Compliance · SOC 2 AICPA Trust Services Criteria · Type I & Type II

SOC 2 Readiness & Attestation Support

The trust report your enterprise customers ask for. We help you build to the AICPA Trust Services Criteria — designing the controls with your teams, validating them the way an attacker would, and assembling the evidence a CPA expects — then coordinate the independent attestation through our licensed CPA partner.

Scope and gap assessment to an audit-ready evidence pack. CERT-In Empaneled. The CPA signs the report — we make sure it's earned.

AICPA Trust Services Criteria (TSP Section 100, 2017 · rev. 2022) Security Availability Processing Integrity Confidentiality Privacy Type I & Type II CERT-In Empaneled
Framework
AICPA Trust Services Criteria (TSP Section 100)
Criteria
5 categories · Security = Common Criteria (CC1–CC9)
Reports
Type I & Type II
Role
Readiness & evidence — the licensed CPA partner issues the report
Validation
Pentest-backed Security-control validation
02

The report your customers trust before they trust you

SOC 2 is an independent examination of how a service organization protects the systems and data it runs on a customer's behalf.

It is not a product you install or a certificate you frame on a wall — it is an attestation report, produced by a licensed CPA firm, on whether your controls meet the AICPA's Trust Services Criteria. The criteria are outcome-based: you describe the system you operate and the commitments you make to customers, design controls to meet them, and a CPA evaluates whether those controls are suitably designed — and, in a Type II, whether they operated effectively over a period of time.

For most technology companies, SOC 2 has become the price of entry. Enterprise buyers, procurement teams and security reviewers increasingly require a current SOC 2 report before they will sign a contract, complete a vendor-risk questionnaire or integrate your service into theirs. A clean report shortens sales cycles and answers the security due-diligence question once, in a form auditors and CISOs already recognise. The work behind it is what this page is about: getting your controls genuinely sound, proving they work, and assembling the evidence so the attestation confirms what is already true.

"A SOC 2 isn't a certificate you obtain. It's an independent opinion a CPA forms about controls that genuinely work — so we build the controls to be true, then bring in the CPA to attest to them."
03

Type I or Type II — point in time, or proven over time

SOC 2 comes in two forms. They examine the same controls against the same criteria — the difference is time, and it's the first scoping decision we make with you.

SOC 2 Type I

Suitability of design, at a point in time

A Type I report addresses whether your controls are suitably designed to meet the selected Trust Services Criteria as of a specified date. It answers, "are the right controls in place and designed correctly, today?" It is faster to reach, and it's often the right first step — a credible, point-in-time assurance you can put in front of a customer while a Type II observation period runs.

SOC 2 Type II

Operating effectiveness, over a period

A Type II report goes further: it addresses whether those controls were suitably designed and operated effectively throughout a period of time — typically a window of several months. It is the report most enterprise buyers ultimately want, because it evidences that controls don't just exist on a given day, they hold up day after day. A Type II includes the CPA's detailed description of the tests performed and their results.

Many organisations start with a Type I, then move to a recurring annual Type II. We help you choose the right entry point, then sequence the work so the observation period starts only once your controls will actually pass.

04

Why service organisations pursue SOC 2

SOC 2 is voluntary — but in many markets it's effectively mandatory. Organisations reach for it because the customers they want expect it.

Criterion Why it comes up
An enterprise customer demands it Large buyers and their security teams increasingly require a current SOC 2 report before they will contract, renew or share data with a vendor.
You're a SaaS or cloud service provider If you store, process or transmit customer data in the cloud, SOC 2 is the report the market uses to evaluate your controls.
You're stuck in security questionnaires A SOC 2 report answers the bulk of vendor-risk and due-diligence questionnaires once, in a form reviewers already accept — and unblocks sales.
You handle sensitive or regulated data Where you process financial, health or personal information for others, a SOC 2 demonstrates due diligence to customers and their regulators alike.
You're scaling up-market Moving from SMB to enterprise deals almost always surfaces a SOC 2 requirement. Reaching it ahead of demand keeps deals from stalling.
You want one control set, many frameworks Controls built for SOC 2 map cleanly to ISO 27001, the DPDP Act and more — build once, reuse the evidence across assurance programs.
05

What SOC 2 actually measures

SOC 2 is built on the AICPA Trust Services Criteria — five categories an engagement can address, individually or in combination.

One is always in scope: Security, whose criteria are the Common Criteria shared across all five categories. The other four — Availability, Processing Integrity, Confidentiality and Privacy — are selected based on the commitments you make to customers and the nature of your service. The Common Criteria are organised into nine series (CC1–CC9), aligned to the COSO Internal Control framework and its seventeen principles; each selected optional category adds its own supplemental criteria on top.

Security — the Common Criteria (always in scope) — Information and systems are protected against unauthorised access, unauthorised disclosure and damage. Organised as CC1–CC9: control environment, communication, risk assessment, monitoring, control activities, logical & physical access, system operations, change management and risk mitigation. Every SOC 2 includes these.

Availability (A-series) — Information and systems are available for operation and use to meet your objectives — capacity management, environmental protection, backup and recovery, and tested recovery procedures.

Processing Integrity (PI-series) — System processing is complete, valid, accurate, timely and authorised — controls over inputs, processing, outputs and storage so the system does what it's meant to.

Confidentiality (C-series) — Information designated confidential is protected — identifying confidential information and disposing of it appropriately through its lifecycle.

Privacy (P-series) — Personal information is collected, used, retained, disclosed and disposed of in line with your privacy commitments — notice, choice and consent, collection, use and retention, access, disclosure, quality and monitoring.

You don't have to address all five. A SOC 2 always covers Security; you add the categories your customer commitments and service actually require — and the criteria for each selected category are addressed in full.

06

From scope to attestation-ready — and the CPA who attests

The SOC 2 report is issued by a licensed CPA firm. Our job is everything that earns it: scoping the right categories, designing controls that are genuinely sound, validating that they work, and assembling the evidence so the examination confirms what is already true.

We coordinate the independent attestation through our licensed CPA partner — so the readiness and the attestation stay properly separate, which is exactly what keeps the report credible.

01 · Intect
Scope & TSC Selection
We define the system in scope and select the Trust Services Categories that match your customer commitments — Security always, plus Availability, Processing Integrity, Confidentiality or Privacy as needed — and decide Type I, Type II, or Type I then Type II.
02 · Intect
Gap Assessment
We measure your current controls against the selected Trust Services Criteria, control by control, and produce a clear gap report with a prioritised roadmap to close it.
03 · Intect
Remediation & Control Design
We design and stand up the controls — policy and procedure, access, change, monitoring, vendor and resilience controls — and support remediation of every gap from step two.
04 · Intect
Evidence Collection
We help you operationalise evidence: the artefacts, logs, tickets and records that show each control operating, organised to map cleanly to the criteria a CPA will test.
05 · Intect
Readiness Assessment
We run a mock examination — assessing you the way the CPA will — so gaps surface and close before the formal engagement, not during it.
06 · CPA partner
Type I Examination
Conducted by the licensed CPA firm (our partner). The CPA examines whether your controls are suitably designed as of a point in time and issues the Type I report. We support you through it.
07 · Type II window
Observation Period
The Type II window. Your controls operate over a defined period (typically several months) while you maintain evidence. We support continuous-compliance monitoring across it.
08 · CPA partner
Type II Report
Conducted by the licensed CPA firm (our partner). The CPA tests operating effectiveness across the period and issues the Type II report, including the description of tests and results. SOC 2 then renews annually.

FIG. 02 — readiness & attestation lifecycle · 01–05 Intect-led · 06 & 08 licensed CPA partner · 07 the Type II observation window

Steps one through five are ours; steps six and eight are the CPA's, coordinated through our partner. We never blur that line — because the independence between who builds the controls and who attests to them is what gives the report its value.

07

What an engagement includes

We scope to where you are — a first SOC 2, a move from Type I to Type II, or a recurring annual cycle — and cover the work end to end up to the attestation.

Scope
01

System-and-boundary definition for the SOC 2 examination

02

Trust Services Category selection

Security always; Availability, Processing Integrity, Confidentiality, Privacy as required

03

Type I vs Type II decision and observation-period planning

Assess
04

Gap assessment against the selected Trust Services Criteria

the Common Criteria CC1–CC9 plus any category-specific criteria

05

Risk assessment aligned to the criteria

06

Principal service commitments and system requirements, articulated for the system description

Build
07

Control design across people, process and technology

08

Policy and procedure suite mapped to the criteria

09

Remediation of identified gaps, with a prioritised roadmap

Validate (the offensive edge)
10

Technical control validation

penetration testing and configuration review that proves the Security / Common Criteria controls actually work

11

Evidence collection and an audit-ready artifact pack

12

Remediation retest after fixes

Prepare for attestation
13

Readiness assessment / mock examination

14

Support drafting the management system description

15

Coordination of the independent CPA attestation through our partner, and liaison through the examination

Sustain
16

Continuous-compliance monitoring across the Type II observation period

17

Annual SOC 2 renewal readiness

18

Evidence discipline as your scope, commitments and controls evolve

08

We don't just document the control. We test it.

A readiness review confirms that a control is designed and written down. We confirm that it actually holds.

Evidence on paper

Most readiness work stops at the design

The conventional path to SOC 2 reviews policies, samples records and confirms the controls that have documentation behind them. That satisfies the design question — but a written logical-access policy and an access control an attacker can walk through are not the same thing. The Trust Services Criteria for Security expect controls like logical access, boundary protection, encryption and vulnerability detection to be effective, not just present — and the gap between "documented" and "effective" is exactly what a breach exploits.

Evidence that's been proven

We test the control, not just the claim

Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the Common Criteria expect access control, network segmentation, encryption, boundary protection or vulnerability management to work, our researchers test them — safely, the way an adversary would — and bring you pentest-backed evidence that the control performs. The criteria themselves contemplate this: they call for vulnerability scans and a variety of evaluations, including penetration testing. You walk into the CPA's examination with Security controls that have already withstood a real probe.

The CPA's report attests that your controls are designed and operating. Our testing proves the Security controls actually stop an attacker.

PENTEST-BACKED EVIDENCE
09

What you receive

Every engagement produces the artefacts your team needs to operate the control set — and the evidence pack a CPA expects to examine — up to and through the independent attestation we coordinate.

01

Scope & TSC selection memo

The system boundary, the Trust Services Categories in scope and the Type I / Type II decision, documented and rationalised.

02

Gap assessment report

Your current controls mapped against the selected Trust Services Criteria, with a prioritised roadmap to attestation-ready.

03

Risk assessment

A methodology and risk register aligned to the criteria the CPA will examine.

04

Control design & policy suite

The control set and supporting policy and procedure documentation, mapped to the Common Criteria and any category-specific criteria.

05

Remediation roadmap

Prioritised, specific remediation guidance with ownership and sequencing.

06

Audit-ready evidence pack

Collected, organised artefacts that map cleanly to each criterion the CPA will test.

07

Technical control validation report

Pentest-backed evidence that key Security controls genuinely work, with remediation guidance and retest.

PENTEST-BACKED
08

Readiness assessment report

A dry run of the examination, with findings to close before the CPA engagement begins.

09

System description support

Help articulating the system, principal service commitments and system requirements for the management description.

10

CPA attestation coordination

We coordinate the independent SOC 2 examination through our licensed CPA partner and support you through it. The CPA issues and signs the report.

AICPA Trust Services Criteria (TSP Section 100) Security / Common Criteria CC1–CC9 Type I & Type II CERT-In Empaneled Independent CPA attestation via partner Supports ISO 27001 & ISO 27701 readiness
10

Why teams choose Intect for SOC 2

CERT-In Empaneled Researcher-led · offensive heritage CPA attestation via partner

We build and we break — Most consultancies only write policy. We design the controls and then test them like attackers, so your Security evidence is proven, not asserted.

CPA attestation, coordinated — We partner with a licensed CPA firm and coordinate the independent attestation end to end — one engagement from gap assessment to issued report, without you assembling the pieces yourself.

CERT-In Empaneled, researcher-led — Senior practitioners accredited under India's national cybersecurity authority design your controls to your real risk — not a copy-paste documentation kit.

One control set, many frameworks — A SOC 2 built with us maps cleanly to ISO 27001, ISO 27701 and ITGC, so the work compounds instead of repeating.

11

Frequently asked questions

Does Intect issue the SOC 2 report?

No — and no consultancy can. A SOC 2 report is an attestation issued and signed by a licensed CPA firm. Intect makes you attestation-ready — scope, gap assessment, control design, remediation, evidence and a mock examination — and then coordinates the independent attestation through our licensed CPA partner. Keeping readiness and the attestation separate is exactly what preserves the report's independence, and its value.

Should we do a Type I or a Type II?

A Type I attests that your controls are suitably designed as of a point in time; a Type II attests that they were designed and operated effectively over a period (often several months). Most enterprise buyers ultimately want a Type II, but a Type I is a credible first step you can share while the Type II observation period runs. We help you choose, and we don't start the observation period until your controls will actually pass.

Which Trust Services Categories do we need?

Security is always in scope — its criteria are the Common Criteria shared across all five categories. You add Availability, Processing Integrity, Confidentiality or Privacy based on the commitments you make to customers and what your service actually does. We scope this with you so you address what matters and nothing you don't.

How is SOC 2 different from ISO 27001?

ISO 27001 certifies a management system (an ISMS) against a fixed control catalogue, issued by an accredited certification body. SOC 2 is a CPA attestation against the outcome-based Trust Services Criteria, issued as a detailed report rather than a certificate. They overlap heavily — controls built for one largely serve the other — and many organisations pursue both. We can build to both from one control set.

How long does SOC 2 take?

It depends on the size and complexity of your scope, the categories you select, whether you're going for Type I or Type II, and how mature your current controls are — which is exactly what the gap assessment establishes first. We give you a realistic, evidence-based timeline up front rather than a generic promise, and we sequence the work so the observation period starts only when you're ready.

What happens after the report is issued?

SOC 2 is point-in-time or period-based, so it's maintained on an annual cycle — most organisations run a recurring Type II. Between reports, a bridge (gap) letter can cover the interval for customers. We support continuous-compliance monitoring across the observation period and into each renewal, so the report stays current and the controls keep working.

12

Build it once, reuse it everywhere

A SOC 2 control set is the foundation for much more than one report.

Scope an engagement

Build a SOC 2 that's ready to be attested.

Tell us where you are — first SOC 2, Type I to Type II, or an annual renewal — and we'll scope a readiness assessment that fits, then coordinate the independent CPA attestation through our partner.