The attestation report North American enterprise buyers ask for by name, issued by an independent CPA firm against the Trust Services Criteria.
SOC 2 is an attestation report on a service organisation's controls, developed by the American Institute of Certified Public Accountants. It is the report North American enterprise buyers ask for by name, and increasingly one that Australian companies selling into the United States are expected to hold.
It is assessed against the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Security is always in scope; the others are included only where relevant to what you promise customers. Choosing more criteria than you need is a straightforward way to make the engagement more expensive than it had to be.
Two report types matter:
An important distinction from ISO certification. SOC 2 is not a certification and there is no certificate. It is an attestation report issued by an independent CPA firm, containing the auditor's opinion. No consultancy can issue one, and any that claims to is misrepresenting the scheme.
The dominant case. US enterprise procurement asks for SOC 2 the way Australian procurement asks for ISO 27001, and the absence of one stalls deals at the security review stage.
Anywhere a customer's own compliance depends on the controls you operate on their behalf.
Where SOC 2 and ISO 27001 are both asked for. The underlying controls overlap heavily, so building them together costs far less than running two separate programmes.
An organisation with no North American buyers asking for it. SOC 2 is a recurring cost with an annual cycle, and ISO 27001 is usually the better first investment for a business selling into Australia, Europe or government.
Security is required; the other four are included only where relevant to what you promise customers. Adding criteria you do not need is a common and avoidable cost.
Against the applicable criteria, establishing what exists and what has to be built.
Policies, access control, change management, vendor management, incident response, monitoring — and, critically, the routines that generate evidence as a by-product of normal operation.
For Type II, this is the substance of the engagement. The auditor samples evidence across the period, so controls must be running and producing records throughout. There is no way to compress this.
The CPA firm tests controls and evidence. Soveriq supports the process; the opinion is the auditor's.
Reports cover a stated period, so buyers expect a current one. Plan for a recurring annual cycle rather than a one-off project.
Soveriq builds the control environment and the evidence routines inside the systems you already run, so the observation window produces records naturally rather than requiring a reconstruction exercise at audit time.
Where ISO 27001 is also needed, we scope both together. The control overlap is substantial and the marginal cost of the second is far lower than doing them separately — which matters for any Australian company selling into both markets.
Being direct about the boundary. Soveriq is not a CPA firm and cannot issue a SOC 2 report. We prepare you and support the audit; the attestation is issued independently. That separation is the point of the report, and any provider blurring it is devaluing the thing you are buying.
On internal review. Where Soveriq has built your control environment, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day. CPA firm fees are separate and paid directly to that firm.
No. A SOC 2 report can only be issued by an independent CPA firm. We prepare the control environment and evidence; the attestation is theirs. Any consultancy claiming to issue SOC 2 reports is describing something it cannot do.
Type I tests design at a point in time and is faster. Type II tests operating effectiveness over a window and is what most enterprise buyers actually want. Type I is a reasonable staging post if a deal needs something immediately, but budget for Type II.
It depends on the buyer. North American enterprise buyers usually ask for SOC 2. Australian, European and government buyers usually ask for ISO 27001. Organisations selling into both markets often need both, and because the underlying controls overlap heavily, doing them together is far cheaper than sequentially.
It covers a stated period rather than carrying an expiry. In practice buyers expect a report covering a recent period, which usually means an annual cycle. A report more than twelve months old starts drawing questions.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope