Compliance · AICPA attestation
The report your enterprise customers keep asking for.
SOC 2 is an AICPA attestation that shows an independent CPA firm examined your controls against the Trust Services Criteria. It is the report B2B buyers, procurement teams, and security questionnaires ask for most often. intSignal gets you audit-ready and supports you through the examination.
5
Trust Services Criteria
I & II
Report types
3–12 mo
Type II window
SOC 2 isn't a checklist you pass — it's an opinion on whether your controls are designed (Type I) and operating (Type II) effectively over time.
Security is always in scope. Availability, Processing Integrity, Confidentiality, and Privacy are optional — you choose based on what you promise customers. Adding criteria you don't need only widens the audit.
Type I says your controls were suitably designed at a point in time. Type II says they actually operated effectively across a window (commonly 3–12 months). Buyers increasingly insist on Type II.
There is no fixed control list. You define the system boundary and controls that meet the criteria, and the auditor tests those. That flexibility is why scoping is the highest-leverage decision you make.
Typically any company that stores or processes customer data and sells to other businesses.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We map your current controls to the criteria you're claiming and produce a prioritized gap list — no 400-page report you'll never read.
We help you draw the system boundary and pick criteria deliberately, so you aren't audited on promises you never made.
We implement the access, change-management, monitoring, and vendor controls the criteria expect — using your existing stack wherever possible.
We wire evidence collection into your tooling so the Type II window doesn't become a year of manual screenshots.
We write the policies auditors ask for and make sure they match what you actually do — mismatches are the most common finding.
We help you select a CPA firm, run the request list, and respond to auditor questions so the examination doesn't stall your engineers.
Define the system, choose criteria, and assess current state against them.
Design and implement the missing controls, with owners and dates.
Run the controls through the observation window while evidence accumulates automatically.
Your CPA firm tests the controls; we manage the request list and evidence.
Keep controls running and evidence flowing so next year's report is routine, not a fire drill.
Readiness typically runs 6–12 weeks depending on your gaps. A Type I can follow immediately. A Type II then requires an observation window — commonly 3 months for a first report, 12 months thereafter. Companies that start with clean tooling move considerably faster.
If a customer needs proof now, a Type I buys credibility while you accumulate the Type II window. If you can wait, going straight to a 3-month Type II saves an audit fee and is what most buyers actually want.
No — only a licensed CPA firm can perform the examination and issue the report. intSignal makes you ready, builds and runs the controls, manages the evidence, and supports you through the audit. We'll help you select an audit firm, and we stay independent of it.
Security is mandatory. Add others only when you make a matching promise: Availability if you commit to uptime SLAs, Confidentiality if you handle customer-confidential data, Processing Integrity for transaction accuracy, and Privacy if you handle personal information under a published notice.
Yes — that's the point. SOC 2 controls overlap heavily with ISO 27001, HITRUST, and CIS. We map controls once and reuse the evidence, which is how a second framework costs a fraction of the first.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.