SOC 2

SOC 2 readiness assessment and remediation

We find the gaps between your controls and the SOC 2 Trust Services Criteria, help you close them and prepare your evidence. When your independent CPA firm starts the audit, your team is ready for it.

  • Readiness for Type 1 and Type 2 reports
  • Remediation by our engineers or yours
  • Proven with a 200+ person accounting firm
Team reviewing findings around a conference table

SOC 2 programs delivered

Including accounting and tax firms growing fast

Controls we can operate

MFA, SOC monitoring, backups and endpoint management

Top virtual CISO services company

Recognized by Cyber Security Review

Two colleagues reviewing financial reports

What SOC 2 readiness means

Get ready before the auditor arrives

A SOC 2 report is an independent attestation, issued by a licensed CPA firm, on how well your controls meet the AICPA Trust Services Criteria. Security is required in every SOC 2. Availability, processing integrity, confidentiality and privacy are added when they matter to your customers.

Triden does not issue SOC 2 reports. Our role is to prepare you. A SOC 2 readiness assessment shows where you fall short before the audit starts, when gaps are still cheap to fix and do not show up as exceptions in your report.

What’s included

SOC 2 readiness services from scoping to audit support

How it works

The path to your SOC 2 report

1

Discovery and scoping

We learn your environment, your customers’ expectations and which criteria belong in scope.

2

Readiness assessment

We test your controls against the criteria and deliver a prioritized gap list with a remediation plan.

3

Remediate

Policies, technical controls and processes are put in place and start producing evidence.

4

Audit

Your CPA firm performs a Type 1 or Type 2 examination while we support your team through it.

Type 1 vs Type 2

Which SOC 2 report do you need?

A Type 1 report looks at whether your controls are designed properly at a single point in time. A Type 2 report tests whether those controls operated effectively over a period, commonly several months to a year.

Many customers ask for Type 2. Some companies start with Type 1 to meet a near-term sales need, then move to Type 2 once controls have run long enough to be tested. We help you choose based on what your customers are asking for.

At a glance

Type 1 and Type 2

Both are issued by an independent CPA firm against the same criteria.

  • Type 1: control design at a point in time
  • Type 2: design and operating effectiveness over a period
  • Type 2 needs controls in place before the period starts

Case study

SOC 2 compliance for a Southern California accounting firm

An accounting firm with more than 200 professionals across Los Angeles and Orange County handles client financial data and personal information every day. It needed SOC 2 compliance and a security program that could grow with it.

We assessed its infrastructure, ran a readiness assessment and mapped the path to SOC 2. We implemented multi-factor authentication, segmented personal data behind 24/7 SOC services and later added immutable backups. The firm now keeps us on as its vCISO.

  • A SOC 2 compliant environment that protects client data
  • Immutable backups that keep ransomware from halting the business
  • Ongoing vCISO guidance on policy, risk and compliance

FAQ

SOC 2 readiness questions

It’s a review of your controls against the SOC 2 Trust Services Criteria before a formal audit. It identifies gaps and gives you a remediation plan so your audit has fewer exceptions.

Type 1 evaluates whether your controls are designed correctly at one point in time. Type 2 tests whether they operated effectively over a review period. Type 2 takes longer but is what many customers ask for.

It depends on how many gaps you start with. Organizations with mature controls can be ready in a few months, while others need longer for remediation. A Type 2 also requires controls to run through the full review period.

Cost depends on the size of your environment, the criteria in scope, how many gaps need fixing and whether our engineers do the remediation. The CPA firm’s audit fee is separate. We give you a fixed proposal after scoping.

No. Only an independent CPA firm can issue a SOC 2 report. We prepare you for the audit and support you through it, which keeps our advice independent of the auditor’s opinion.

Many do, because their clients and partners ask for proof that financial data is protected. Tax firms also need a written information security plan. See our work with accounting and tax firms.

Talk to a SOC 2 expert

Start your SOC 2 readiness assessment

Tell us about your customers and your timeline and an advisor will reply by email to scope your readiness work.

  • Advice on Type 1 or Type 2 for your situation
  • A fixed proposal for readiness and remediation

Prefer email? Write to [email protected] or call (858) 712-0040.

Send us a message