COMPLIANCE & FRAMEWORK
SOC 2 readiness and control assessment
A SOC 2 examination evaluates controls within a service organisation's system against applicable Trust Services Criteria.
Digisecuritas helps organisations define the system boundary, select relevant criteria, assess control design, organise evidence, address gaps, and prepare for an independent Type 1 or Type 2 examination.
Clear scope. Owned controls. Examination ready evidence.
CONTROL TO EVIDENCE
SOC 2 assurance path connecting customer commitments, risks, controls, evidence, and independent examination
THE SYSTEM IN SCOPE
The examination covers the system used to deliver the service
SOC 2 scope should reflect the service customers rely on and the controls supporting that service. A vague or oversized scope creates unnecessary effort. A scope that excludes important dependencies may fail to address customer concerns.
Subservice organisations and customer responsibilities
TRUST SERVICES CRITERIA
Select criteria according to the service and customer commitments
SOC 2 examinations address controls relevant to Security and may also include Availability, Processing Integrity, Confidentiality, or Privacy according to the system and engagement scope.
SECURITY — REQUIRED
Security
Addresses protection against unauthorised access, use, or disclosure that could affect the organisation's ability to meet its commitments.
Typical areas
- Governance and risk assessment
- Logical and physical access
- System operations
- Change management
- Risk mitigation
- Vendor oversight
Availability
Addresses whether the system is available for operation and use according to commitments.
Processing integrity
Addresses whether system processing is complete, valid, accurate, timely, and authorised according to commitments.
Confidentiality
Addresses protection of information designated as confidential.
Privacy
Addresses the collection, use, retention, disclosure, and disposal of personal information according to relevant commitments and criteria.
More categories create a broader examination scope. They should be included because the service and customer commitments require them.
EXAMINATION TYPE
Type 1 or Type 2
SHARED PREPARATION
POINT IN TIME
SOC 2 Type 1
Evaluates the description of the service organisation's system and the suitability of control design at a specified date.
Useful when
- The control environment is newly established
- Customers need an initial report
- The organisation is beginning its assurance programme
- Management wants a point in time assessment before Type 2
Evidence focus: Control design and implementation as of the specified date.
PERIOD OF TIME
SOC 2 Type 2
Evaluates the system description, suitability of control design, and operating effectiveness of controls over a defined period.
Useful when
- Customers require evidence of sustained control operation
- Controls have operated long enough to be tested
- The organisation has a mature evidence process
- Ongoing assurance is expected
Evidence focus: Control design and operating evidence across the review period.
The appropriate report type depends on customer needs, control readiness, evidence history, and the CPA firm's examination plan.
CONTROL TRACEABILITY
Every control should support a defined risk and commitment
Controls become difficult to defend when they exist as an isolated checklist. A stronger control environment shows how service commitments, risks, controls, ownership, and evidence connect.
CONTROL DOMAINS
Common control domains
DESCRIPTION CRITERIA
The system description should match how the service operates
Management prepares the description of the service organisation's system. It gives report users the context needed to understand the services, system boundaries, controls, commitments, risks, and relevant dependencies.
OUR SERVICES
SOC 2 readiness and consulting services
Unsure whether your controls are ready for Type 1 or Type 2?
Discuss your SOC 2 roadmapOPERATING EVIDENCE
Type 2 readiness depends on evidence created during normal operations
Build an evidence trail across 12 months to support a Type 2 examination.
The actual examination period and testing approach are determined with the independent CPA firm.
EVIDENCE QUALITY
What makes evidence usable
Complete
The evidence contains the full population, review period, and information needed to support the control.
Traceable
The evidence can be connected to the relevant system, activity, owner, reviewer, and date.
Timely
The control and its review occurred within the required period.
Consistent
The evidence shows that the control operated according to its stated frequency and procedure.
Approved
Required reviews and decisions can be linked to an authorised person.
Retained
Evidence remains available, readable, and protected throughout the examination and retention period.
Screenshots can support evidence. They rarely explain the complete control on their own.
CONTROL EXCEPTIONS
An exception needs a clear response, not a hidden workaround
STAGE 01
Identify
Record the missing, late, incomplete, or inconsistent control activity.
STAGE 02
Validate
Confirm the facts, affected population, period, systems, and evidence.
STAGE 03
Understand cause
Determine whether the issue relates to design, ownership, tooling, training, timing, or execution.
STAGE 04
Assess impact
Consider the relevant risk, customer commitment, affected criteria, and extent of the exception.
STAGE 05
Correct
Implement a practical corrective action with clear ownership.
STAGE 06
Retest
Confirm that the revised control now operates as intended.
STAGE 07
Record
Retain the exception, decision, remediation, approval, and retest evidence.
RESPONSIBILITY ALLOCATION
Subservice organisations and customer responsibilities
Service organisation
Controls operated directly by the organisation providing the service.
Subservice organisations
Relevant services and controls provided by cloud platforms, data centres, managed providers, or other external organisations.
User entities
Controls that customers are expected to implement for the overall control objectives to be achieved.
Scope should show which responsibilities are included, excluded, or expected from another party.
ENGAGEMENT PROCESS
How the SOC 2 readiness engagement works
STAGE 01
Define
Confirm the service, system boundary, report users, Trust Services Criteria categories, and intended examination type.
STAGE 02
Assess
Review risks, controls, policies, procedures, architecture, vendors, and available evidence.
STAGE 03
Design
Address control gaps, assign ownership, define evidence, and improve documentation.
STAGE 04
Operate
Allow controls to run through normal business processes and retain evidence.
STAGE 05
Validate
Perform readiness testing, document exceptions, remediate issues, and retest affected controls.
STAGE 06
Prepare
Finalise the system description, organise evidence, coordinate requests, and prepare management for the CPA examination.
Outcome: A defined control environment ready for independent examination.
THE FINAL REPORT
A SOC 2 report gives customers detailed assurance information
SOC 2 reports contain detailed information and are generally intended for restricted use by specified parties. SOC 3 reports provide less detail and are intended for general use.
Readiness should improve the control environment
Digisecuritas connects Trust Services Criteria with the organisation's services, architecture, people, risks, control owners, and operating evidence.
Our work prepares management and control owners for the examination while strengthening the processes customers depend on.
Independent readiness view
Receive an objective assessment before the CPA examination begins.
Security and compliance expertise
Connect assurance requirements with practical cybersecurity controls.
Clear system boundaries
Define the service, technology, people, data, suppliers, and customer responsibilities in scope.
Evidence based testing
Examine whether controls produce reliable evidence during normal operation.
Practical remediation
Give owners clear actions, priorities, and retesting requirements.
Examination coordination
Organise documentation and evidence for efficient interaction with the CPA firm.
FREQUENTLY ASKED QUESTIONS
SOC 2 questions answered
Prepare your controls for independent examination
Define the SOC 2 scope, address control gaps, strengthen evidence, and build a clear path towards Type 1 or Type 2.
