Compliance · AICPA attestation

SOC 2 — Trust Services Criteria for security and privacy

The report your enterprise customers keep asking for.

SOC 2 is an AICPA attestation that shows an independent CPA firm examined your controls against the Trust Services Criteria. It is the report B2B buyers, procurement teams, and security questionnaires ask for most often. intSignal gets you audit-ready and supports you through the examination.

5

Trust Services Criteria

I & II

Report types

3–12 mo

Type II window

What SOC 2 actually covers

SOC 2 isn't a checklist you pass — it's an opinion on whether your controls are designed (Type I) and operating (Type II) effectively over time.

The five criteria

Security is always in scope. Availability, Processing Integrity, Confidentiality, and Privacy are optional — you choose based on what you promise customers. Adding criteria you don't need only widens the audit.

Type I vs. Type II

Type I says your controls were suitably designed at a point in time. Type II says they actually operated effectively across a window (commonly 3–12 months). Buyers increasingly insist on Type II.

Your controls, your scope

There is no fixed control list. You define the system boundary and controls that meet the criteria, and the auditor tests those. That flexibility is why scoping is the highest-leverage decision you make.

Who needs SOC 2

Typically any company that stores or processes customer data and sells to other businesses.

  • SaaS and technology companies losing deals to security review
  • Managed service and hosting providers
  • Fintech, healthtech, and HR platforms handling sensitive records
  • Any vendor whose enterprise customers demand a Type II report

How intSignal gets you there

We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.

Readiness assessment

We map your current controls to the criteria you're claiming and produce a prioritized gap list — no 400-page report you'll never read.

Scope definition

We help you draw the system boundary and pick criteria deliberately, so you aren't audited on promises you never made.

Control design & remediation

We implement the access, change-management, monitoring, and vendor controls the criteria expect — using your existing stack wherever possible.

Evidence automation

We wire evidence collection into your tooling so the Type II window doesn't become a year of manual screenshots.

Policy set

We write the policies auditors ask for and make sure they match what you actually do — mismatches are the most common finding.

Audit support

We help you select a CPA firm, run the request list, and respond to auditor questions so the examination doesn't stall your engineers.

How the engagement runs

1

Scope & readiness

Define the system, choose criteria, and assess current state against them.

2

Remediate gaps

Design and implement the missing controls, with owners and dates.

3

Operate & collect

Run the controls through the observation window while evidence accumulates automatically.

4

Examination

Your CPA firm tests the controls; we manage the request list and evidence.

5

Maintain

Keep controls running and evidence flowing so next year's report is routine, not a fire drill.

Frequently asked questions

How long does SOC 2 take?

Readiness typically runs 6–12 weeks depending on your gaps. A Type I can follow immediately. A Type II then requires an observation window — commonly 3 months for a first report, 12 months thereafter. Companies that start with clean tooling move considerably faster.

Should we do Type I or go straight to Type II?

If a customer needs proof now, a Type I buys credibility while you accumulate the Type II window. If you can wait, going straight to a 3-month Type II saves an audit fee and is what most buyers actually want.

Does intSignal issue the SOC 2 report?

No — only a licensed CPA firm can perform the examination and issue the report. intSignal makes you ready, builds and runs the controls, manages the evidence, and supports you through the audit. We'll help you select an audit firm, and we stay independent of it.

Which criteria should we include?

Security is mandatory. Add others only when you make a matching promise: Availability if you commit to uptime SLAs, Confidentiality if you handle customer-confidential data, Processing Integrity for transaction accuracy, and Privacy if you handle personal information under a published notice.

Can we reuse SOC 2 work for other frameworks?

Yes — that's the point. SOC 2 controls overlap heavily with ISO 27001, HITRUST, and CIS. We map controls once and reuse the evidence, which is how a second framework costs a fraction of the first.

Other frameworks we support

Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.

SOC 2 for your environment

Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.