Control design at a point in time
- Reports on your system as of a specific date.
- Tests whether controls are suitably designed.
- Often a first step for a new program.
Scoping, gap assessment, control design and evidence, so you are ready when your auditor starts the SOC 2 examination.
A SOC 2 report gives your customers independent assurance about the controls in the systems you use to serve them. The report is issued by an independent CPA firm after it examines your controls against the AICPA Trust Services Criteria. Vectra does the work that comes before and around that examination. We help you set the scope, find the gaps, design the controls and collect the evidence. We then work alongside your chosen auditor so the examination runs on a clear, well-prepared footing.
The AICPA Trust Services Criteria sit behind every SOC 2 report. They cover five categories. The security criteria, known as the common criteria, apply in every report.
You add the other categories that match the commitments you make to customers.
Information and systems are protected against unauthorised access, disclosure and damage.
Systems are available to operate and be used as committed or agreed.
System processing is complete, valid, accurate, timely and authorised.
Information marked as confidential is protected as committed or agreed.
Personal information is collected, used, kept, disclosed and disposed of as committed or agreed.
Both types describe your system. They differ in what the auditor tests, and over what time.
Prepare with a platform, or without one.
Vectra is a Vanta partner. We can set up Vanta to monitor your controls and collect evidence, then help you run the program around it.
We prepare you and support you. The CPA firm performs the examination and issues the report.
Agree the services, systems, locations, people and third parties in scope, and which Trust Services Criteria categories your customers need.
Compare your current controls and evidence with the criteria you chose. Rank each gap by risk and effort.
Design or improve the policies, processes and technical controls that close each gap, with a named owner for every control.
Set up how evidence is collected, stored and kept current, by hand or through a compliance platform such as Vanta.
Review controls and evidence as an auditor would, before the examination starts, and fix what the review finds.
Work alongside your CPA firm during the examination. Answer requests, supply evidence and help close any exceptions.
A clear boundary for the report, and the choice of criteria categories that match what your customers ask for.
A control-by-control view of where you stand against the Trust Services Criteria, with a ranked plan to close the gaps.
Policies, procedures and technical controls written for how your business actually runs, not copied from a template.
Evidence collection built into daily work, by hand or on a compliance platform such as Vanta.
Support while you choose a CPA firm, plan the examination and respond to its requests.
Help between reports to keep controls running and evidence current for the next examination period.
A defined scope and a clear set of Trust Services Criteria categories.
Controls designed for your systems, each with an owner.
Evidence organised the way an auditor expects to see it.
Fewer surprises when the CPA firm starts its examination.
Controls and evidence you can reuse for ISO/IEC 27001 and customer questionnaires.
No. Only an independent CPA firm can perform a SOC 2 examination and issue the report. Vectra prepares you for the examination and works alongside the auditor you appoint.
Customers and business partners of service organisations ask for it. They use it to understand and manage the risk of relying on your service, often as part of vendor due diligence.
Many organisations start with a Type 1 report to confirm their control design, then move to Type 2. Your customers' needs and how long your controls have been running shape the choice. We help you decide during scoping.
No. SOC 2 does not require any particular platform. Vanta can save effort by automating evidence collection and tracking controls. We can run your program with or without it.
They overlap a lot. ISO/IEC 27001 leads to a certificate for an information security management system. SOC 2 leads to an attestation report on the controls of a service. Many controls and much of the evidence can serve both.
Speak to us about your cyber governance and compliance requirements.