FramewiseCOMPLIANCE
Practice

SOC 2

The North American default for software companies selling to enterprise security teams.

What it is

SOC 2 is an attestation performed by a licensed CPA firm against the AICPA Trust Services Criteria — security, and optionally availability, confidentiality, processing integrity, and privacy. A Type 1 reports on control design at a point in time; a Type 2 reports on operating effectiveness across a period, usually three to twelve months. There is no certificate and no pass mark: the deliverable is a report containing the auditor opinion and any exceptions.

Who typically needs it

  • SaaS companies whose enterprise deals stall in the security review
  • Vendors asked for a Type 2 report by a customer with a hard renewal date
  • Companies that issued a Type 1 to close a deal and now owe the Type 2
  • Series B and C companies building a repeatable security review response
  • Sub-processors whose own customers are under SOC 2 obligations

What the engagement looks like

Baseline. We assess against the Trust Services Criteria in scope, confirm which criteria your customers are actually asking for, and score control design. Most companies scope in more criteria than their buyers require, which adds cost without adding deals.

Build. We author control narratives, the policy suite, and the evidence procedures that will survive a Type 2 observation window. Where you run a compliance automation platform, we configure it against the real control set rather than accepting the vendor default mapping.

Build, continued. We work with your engineering team on access reviews, change management, vulnerability handling, and vendor management — the four areas where exceptions most often appear in the final report.

Audit Sprint. We mock the auditor sample requests, close the gaps that would land as exceptions, and manage the evidence exchange during fieldwork. We are in the room for the walkthroughs, which shortens them considerably.

Steady State. A Type 2 is an annual obligation with a continuous observation window. We keep the evidence flowing, run access reviews on cadence, and prepare each period so the following audit reuses the program rather than reconstructing it.

Common failure modes

  • Choosing a twelve-month observation window when the customer would have accepted three
  • Automation platform evidence that does not match the control narrative the auditor is testing
  • Access reviews performed but not documented, which is the single most common Type 2 exception
  • Scoping in availability or privacy criteria that no customer asked for

Price range

Programs typically run between $25,000 and $60,000 for a Type 2 Build, depending on criteria in scope and the state of existing controls.

Related frameworks

Talk to us about your SOC 2.

Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.

Book a consultation