Compliance

SOC 2

SOC 2 is the assurance report enterprise and US customers expect from technology and service providers. It shows an independent auditor has tested your controls against the AICPA Trust Services Criteria.

SOC 2TYPE 2TRUSTSERVICESTESTED
100% success record

Every client we have taken through an accreditation has achieved it - and kept it at every renewal.

We never mark our own homework

We submit ourselves to independent third-party testing. Certification is always issued by an independent body, never by us.

Physical tests, not questionnaires

We prove each control works on your real devices and services. Questionnaire answers can be inaccurate or optimistic; tests cannot.

Free assessment of where you are

We will look at your current position for free and tell you exactly which controls you need - with no obligation.

What is SOC 2?

SOC 2 reports are issued by independent licensed CPA firms under standards set by the American Institute of CPAs (AICPA). Every report covers the Security criteria; you can add Availability, Processing Integrity, Confidentiality and Privacy.

A Type I report looks at the design of your controls at a point in time. A Type II report tests that they operated effectively over a period, typically three to twelve months - which is what most customers ask for.

Who needs it

The controls you will need

Control environment and governance

Policies, risk assessment, roles and oversight by management.

Logical and physical access

Joiners, movers and leavers, MFA, least privilege and access reviews.

System operations

Monitoring, vulnerability management and incident response.

Change management

Controlled, reviewed and tested changes to systems and code.

Risk mitigation and vendors

Business continuity, backups and supplier risk management.

The five Trust Services Criteria - and the controls we run for each

Every SOC 2 report covers Security. You choose which of the other four criteria your customers need. Whichever you pick, our engineers operate the controls behind them every day - not just document them.

SECURITYAVAILABILITYPROCESSINGINTEGRITYCONFIDENTIALITYPRIVACYSOC 2TRUST SERVICES
SecurityAlways in scope
  • Firewalls and network security
  • MFA and access control
  • Endpoint detection and response
  • Vulnerability and patch management
  • Intrusion detection and logging
AvailabilityOptional
  • Performance and capacity monitoring
  • Backups with tested restores
  • Disaster recovery and continuity
  • Security incident handling
Processing integrityOptional
  • Change management and quality assurance
  • Input and processing validation
  • Job and pipeline monitoring
ConfidentialityOptional
  • Encryption at rest and in transit
  • Data classification and retention
  • Secure disposal
PrivacyOptional
  • Privacy notice and consent
  • Data subject requests
  • Access to personal data limited
  • Maps closely to UK GDPR

Type 1 or Type 2?

Type 1Type 2
What the auditor checksYour controls are designed properlyYour controls worked, every day, across a period
Period coveredA single dateAn observation window, usually 3 to 12 months
Typical useA first milestone to unblock early dealsWhat most enterprise customers ask for
What it takesControls in place and documentedControls run consistently with evidence for the whole window
Where we help mostDesigning and implementing the controlsOperating and evidencing them continuously so nothing slips in the window
Why Total Group

Compliance software tells you what is broken. We fix it - and run it.

Compliance automation platforms are good at tracking controls and collecting evidence, but someone still has to operate the security behind the trust. That is what we do: we are the engineers running your controls, with the monitoring and evidence built in.

Compliance software on its ownTotal Group
Policy templates and evidence collection
Continuous monitoring of controls
Tells you when a control is failing
Fixes it - patches, reconfigures, enforces MFAYour team Our engineers
Runs the controls day to day - EDR, firewalls, backups, access reviewsYour team Our engineers
Physically tests controls before the auditor looks–
Compliant change management for every changeYour process Built in
Readiness through to the independent auditAuditor referral End to end

Your SOC 2 journey

  1. 1Free readiness assessment

    Where you stand against the criteria you need.

  2. 2Scope

    Systems, people and criteria in scope - kept as small as your customers allow.

  3. 3Remediate and operate

    We implement the missing controls and start running them.

  4. 4Type 1 (optional)

    A point-in-time report to unblock early deals.

  5. 5Observation window

    3 to 12 months of controls running with evidence captured continuously.

  6. 6Type 2 report

    Issued by an independent CPA firm - never by us.

  7. 7Stay continuous

    Monitoring, bridge letters and the next period, without the scramble.

One set of controls, many frameworks

The controls we run for SOC 2 are the same ones other standards test. We map the evidence once and reuse it, so adding the next framework is a fraction of the work.

How we get you there - and keep you there

  1. 1Free assessment

    We review your devices, cloud services and processes against SOC 2 and show you where you stand.

  2. 2Close the gaps

    We fix or guide you through every control that would fail, in priority order.

  3. 3Test physically

    We prove each control works - scans, patch checks, malware tests, restores and MFA checks - before anyone else looks.

  4. 4Independent sign-off

    An independent assessor, auditor or certification body confirms it. We never certify our own work.

  5. 5Stay compliant

    We monitor your controls in real time and fix drift as it happens, so renewal is a normal day, not a cliff edge.

What sets Total Group apart

Compliance monitored in real time - not checked once a year

Our own intellectual property is how we run compliance: we monitor the major SOC 2 controls in real time using the leading enterprise SaaS tools. That lets us map gaps and bridge controls quickly and accurately while you work towards accreditation - and then keep standards up, and risk down, every day after it.

Controls monitored in real time

We watch the major controls continuously using leading enterprise SaaS security and compliance tools - not once a year with a questionnaire.

Gaps mapped and bridged fast

Live data shows exactly which controls are missing or drifting, so we can map the gaps and bridge them quickly and accurately.

Compliant change management

Every change to your systems follows a compliant change process, so an upgrade or a new starter never quietly breaks a control.

Compliance that improves, not decays

Issues are picked up and fixed as they happen. Your risk goes down over the year instead of creeping up until the next audit.

HighLowaudit panic▬ Annual review▬ Total Group real-time monitoringControl health over 12 months
Annual review“We were compliant a year ago.”
  • Controls drift unnoticed for months
  • Renewal is a fraught cliff edge
  • Evidence is gathered in a rush
  • Risk rises until the next audit
Total Group real-time“We were compliant yesterday.”
  • Every major control watched continuously
  • Accreditation day is a normal day
  • Evidence is always current
  • Issues fixed as they happen, so compliance improves

Annual review is not viable in the current threat landscape. Attackers do not wait twelve months - so neither do we.

Stay compliant all year: Levels 1 to 3

Certification is a snapshot. Our compliance plans keep the controls tested, the evidence current and renewals handled - Level 1 demonstrates, Level 2 practises and Level 3 proves compliance continuously.

Level 1 - Demonstrate

CE and Digital GDPR Controls - Our consultants will complete the CE submission with input from your staff.

£163.50/month + VAT
£545 setup + VAT today, then 12 monthly Direct Debits of £196.20 inc VAT

Level 2 - Practice

CE, CE+ and Digital GDPR Controls -Monitoring & Submission as a Service (Submission following Quarter)

£599.50/month + VAT
£2,725 setup + VAT today, then 12 monthly Direct Debits of £719.40 inc VAT

Level 3 - Prove

CE, CE+, GDPR Governance, Supply Chain Audits, Pen Testing, Vulnerability Scanning, (Real-time Maintained) Compliance As A Service

£708.50/month + VAT
£4,360 setup + VAT today, then 12 monthly Direct Debits of £850.20 inc VAT

SOC 2 questions and answers

Can Total Group issue our SOC 2 report?

No - and that is deliberate. Reports must come from an independent CPA firm. We get you ready, run the controls and collect the evidence, so the audit confirms what we have already tested.

Type I or Type II?

Type I is quicker and proves design; Type II proves operation over time and is what most customers want. Many organisations do a Type I first, then a Type II.

How long does it take?

Readiness usually takes two to four months depending on your starting point; a Type II then needs an observation period of at least three months.

Does ISO 27001 overlap?

Heavily. Much of the control work is shared, so we design it once and map it to both.

Is SOC 2 a certification?

Strictly no - it is an attestation. An independent CPA firm gives an opinion on your controls in a report you share with customers under NDA. In practice people say "SOC 2 certified" to mean they hold a clean report.

What is the difference between SOC 1, SOC 2 and SOC 3?

SOC 1 covers controls relevant to your customers' financial reporting. SOC 2 covers security and the other Trust Services Criteria, and is the one technology buyers ask for. SOC 3 is a short public summary of a SOC 2 that you can publish on your website.

What is a bridge letter?

A letter from you covering the gap between the end of your last report period and today, confirming nothing material has changed. Because we monitor controls continuously, we can back it with live evidence rather than a promise.

We already use a compliance platform. Can you work with it?

Yes. Platforms track controls and evidence; we operate the controls they monitor - patching, access, endpoint protection, backups and change management - and fix what they flag. Many clients keep their platform and add us as the team that makes the tests pass.

What makes Total Group different from other compliance providers?

We monitor the major controls in real time using leading enterprise SaaS tools, with compliant change management behind every change. Gaps are found and bridged quickly, standards are maintained every day, and accreditation stops being a fraught cliff edge - you can say you were compliant yesterday, not a year ago.

Why is an annual review not enough?

Controls drift: devices miss patches, accounts change, new services appear. With an annual review that drift goes unnoticed for months while risk rises. Real-time monitoring catches it as it happens, so issues are fixed quickly and your compliance improves rather than decays.

Find out where you stand - free

Book a free, no-obligation SOC 2 assessment. We will show you which controls you already meet, which you need, and the quickest route to getting certified.

Free resources

Related compliance