SOC 2 · AICPA Trust Services Criteria

SOC 2, Run End to End

The report US enterprise buyers ask for before they sign. Auditara carries all 61 Trust Services Criteria, the full programme lifecycle, and the evidence trail your auditors will sample.

61 criteria across 13 themes22 activities across 4 phasesType I and Type II

Who Needs It

SaaS companies selling into the US

SOC 2 is the default ask in American enterprise procurement and security reviews.

Companies losing deals to security questionnaires

A current Type II report answers most of the questionnaire before it is sent.

Vendors to fintech and healthtech

Upstream customers pass their own compliance obligations down the chain.

Teams already holding ISO 27001

The control overlap is large; many companies run both from the same evidence base.

What It Is

SOC 2 is an attestation framework from the AICPA. A licensed CPA firm examines your organisation against the Trust Services Criteria and issues a report: Type I on the design of your controls at a point in time, Type II on how they operated over a period, usually three to twelve months. Type II is what enterprise customers normally expect.

Security is always in scope. Availability, Confidentiality, Processing Integrity, and Privacy are added only where your commitments to customers justify them. The result is a confidential report you share with customers, usually under NDA; there is no public certificate.

What Is Inside Auditara

Every criterion, assessable

All 61 Trust Services Criteria built in across 13 themes, with plain English guidance and the optional categories handled through scoping.

The programme lifecycle

22 activities across 4 phases, from scope and report-type decisions through the observation period to fieldwork support.

Documents and policies

Your policy set generated from intake answers with approval workflow and branded Word and PDF export.

The evidence trail

Evidence attached where the work happens across the observation period, organised for sampling, with a read-only auditor room when fieldwork starts.

How It Works

Step 1

Scope It

Choose Type I or Type II and the criteria categories your customer commitments require. The assessment scopes itself accordingly.

Step 2

Operate and Evidence

Score every criterion, close the gaps with owners and dates, and let evidence accumulate across the observation period instead of scrambling at the end.

Step 3

Support the Examination

A CPA firm samples your evidence and interviews your team. The organised trail and auditor room make fieldwork the calm part.

Two Ways to Run It

At Your Own Pace

Readiness Workspace: the guided workspace, free to start, opened after your onboarding call.

With Us Delivering

Guided Implementation: we run the programme with you to audit readiness, with a written guarantee. Scope is agreed on your onboarding call.

Every route starts with a call with a certified ISO 27001 and ISO 42001 Lead Implementer.

Book A Call

Questions

What is the difference between SOC 2 and ISO 27001?

ISO 27001 is a certification issued by an accredited certification body and recognised globally. SOC 2 is an attestation report from a CPA firm, dominant in the US market. Many companies hold both; the underlying controls overlap heavily and Auditara runs both from one workspace.

Type I or Type II?

Type I covers control design at a point in time and is faster. Type II covers operation over a period, usually three to twelve months, and is what enterprise buyers typically expect.

Who issues the SOC 2 report?

A licensed CPA firm engaged by you. Auditara prepares you, keeps the evidence organised, and supports fieldwork. The firm's fees are separate.

Which criteria categories do we need?

Security always applies. Add Availability, Confidentiality, Processing Integrity, or Privacy only where your service commitments justify them; the onboarding call settles this in minutes.

Can we run SOC 2 and ISO 27001 together?

Yes, in one workspace, and most of the evidence serves both.

Ready for the Report Buyers Ask For?

Readiness Workspace is free to start. Guided Implementation adds delivery to audit readiness, agreed with you on the call.

Written Readiness GuaranteeDelivered by a PECB Certified Lead Auditor and Lead ImplementerAll 61 Criteria Built In

See all frameworks