BY BUSINESS OBJECTIVE
ASSESS & VALIDATE — FIND WEAKNESSES
Digisecuritas logo

COMPLIANCE & FRAMEWORK

SOC 2 readiness and control assessment

A SOC 2 examination evaluates controls within a service organisation's system against applicable Trust Services Criteria.

Digisecuritas helps organisations define the system boundary, select relevant criteria, assess control design, organise evidence, address gaps, and prepare for an independent Type 1 or Type 2 examination.

Clear scope. Owned controls. Examination ready evidence.

CONTROL TO EVIDENCE

Service commitmentWhat the organisation promises customers
RiskWhat could prevent meeting the commitment
ControlActivity that reduces the identified risk
EvidenceRecord showing the control operated
CPA examinationIndependent assessment by licensed CPA firm
Customer assurance

SOC 2 assurance path connecting customer commitments, risks, controls, evidence, and independent examination

THE SYSTEM IN SCOPE

The examination covers the system used to deliver the service

SOC 2 scope should reflect the service customers rely on and the controls supporting that service. A vague or oversized scope creates unnecessary effort. A scope that excludes important dependencies may fail to address customer concerns.

SYSTEM BOUNDARY

Services

The products, platforms, managed services, or business processes covered by the report.

Infrastructure

Cloud resources, networks, systems, endpoints, facilities, and supporting technology.

Software

Applications, code, configurations, integrations, deployment processes, and supporting tools.

People and procedures

Employees, contractors, responsibilities, policies, operational processes, and review activities.

Data

Information collected, processed, stored, transmitted, retained, or deleted through the service.

Subservice organisations

External providers whose services are relevant to the system, including cloud platforms, data centres, and managed service providers.

Subservice organisations and customer responsibilities

Cloud providersData centresManaged servicesPayment or communication providersComplementary user entity controls

TRUST SERVICES CRITERIA

Select criteria according to the service and customer commitments

SOC 2 examinations address controls relevant to Security and may also include Availability, Processing Integrity, Confidentiality, or Privacy according to the system and engagement scope.

SECURITY — REQUIRED

Security

Addresses protection against unauthorised access, use, or disclosure that could affect the organisation's ability to meet its commitments.

Typical areas

  • Governance and risk assessment
  • Logical and physical access
  • System operations
  • Change management
  • Risk mitigation
  • Vendor oversight

Availability

Addresses whether the system is available for operation and use according to commitments.

Processing integrity

Addresses whether system processing is complete, valid, accurate, timely, and authorised according to commitments.

Confidentiality

Addresses protection of information designated as confidential.

Privacy

Addresses the collection, use, retention, disclosure, and disposal of personal information according to relevant commitments and criteria.

More categories create a broader examination scope. They should be included because the service and customer commitments require them.

EXAMINATION TYPE

Type 1 or Type 2

SHARED PREPARATION

ScopeCriteriaRisksControlsEvidence

POINT IN TIME

SOC 2 Type 1

Evaluates the description of the service organisation's system and the suitability of control design at a specified date.

Useful when

  • The control environment is newly established
  • Customers need an initial report
  • The organisation is beginning its assurance programme
  • Management wants a point in time assessment before Type 2

Evidence focus: Control design and implementation as of the specified date.

PERIOD OF TIME

SOC 2 Type 2

Evaluates the system description, suitability of control design, and operating effectiveness of controls over a defined period.

Useful when

  • Customers require evidence of sustained control operation
  • Controls have operated long enough to be tested
  • The organisation has a mature evidence process
  • Ongoing assurance is expected

Evidence focus: Control design and operating evidence across the review period.

The appropriate report type depends on customer needs, control readiness, evidence history, and the CPA firm's examination plan.

CONTROL TRACEABILITY

Every control should support a defined risk and commitment

Controls become difficult to defend when they exist as an isolated checklist. A stronger control environment shows how service commitments, risks, controls, ownership, and evidence connect.

01

Commitment

What has the organisation promised customers about security, availability, confidentiality, processing, or privacy?

02

Risk

What could prevent the organisation from meeting that commitment?

03

Control

Which activity reduces the identified risk?

04

Owner

Who performs, reviews, and remains accountable for the control?

05

Evidence

What record shows that the control operated as described?

ILLUSTRATIVE EXAMPLE

Commitment

Production access is restricted

Risk

Inappropriate access could affect customer data

Control

Access is approved and reviewed

Owner

Security and engineering

Evidence

Approval record and access review

CONTROL DOMAINS

Common control domains

Governance

Organisational oversight

Policies, risk assessment, leadership responsibility, communication, monitoring, and corrective action.

Workforce management

Screening, confidentiality, awareness, training, role changes, and termination procedures.

Access and infrastructure

Identity and access

Account provisioning, authentication, privileged access, access reviews, and timely removal.

Infrastructure security

Secure configuration, vulnerability management, endpoint protection, network controls, and encryption.

Software and operations

Change management

Code review, testing, approval, deployment, emergency changes, and separation of responsibilities.

Security operations

Logging, monitoring, alerting, incident escalation, backup, recovery, and operational review.

External and information risk

Vendor management

Due diligence, contracts, security review, monitoring, and service termination.

Data governance

Classification, access, retention, deletion, confidentiality, privacy, and secure transfer.

DESCRIPTION CRITERIA

The system description should match how the service operates

Management prepares the description of the service organisation's system. It gives report users the context needed to understand the services, system boundaries, controls, commitments, risks, and relevant dependencies.

SYSTEM DESCRIPTION — DOCUMENT SECTIONS
01Types of services provided
02Principal service commitments and system requirements
03Components of the system
04System boundaries
05Relevant incidents and changes
06Applicable Trust Services Criteria
07Complementary user entity controls
08Subservice organisation responsibilities

The description should be consistent with policies, architecture, operations, and evidence.

OUR SERVICES

SOC 2 readiness and consulting services

Scope and readiness

SERVICE 01

SOC 2 scoping and criteria selection

Define the service, system boundary, report users, applicable Trust Services Criteria categories, and key dependencies.

Typical outputs

Scope statementSystem boundaryCriteria recommendationResponsibility map

SERVICE 02

SOC 2 readiness assessment

Evaluate current controls, documentation, evidence, and operating practices before the CPA examination.

Typical outputs

Readiness findingsControl gap registerEvidence observationsRemediation priorities
Controls and evidence

SERVICE 03

Control design and mapping

Connect commitments, risks, Trust Services Criteria, controls, owners, and evidence.

Typical outputs

Control matrixOwnership recordsEvidence requirementsControl improvement plan

SERVICE 04

Evidence readiness and review

Assess whether evidence is complete, consistent, timely, and aligned with the stated control.

Typical outputs

Evidence registerSample reviewMissing evidence logReadiness status
Testing and preparation

SERVICE 05

Readiness testing and remediation

Test control performance before the examination and help owners correct identified weaknesses.

Typical outputs

Testing observationsException registerRemediation roadmapRetest results

SERVICE 06

Type 1 and Type 2 examination preparation

Support management through system description preparation, evidence organisation, request coordination, and issue tracking.

Typical outputs

Examination preparation planDocument reviewRequest trackerOpen issue summary

Unsure whether your controls are ready for Type 1 or Type 2?

Discuss your SOC 2 roadmap

OPERATING EVIDENCE

Type 2 readiness depends on evidence created during normal operations

Build an evidence trail across 12 months to support a Type 2 examination.

Q1
  • Confirm control owners
  • Establish evidence sources
  • Review access and changes
  • Track operational exceptions
Q2
  • Test evidence quality
  • Correct inconsistent performance
  • Review vendors and risks
  • Update policies where required
Q3
  • Complete scheduled reviews
  • Validate incident and recovery records
  • Examine recurring exceptions
  • Prepare management reporting
Q4
  • Organise examination evidence
  • Resolve open gaps
  • Confirm system description accuracy
  • Prepare for CPA requests

The actual examination period and testing approach are determined with the independent CPA firm.

EVIDENCE QUALITY

What makes evidence usable

Complete

The evidence contains the full population, review period, and information needed to support the control.

Traceable

The evidence can be connected to the relevant system, activity, owner, reviewer, and date.

Timely

The control and its review occurred within the required period.

Consistent

The evidence shows that the control operated according to its stated frequency and procedure.

Approved

Required reviews and decisions can be linked to an authorised person.

Retained

Evidence remains available, readable, and protected throughout the examination and retention period.

Screenshots can support evidence. They rarely explain the complete control on their own.

CONTROL EXCEPTIONS

An exception needs a clear response, not a hidden workaround

STAGE 01

Identify

Record the missing, late, incomplete, or inconsistent control activity.

STAGE 02

Validate

Confirm the facts, affected population, period, systems, and evidence.

STAGE 03

Understand cause

Determine whether the issue relates to design, ownership, tooling, training, timing, or execution.

STAGE 04

Assess impact

Consider the relevant risk, customer commitment, affected criteria, and extent of the exception.

STAGE 05

Correct

Implement a practical corrective action with clear ownership.

STAGE 06

Retest

Confirm that the revised control now operates as intended.

STAGE 07

Record

Retain the exception, decision, remediation, approval, and retest evidence.

RESPONSIBILITY ALLOCATION

Subservice organisations and customer responsibilities

Service organisation

Controls operated directly by the organisation providing the service.

Subservice organisations

Relevant services and controls provided by cloud platforms, data centres, managed providers, or other external organisations.

User entities

Controls that customers are expected to implement for the overall control objectives to be achieved.

Responsibility
Example
Service organisation control
Reviews privileged access to the production environment
Subservice organisation control
Cloud provider operates physical data centre controls
Complementary user entity control
Customer protects its administrator credentials
Monitoring responsibility
Service organisation reviews relevant provider assurance reports

Scope should show which responsibilities are included, excluded, or expected from another party.

ENGAGEMENT PROCESS

How the SOC 2 readiness engagement works

STAGE 01

Define

Confirm the service, system boundary, report users, Trust Services Criteria categories, and intended examination type.

STAGE 02

Assess

Review risks, controls, policies, procedures, architecture, vendors, and available evidence.

STAGE 03

Design

Address control gaps, assign ownership, define evidence, and improve documentation.

STAGE 04

Operate

Allow controls to run through normal business processes and retain evidence.

STAGE 05

Validate

Perform readiness testing, document exceptions, remediate issues, and retest affected controls.

STAGE 06

Prepare

Finalise the system description, organise evidence, coordinate requests, and prepare management for the CPA examination.

Outcome: A defined control environment ready for independent examination.

THE FINAL REPORT

A SOC 2 report gives customers detailed assurance information

01

Independent service auditor's report

The CPA firm's opinion and information about the scope and nature of the examination.

02

Management's assertion

Management's written assertion about the system description and applicable controls.

03

System description

Management's description of the service organisation's system and relevant boundaries.

04

Applicable criteria and controls

The controls associated with the selected Trust Services Criteria.

05

Tests and results

For Type 2 reports, the report includes the service auditor's tests of controls and the results of those tests.

SOC 2 reports contain detailed information and are generally intended for restricted use by specified parties. SOC 3 reports provide less detail and are intended for general use.

Readiness should improve the control environment

Digisecuritas connects Trust Services Criteria with the organisation's services, architecture, people, risks, control owners, and operating evidence.

Our work prepares management and control owners for the examination while strengthening the processes customers depend on.

01

Independent readiness view

Receive an objective assessment before the CPA examination begins.

02

Security and compliance expertise

Connect assurance requirements with practical cybersecurity controls.

03

Clear system boundaries

Define the service, technology, people, data, suppliers, and customer responsibilities in scope.

04

Evidence based testing

Examine whether controls produce reliable evidence during normal operation.

05

Practical remediation

Give owners clear actions, priorities, and retesting requirements.

06

Examination coordination

Organise documentation and evidence for efficient interaction with the CPA firm.

FREQUENTLY ASKED QUESTIONS

SOC 2 questions answered

Prepare your controls for independent examination

Define the SOC 2 scope, address control gaps, strengthen evidence, and build a clear path towards Type 1 or Type 2.