SOC 2 reports have become the de facto standard for demonstrating security and compliance to enterprise customers. Summit Advisory performs SOC 2 Type I and Type II examinations under AICPA Trust Services Criteria — helping SaaS companies, technology firms, and service organizations earn and maintain the trust of their customers and prospects.
Get a Free ConsultationUnderstanding SOC 2
A SOC 2 (System and Organization Controls 2) examination is an independent audit performed by a licensed CPA firm that evaluates the controls a service organization has in place to protect customer data. SOC 2 reports are issued under the AICPA's Trust Services Criteria (TSC), which define requirements across five categories: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Enterprise customers, Fortune 500 procurement teams, and information security reviewers routinely require SOC 2 reports before awarding vendor contracts or allowing access to their systems and data. Without a SOC 2, organizations regularly lose deals to compliant competitors — or spend weeks responding to custom security questionnaires that a SOC 2 report would answer comprehensively.
Start Your SOC 2 JourneyEvaluates whether your controls are suitably designed as of a specific date. Faster to complete. Good for initial market entry or when a customer requires a report immediately.
Evaluates whether controls were operating effectively over a defined period (typically 6-12 months). Provides stronger assurance. Required by most enterprise customers and preferred by information security teams.
Trust Services Criteria
SOC 2 reports can cover one or more of the five Trust Services Criteria. Security (CC criteria) is required for all SOC 2 reports. Additional categories are selected based on the services you provide and what your customers need to evaluate.
Protection against unauthorized access. Required for all SOC 2 reports.
System availability and performance per service level commitments.
Complete, accurate, timely, and authorized system processing.
Protection of information designated as confidential.
Collection, use, retention, and disposal of personal information.
Our Services
From readiness to report issuance, Summit Advisory supports your complete SOC 2 compliance journey — whether you're pursuing your first report or maintaining annual Type II examinations.
Pre-examination assessment identifying control gaps against Trust Services Criteria before formal testing begins. We identify what you have, what you're missing, and what to build — reducing surprises during the examination and accelerating your path to a clean report.
Point-in-time examination evaluating the design and implementation of your controls as of a specific date. Issued with our independent service auditor's report describing your system and control environment.
Period-of-coverage examination testing the operating effectiveness of your controls over 6-12 months. The gold standard for enterprise customer due diligence — includes detailed testing results and our opinion on control effectiveness throughout the period.
Following a readiness assessment, we help you design and implement controls that satisfy Trust Services Criteria — including policy development, evidence collection processes, and monitoring procedures that hold up under examination.
Ongoing Type II examinations to maintain your SOC 2 report currency. We provide year-over-year continuity, document control changes, and help your team stay audit-ready throughout the year — not just during examination season.
For service organizations whose controls affect user entities' financial reporting — payroll processors, benefit plan administrators, loan servicers — we perform SOC 1 Type I and Type II examinations under SSAE 18.
Our Process
We define the audit scope, select Trust Services Criteria, and perform a readiness assessment to identify control gaps — giving you a clear picture of preparation needed before formal testing.
We help you address gaps identified in the readiness assessment — developing policies, implementing controls, and building evidence collection workflows before the examination period begins.
We perform the formal Type I or Type II examination — testing controls, reviewing evidence, interviewing personnel, and assessing operating effectiveness throughout the examination period.
We issue the final SOC 2 report including our independent service auditor's opinion — a professional, shareable document that satisfies enterprise customer security review requirements.
FAQ
A Type I report typically takes 2-4 months from readiness assessment to report issuance. A Type II report requires a 6-12 month observation period plus 1-2 months for examination and reporting — most companies allow 9-14 months total for their first Type II.
SOC 2 examination costs vary based on scope, number of Trust Services Criteria included, and company complexity. Summit Advisory provides transparent fixed-scope pricing after an initial scoping consultation — no hourly surprises.
SOC 1 reports address controls relevant to user entity financial reporting (e.g., payroll processing). SOC 2 reports address operational controls relevant to security, availability, processing integrity, confidentiality, and privacy — what most tech and SaaS companies need.
ISO 27001 and SOC 2 overlap significantly but serve different audiences. ISO 27001 is an international management system standard. SOC 2 is an independent CPA examination with a formal auditor's report — what U.S. enterprise customers and their legal teams typically require.