Trust services · Global (US-origin)SOC 2
SOC 2 (AICPA Trust Services Criteria)
An attestation report by a CPA firm on how well a service organisation's controls meet the AICPA Trust Services Criteria.
5
trust criteria
Type I / II
report kinds
6-12 mo
Type II window
SOC 2
Security
required
Availability
Processing integrity
Confidentiality
Privacy
Trust Services Criteria
Why it matters
The default assurance SaaS buyers ask for in North America. A Type II report is often required before a deal closes.
Who it's for
Service organisations that store or process customer data and need to give customers assurance over their controls.
The journey
How you get to SOC 2
- 1Pick criteriaSecurity + any others
- 2ReadinessGap assessment
- 3RemediateClose control gaps
- 4ObservationType II evidence window
- 5FieldworkCPA testing
- 6ReportAnnual renewal
On Compliverse
SOC 2, worked in the platform
Get the evidence you need
The AI recommends which evidence answers each SOC 2 control, ready to confirm.
See what's missing
Gaps and missing artifacts surface on their own, not the week of the audit.
Create from templates
Spin up policies, assessments and charters from standard templates, then tailor them to your scope.
Collected once, reused
One artifact satisfies this framework and every other it maps to.
Get SOC 2-ready on your own stack.
Demos are scoped to your frameworks. Pick a slot and we'll run SOC 2 live.