Service organization assurance

SOC 2 readiness for service organizations

Build an examinable control environment for the service you actually deliver. We help technology teams define the system, operate controls, and prepare evidence for an independent CPA examination.

Our implementation focus

Make the requirements operational.

  1. 01

    Define the system boundary and reporting goals

  2. 02

    Map risks to applicable Trust Services Criteria

  3. 03

    Implement and assign control owners

  4. 04

    Establish evidence collection and exception handling

  5. 05

    Prepare the system description and auditor handoff

Independent assessment

SOC 2 produces an independent attestation report, not a certification. A licensed CPA firm performs the examination.

Questions we hear

Get the distinctions right.

Is SOC 2 a certification?

No. SOC 2 is an attestation examination performed by an independent licensed CPA firm. The outcome is a report on a described system and its controls.

Can a company outside the United States pursue SOC 2?

Yes. The decision is usually driven by customer assurance needs rather than the company’s home country. Reporting scope and criteria should reflect the actual service and its users.

How does SOC 2 relate to ISO/IEC 27001?

The same operating controls can support both efforts, but the outcomes differ: SOC 2 is a report on a service organization system; ISO/IEC 27001 sets requirements for an information security management system.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation