SOC (System and Organization Controls) is a suite of attestation standards from the American Institute of Certified Public Accountants (AICPA). A SOC report is an independent opinion on the controls at a service organization — it is not a certification, and no certification body can issue one.
SOC reports can only be issued by a licensed CPA firm enrolled in the AICPA peer review program. Cetonix is not a CPA firm. What we do is get you ready for the examination and stay alongside you through it, so that when your CPA firm arrives there are no surprises and no scramble for evidence.
SOC 1 covers controls relevant to your clients' financial reporting. SOC 2 covers the Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. A Type I report covers control design at a point in time; a Type II report covers operating effectiveness over a period, usually three to twelve months.
SaaS platforms whose enterprise prospects have started asking for a SOC 2 report before signing; service organizations — payroll, data center, managed services — whose clients need assurance over controls they depend on; and teams renewing a Type II who want the next cycle to cost less than the last.
We are not a CPA firm and we do not issue SOC reports. Any vendor offering you a "SOC 2 certificate" is describing something that does not exist. We will tell you exactly what the examination requires, get you there, and work with the CPA firm that performs it — but the opinion is theirs, not ours.
Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.