Skip to content

SOC 2

Get SOC 2 ready and pass the examination US enterprise buyers ask for.

Trust Criteria Gap

Assessed against the Trust Services Criteria

Type I & II Readiness

Prepared for point-in-time and period reports

CPA-Firm Liaison

We manage the examining CPA firm for you

SOC 2 Specialists

Experienced readiness practitioners

SOC 2 compliance and audit

What it is

SOC 2 is an AICPA attestation report on a service organisation's controls relevant to security and, optionally, availability, processing integrity, confidentiality and privacy. A Type I report tests control design at a point in time; a Type II report tests design and operating effectiveness over a period, and is the de facto trust signal US enterprise buyers ask for.

Who must comply

US-market B2B SaaS and technology vendors, data processors and any service organisation whose customers demand SOC 2, usually surfaced during enterprise procurement or vendor-risk reviews.

How IntelligenceX helps

Readiness assessment against the Trust Services Criteria
Control, policy and evidence-collection setup
Gap remediation and system-description drafting
Liaison with the auditing CPA firm
Evidence-automation and control-monitoring tooling setup
Auditor selection support and post-report bridge-letter guidance
Gap AssessmentISMS DesignInternal AuditStage 1 & 2 SupportRemediation GuidanceCertification Readiness

Frequently Asked Questions

Type I proves your controls are designed correctly today and is faster. Type II proves they operated over 6-12 months and is what most enterprise buyers ultimately require. We often deliver Type I, then run the observation window into Type II.

Type I readiness runs 6-10 weeks; Type II adds the observation period. Budget separately for our readiness work and the CPA firm's examination fee, which we help you scope.

Security (the Common Criteria) is mandatory; availability, confidentiality, processing integrity and privacy are optional and chosen to match what you actually promise customers. We scope only the categories your contracts and risk profile require, so the examination stays focused and the cost stays proportionate.

Talk to a security expert today

A penetration test, an audit, or 24/7 monitoring, our team is ready across the UK, USA, EU and India.