SOC 2 is the assurance report enterprise and US customers expect from technology and service providers. It shows an independent auditor has tested your controls against the AICPA Trust Services Criteria.
Every client we have taken through an accreditation has achieved it - and kept it at every renewal.
We submit ourselves to independent third-party testing. Certification is always issued by an independent body, never by us.
We prove each control works on your real devices and services. Questionnaire answers can be inaccurate or optimistic; tests cannot.
We will look at your current position for free and tell you exactly which controls you need - with no obligation.
SOC 2 reports are issued by independent licensed CPA firms under standards set by the American Institute of CPAs (AICPA). Every report covers the Security criteria; you can add Availability, Processing Integrity, Confidentiality and Privacy.
A Type I report looks at the design of your controls at a point in time. A Type II report tests that they operated effectively over a period, typically three to twelve months - which is what most customers ask for.
Policies, risk assessment, roles and oversight by management.
Joiners, movers and leavers, MFA, least privilege and access reviews.
Monitoring, vulnerability management and incident response.
Controlled, reviewed and tested changes to systems and code.
Business continuity, backups and supplier risk management.
Every SOC 2 report covers Security. You choose which of the other four criteria your customers need. Whichever you pick, our engineers operate the controls behind them every day - not just document them.
| Type 1 | Type 2 | |
|---|---|---|
| What the auditor checks | Your controls are designed properly | Your controls worked, every day, across a period |
| Period covered | A single date | An observation window, usually 3 to 12 months |
| Typical use | A first milestone to unblock early deals | What most enterprise customers ask for |
| What it takes | Controls in place and documented | Controls run consistently with evidence for the whole window |
| Where we help most | Designing and implementing the controls | Operating and evidencing them continuously so nothing slips in the window |
Compliance automation platforms are good at tracking controls and collecting evidence, but someone still has to operate the security behind the trust. That is what we do: we are the engineers running your controls, with the monitoring and evidence built in.
| Compliance software on its own | Total Group | |
|---|---|---|
| Policy templates and evidence collection | ||
| Continuous monitoring of controls | ||
| Tells you when a control is failing | ||
| Fixes it - patches, reconfigures, enforces MFA | Your team | Our engineers |
| Runs the controls day to day - EDR, firewalls, backups, access reviews | Your team | Our engineers |
| Physically tests controls before the auditor looks | – | |
| Compliant change management for every change | Your process | Built in |
| Readiness through to the independent audit | Auditor referral | End to end |
Where you stand against the criteria you need.
Systems, people and criteria in scope - kept as small as your customers allow.
We implement the missing controls and start running them.
A point-in-time report to unblock early deals.
3 to 12 months of controls running with evidence captured continuously.
Issued by an independent CPA firm - never by us.
Monitoring, bridge letters and the next period, without the scramble.
The controls we run for SOC 2 are the same ones other standards test. We map the evidence once and reuse it, so adding the next framework is a fraction of the work.
We review your devices, cloud services and processes against SOC 2 and show you where you stand.
We fix or guide you through every control that would fail, in priority order.
We prove each control works - scans, patch checks, malware tests, restores and MFA checks - before anyone else looks.
An independent assessor, auditor or certification body confirms it. We never certify our own work.
We monitor your controls in real time and fix drift as it happens, so renewal is a normal day, not a cliff edge.
Our own intellectual property is how we run compliance: we monitor the major SOC 2 controls in real time using the leading enterprise SaaS tools. That lets us map gaps and bridge controls quickly and accurately while you work towards accreditation - and then keep standards up, and risk down, every day after it.
We watch the major controls continuously using leading enterprise SaaS security and compliance tools - not once a year with a questionnaire.
Live data shows exactly which controls are missing or drifting, so we can map the gaps and bridge them quickly and accurately.
Every change to your systems follows a compliant change process, so an upgrade or a new starter never quietly breaks a control.
Issues are picked up and fixed as they happen. Your risk goes down over the year instead of creeping up until the next audit.
Annual review is not viable in the current threat landscape. Attackers do not wait twelve months - so neither do we.
Certification is a snapshot. Our compliance plans keep the controls tested, the evidence current and renewals handled - Level 1 demonstrates, Level 2 practises and Level 3 proves compliance continuously.
CE and Digital GDPR Controls - Our consultants will complete the CE submission with input from your staff.
CE, CE+ and Digital GDPR Controls -Monitoring & Submission as a Service (Submission following Quarter)
CE, CE+, GDPR Governance, Supply Chain Audits, Pen Testing, Vulnerability Scanning, (Real-time Maintained) Compliance As A Service
No - and that is deliberate. Reports must come from an independent CPA firm. We get you ready, run the controls and collect the evidence, so the audit confirms what we have already tested.
Type I is quicker and proves design; Type II proves operation over time and is what most customers want. Many organisations do a Type I first, then a Type II.
Readiness usually takes two to four months depending on your starting point; a Type II then needs an observation period of at least three months.
Heavily. Much of the control work is shared, so we design it once and map it to both.
Strictly no - it is an attestation. An independent CPA firm gives an opinion on your controls in a report you share with customers under NDA. In practice people say "SOC 2 certified" to mean they hold a clean report.
SOC 1 covers controls relevant to your customers' financial reporting. SOC 2 covers security and the other Trust Services Criteria, and is the one technology buyers ask for. SOC 3 is a short public summary of a SOC 2 that you can publish on your website.
A letter from you covering the gap between the end of your last report period and today, confirming nothing material has changed. Because we monitor controls continuously, we can back it with live evidence rather than a promise.
Yes. Platforms track controls and evidence; we operate the controls they monitor - patching, access, endpoint protection, backups and change management - and fix what they flag. Many clients keep their platform and add us as the team that makes the tests pass.
We monitor the major controls in real time using leading enterprise SaaS tools, with compliant change management behind every change. Gaps are found and bridged quickly, standards are maintained every day, and accreditation stops being a fraught cliff edge - you can say you were compliant yesterday, not a year ago.
Controls drift: devices miss patches, accounts change, new services appear. With an annual review that drift goes unnoticed for months while risk rises. Real-time monitoring catches it as it happens, so issues are fixed quickly and your compliance improves rather than decays.
Book a free, no-obligation SOC 2 assessment. We will show you which controls you already meet, which you need, and the quickest route to getting certified.