info@cetonix.com +91 (966) 512-1196 Mon–Fri, 09:30–18:00 IST
HomeGRCSOC 1 / SOC 2

SOC 1 / SOC 2

SOC 2 is an attestation issued by a licensed CPA firm, not a certification. We get you ready for the examination and stay alongside you through it.

SOC (System and Organization Controls) is a suite of attestation standards from the American Institute of Certified Public Accountants (AICPA). A SOC report is an independent opinion on the controls at a service organization — it is not a certification, and no certification body can issue one.

SOC reports can only be issued by a licensed CPA firm enrolled in the AICPA peer review program. Cetonix is not a CPA firm. What we do is get you ready for the examination and stay alongside you through it, so that when your CPA firm arrives there are no surprises and no scramble for evidence.

SOC 1 covers controls relevant to your clients' financial reporting. SOC 2 covers the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. A Type I report covers control design at a point in time; a Type II report covers operating effectiveness over a period, usually three to twelve months.

What SOC 2 readiness covers

  • Scoping — which Trust Services Criteria apply, which systems are in scope, and whether Type I or Type II fits your timeline
  • Gap assessment against the applicable criteria, with every gap rated, owned and dated
  • Control design — access reviews, change management, vendor management, incident response, logging and monitoring
  • Evidence collection — what your auditor will ask for, gathered before they ask for it
  • Penetration testing against CC4.1 and CC7.1, the evidence most auditors expect (see Penetration Testing)
  • Coordination with the CPA firm you appoint, through to report issuance

What you get out of it

  • A shorter, cheaper examination, because findings are closed before fieldwork starts
  • Fewer blocking questions on enterprise vendor-risk questionnaires
  • A penetration test report and signed attestation letter you can share with prospects
  • Control documentation that survives the next cycle instead of being rebuilt annually

Who it is for

SaaS platforms whose enterprise prospects have started asking for a SOC 2 report before signing; service organizations — payroll, data center, managed services — whose clients need assurance over controls they depend on; and teams renewing a Type II who want the next cycle to cost less than the last.

What we are not

We are not a CPA firm and we do not issue SOC reports. Any vendor offering you a "SOC 2 certificate" is describing something that does not exist. We will tell you exactly what the examination requires, get you there, and work with the CPA firm that performs it — but the opinion is theirs, not ours.

Talk to us about certification or a penetration test

Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.