a service. Many controls and much of the evidence can serve both.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.