Governance, Risk & Compliance

SOC 2 is not a badge. It is a CPA’s opinion on your controls.

SOC 2 produces a report, not a certificate, and only a licensed CPA firm can issue it. Our job is upstream of that: design the controls against the Trust Services Criteria you actually need, build the evidence trail, and make the audit a formality rather than a discovery process.

Type I one date · design only Type II 3–12 months · evidence accumulating operating effectiveness, sampled by the auditor A report, not a certificate issued by a licensed CPA firm
5Trust Services Criteria
1That is mandatory
3–12 moType II observation window
0Reports we issue

Why the wording matters more than it sounds

SOC 2 is an attestation performed under AICPA standards. A licensed CPA firm examines your controls and issues a report containing their opinion. There is no certificate, no certification body, and no such thing as being "SOC 2 certified" — which is why enterprise procurement teams ask to see the actual report and check who signed it. A vendor whose website claims certification is telling a security reviewer something useful about their rigour before the review has even started.

The second thing buyers underestimate is the observation window. A Type I report says your controls were suitably designed on one specific date. A Type II report says they operated effectively across a period — typically three to twelve months, most commonly six for a first report. That window is real elapsed time during which the controls have to actually run, and evidence has to actually accumulate. It cannot be compressed by working harder in the final fortnight.

The third is scope. Security is the only mandatory criterion. Availability, Processing Integrity, Confidentiality and Privacy are scoped in based on what your product does and what your contracts commit you to. Platforms that bundle all five as standard are selling you audit hours you may not need, and every additional criterion is additional cost in perpetuity.

Coverage

The five criteria, and which ones you actually need

We scope to the commitments in your contracts and the questions in your customers’ security questionnaires — not to whatever produces the largest engagement.

Security — mandatory

The common criteria: access control, change management, risk assessment, monitoring, incident response and vendor management. Every SOC 2 report includes this, and for many companies it is the only criterion required.

Availability

Relevant when you have made uptime commitments in a contract or SLA. Covers capacity planning, environmental protection, backup and disaster recovery.

Processing Integrity

Relevant where your product processes transactions or performs calculations customers rely on for accuracy and completeness. Frequently not needed, and frequently sold anyway.

Confidentiality

Data classification, encryption in transit and at rest, retention and secure disposal — for information designated confidential by agreement.

Privacy

Notice, choice and consent, collection, use, retention and disclosure of personal information. Distinct from Confidentiality, and often confused with it during scoping.

Type I versus Type II

Type I tests design at a point in time and is sometimes used as an interim milestone. Type II tests operating effectiveness over a window and is what most enterprise buyers actually mean when they ask for a SOC 2.

Approach

How a SOC 2 programme runs

The readiness work is ours. The examination is your auditor’s. We are explicit about the boundary, and we work alongside your chosen CPA firm rather than around them.

  1. 01 · Readiness assessment and scoping

    Which criteria you genuinely need, whether Type I is a useful milestone or a distraction, and an honest gap list against current-state controls.

  2. 02 · Control design and remediation

    Close the gaps — access reviews, change management, logging, vendor risk, onboarding and offboarding — grounded in what testing actually found rather than what a template assumed.

  3. 03 · Policy and evidence framework

    Policies that describe what you really do, plus the collection cadence your auditor will sample against. Evidence that has to be assembled by hand will be assembled badly, once.

  4. 04 · Type I examination, if useful

    A point-in-time report for buyers who need something now while the Type II window runs. Optional, and we will tell you when it is not worth the money.

  5. 05 · Observation window support

    The three to twelve months where controls have to operate rather than exist. We keep evidence collection on schedule and flag drift early, while it is still cheap to fix.

  6. 06 · Audit liaison and reporting

    We work directly with your CPA firm through fieldwork and sampling. They test independently and they issue the report — that independence is the entire value of the thing.

Run against recognised standards

  • AICPA Trust Services CriteriaThe criteria the examination is performed against
  • COSO Internal Control frameworkThe control model the common criteria are built on
  • ISO/IEC 27001:2022Cross-mapped for organisations pursuing both
  • NIST CSF 2.0Cross-mapped where a maturity view is also required
  • CIS BenchmarksConfiguration baselines behind the technical criteria

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Scoped criteria recommendation

Which Trust Services Criteria your contracts actually require, in writing, with the reasoning — so you are not paying to be audited against criteria nobody asked for.

Control matrix

Every control mapped to the criteria it satisfies, with an owner, a frequency and the evidence it produces.

Policy set

Access, change management, incident response, vendor risk, business continuity and development — written for your organisation.

Evidence trail

Organised and dated for CPA sampling, collected continuously rather than reconstructed in the week before fieldwork.

Audit-ready package

Handed to your CPA firm with nothing left for them to discover, so fieldwork is examination rather than excavation.

Observation-window monitoring

Control drift flagged during the window, while it can still be corrected without restarting the period.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • A North American customer has made SOC 2 a condition of signing.
  • You are filling in security questionnaires by hand every week and losing days to it.
  • You were quoted for all five Trust Services Criteria and nobody explained why.
  • You have started a Type II window without a working evidence-collection process.
  • You need ISO 27001 and SOC 2 for different customers and want the controls built once.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

SOC 2 — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Does SemperWise issue the SOC 2 report?

No. SOC 2 reports are issued only by licensed CPA firms under AICPA attestation standards. We do the readiness, control design and evidence work that gets you through the examination cleanly, and we work alongside the CPA firm you appoint. If a consultancy tells you they can issue the report, they are describing something that does not exist.

Is SOC 2 a certification?

No, and the distinction is worth getting right before a customer corrects you. SOC 2 produces an attestation report containing a CPA firm’s opinion, valid for the period examined. There is no certificate and no certification body. Enterprise buyers ask for the report itself, not a logo.

Type I or Type II — which do we need?

Almost always Type II. Type I only confirms that controls were suitably designed on a single date, which is a weak signal and one sophisticated buyers discount accordingly. Type I earns its place as an interim deliverable when a deal is waiting and the Type II window has months left to run.

How long does a Type II report take?

The observation window itself is typically three to twelve months, most commonly six for a first report (as of August 2026), and readiness work happens before it starts. Budget realistically: readiness, then the window, then fieldwork and report issuance. Starting the window before evidence collection works is the most common and most expensive mistake.

Do we need all five Trust Services Criteria?

No. Security is mandatory. Availability, Processing Integrity, Confidentiality and Privacy are scoped based on your product and your contractual commitments. Each additional criterion adds audit cost every year, so they should be added because a customer requires them, not because they were on a package.

Can we run SOC 2 and ISO 27001 together?

Yes, and it is usually the right call if both are on the horizon. The control overlap is substantial — access management, change control, risk assessment, vendor management and incident response serve both. We map shared evidence once so you are not running two disconnected programmes over the same systems.

Is SOC 2 relevant if we only sell in India?

Usually not as a priority. ISO 27001 carries more weight with Indian, European and Middle Eastern buyers and tender processes, and DPDP Act readiness is a legal obligation rather than a commercial preference. SOC 2 becomes relevant the moment US or global SaaS buyers enter your pipeline.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.