Frameworks · SOC 2 (Type I / Type II)
SOC 2: prove your service’s security with an independent attestation.
We prepare you for a SOC 2 attestation (Type I or Type II) — with operational controls and evidence ready for the auditor.
Who it applies to
SOC 2 applies to technology and service companies that process their customers’ data and need to demonstrate reliable controls, especially to sell to enterprise customers.
What the framework requires
SOC 2 evaluates the design and operation of controls against the Trust Services Criteria. It’s not a certification: a CPA issues an attestation report (Type I on the design, Type II on the operation over a period).
Trust Services Criteria
Type I vs Type II
Operational controls
Auditor’s report
Risks of not acting
- Losing enterprise sales opportunities that require SOC 2.
- Answering every security questionnaire from scratch.
- Reaching the audit without evidence of the controls operating.
- Confusing scope and report type, and redoing the work.
The i-Prot proposal
We define the scope and criteria, design and implement the controls, and assemble the evidence so the CPA can issue your SOC 2 report. Integrated into the CGF cycle, with a focus on a sustainable Type II.
How we work with this framework
Scope and criteria
Control design
Implementation and evidence
Readiness
Attestation and upkeep
Deliverables
- Gap analysis
- Implementation plan
- Controls matrix
- System documentation
- Evidence
- Internal audit
- Management review
- Roadmap
How it connects with CGF
CGF uses SOC 2 as a source of requirements. This framework mainly covers the Design, Implement, Operate & measure, and Improve stages of the cycle.
See the CGF methodology →
Complyze and SOC 2
Complyze centralizes the controls, their operational evidence and the status by criterion, so you reach the attestation with everything ready.
Frequently asked questions
Ready for your SOC 2 report?
Tell us your service and your target customers, and we’ll define the scope.
By submitting you accept our privacy policy.