GRC & Compliance

SOC 2 preparation

SOC 2 is the report North American enterprise buyers most often ask software companies to produce before they will commit. It demonstrates that a service provider manages customer data responsibly, and for many companies it is the requirement standing between them and a large deal.

Heelr connects you with professionals who prepare organisations for a SOC 2 examination. They scope the relevant controls, close the gaps, and get you audit-ready before the formal assessment. Every provider must meet Heelr's identity and provider verification requirements, and you agree the scope and price before any work begins.

What SOC 2 preparation involves

SOC 2 is assessed against trust service criteria covering security and, where relevant, availability, processing integrity, confidentiality and privacy. A provider helps you scope which criteria apply, implement and document the controls, and prepare the evidence an auditor will request.

There are two report types. A Type I report assesses your controls at a point in time. A Type II report assesses how they operate over a period, usually several months, and is what most enterprise buyers eventually want. The examination itself is conducted by an independent auditor; the provider gets you ready for it.

Common questions

When does a company need SOC 2?

Usually when enterprise buyers, particularly in North America, start requiring it before signing. Software companies moving upmarket hit this point predictably. Because a Type II report covers a period of months, starting early matters. See SaaS companies.

What is the difference between SOC 2 Type I and Type II?

Type I assesses your controls at a single point in time and is faster to achieve. Type II assesses how those controls operate over a period and carries more weight with buyers. Many companies do Type I first, then Type II.

Is SOC 2 the same as ISO 27001?

No. They overlap heavily in what they cover, but SOC 2 is a reporting framework common in North America, while ISO 27001 is an international certification more common in Europe. Some companies eventually hold both. See ISO 27001, or read about how SOC 2 and ISO 27001 compare in practice.

Who issues the SOC 2 report?

An independent auditor, not Heelr and not the provider. The provider prepares you so the examination goes smoothly.

Working towards SOC 2?

Heelr can help you find cybersecurity providers with experience supporting SOC 2 preparation. You agree the scope and price with the provider before work begins.

Related