SOC 2 Readiness & Attestation Support
The trust report your enterprise customers ask for. We help you build to the AICPA Trust Services Criteria — designing the controls with your teams, validating them the way an attacker would, and assembling the evidence a CPA expects — then coordinate the independent attestation through our licensed CPA partner.
Scope and gap assessment to an audit-ready evidence pack. CERT-In Empaneled. The CPA signs the report — we make sure it's earned.
The report your customers trust before they trust you
SOC 2 is an independent examination of how a service organization protects the systems and data it runs on a customer's behalf.
It is not a product you install or a certificate you frame on a wall — it is an attestation report, produced by a licensed CPA firm, on whether your controls meet the AICPA's Trust Services Criteria. The criteria are outcome-based: you describe the system you operate and the commitments you make to customers, design controls to meet them, and a CPA evaluates whether those controls are suitably designed — and, in a Type II, whether they operated effectively over a period of time.
For most technology companies, SOC 2 has become the price of entry. Enterprise buyers, procurement teams and security reviewers increasingly require a current SOC 2 report before they will sign a contract, complete a vendor-risk questionnaire or integrate your service into theirs. A clean report shortens sales cycles and answers the security due-diligence question once, in a form auditors and CISOs already recognise. The work behind it is what this page is about: getting your controls genuinely sound, proving they work, and assembling the evidence so the attestation confirms what is already true.
"A SOC 2 isn't a certificate you obtain. It's an independent opinion a CPA forms about controls that genuinely work — so we build the controls to be true, then bring in the CPA to attest to them."
Type I or Type II — point in time, or proven over time
SOC 2 comes in two forms. They examine the same controls against the same criteria — the difference is time, and it's the first scoping decision we make with you.
Suitability of design, at a point in time
A Type I report addresses whether your controls are suitably designed to meet the selected Trust Services Criteria as of a specified date. It answers, "are the right controls in place and designed correctly, today?" It is faster to reach, and it's often the right first step — a credible, point-in-time assurance you can put in front of a customer while a Type II observation period runs.
Operating effectiveness, over a period
A Type II report goes further: it addresses whether those controls were suitably designed and operated effectively throughout a period of time — typically a window of several months. It is the report most enterprise buyers ultimately want, because it evidences that controls don't just exist on a given day, they hold up day after day. A Type II includes the CPA's detailed description of the tests performed and their results.
Many organisations start with a Type I, then move to a recurring annual Type II. We help you choose the right entry point, then sequence the work so the observation period starts only once your controls will actually pass.
Why service organisations pursue SOC 2
SOC 2 is voluntary — but in many markets it's effectively mandatory. Organisations reach for it because the customers they want expect it.
| Criterion | Why it comes up |
|---|---|
| An enterprise customer demands it | Large buyers and their security teams increasingly require a current SOC 2 report before they will contract, renew or share data with a vendor. |
| You're a SaaS or cloud service provider | If you store, process or transmit customer data in the cloud, SOC 2 is the report the market uses to evaluate your controls. |
| You're stuck in security questionnaires | A SOC 2 report answers the bulk of vendor-risk and due-diligence questionnaires once, in a form reviewers already accept — and unblocks sales. |
| You handle sensitive or regulated data | Where you process financial, health or personal information for others, a SOC 2 demonstrates due diligence to customers and their regulators alike. |
| You're scaling up-market | Moving from SMB to enterprise deals almost always surfaces a SOC 2 requirement. Reaching it ahead of demand keeps deals from stalling. |
| You want one control set, many frameworks | Controls built for SOC 2 map cleanly to ISO 27001, the DPDP Act and more — build once, reuse the evidence across assurance programs. |
What SOC 2 actually measures
SOC 2 is built on the AICPA Trust Services Criteria — five categories an engagement can address, individually or in combination.
One is always in scope: Security, whose criteria are the Common Criteria shared across all five categories. The other four — Availability, Processing Integrity, Confidentiality and Privacy — are selected based on the commitments you make to customers and the nature of your service. The Common Criteria are organised into nine series (CC1–CC9), aligned to the COSO Internal Control framework and its seventeen principles; each selected optional category adds its own supplemental criteria on top.
Security is always in scope — its Common Criteria (CC1–CC9) are shared across all five categories. The other four categories are selected based on your customer commitments.
Aligned to COSO — 17 principles
The four optional categories — select as needed
Security — the Common Criteria (always in scope) — Information and systems are protected against unauthorised access, unauthorised disclosure and damage. Organised as CC1–CC9: control environment, communication, risk assessment, monitoring, control activities, logical & physical access, system operations, change management and risk mitigation. Every SOC 2 includes these.
Availability (A-series) — Information and systems are available for operation and use to meet your objectives — capacity management, environmental protection, backup and recovery, and tested recovery procedures.
Processing Integrity (PI-series) — System processing is complete, valid, accurate, timely and authorised — controls over inputs, processing, outputs and storage so the system does what it's meant to.
Confidentiality (C-series) — Information designated confidential is protected — identifying confidential information and disposing of it appropriately through its lifecycle.
Privacy (P-series) — Personal information is collected, used, retained, disclosed and disposed of in line with your privacy commitments — notice, choice and consent, collection, use and retention, access, disclosure, quality and monitoring.
You don't have to address all five. A SOC 2 always covers Security; you add the categories your customer commitments and service actually require — and the criteria for each selected category are addressed in full.
From scope to attestation-ready — and the CPA who attests
The SOC 2 report is issued by a licensed CPA firm. Our job is everything that earns it: scoping the right categories, designing controls that are genuinely sound, validating that they work, and assembling the evidence so the examination confirms what is already true.
We coordinate the independent attestation through our licensed CPA partner — so the readiness and the attestation stay properly separate, which is exactly what keeps the report credible.
FIG. 02 — readiness & attestation lifecycle · 01–05 Intect-led · 06 & 08 licensed CPA partner · 07 the Type II observation window
Steps one through five are ours; steps six and eight are the CPA's, coordinated through our partner. We never blur that line — because the independence between who builds the controls and who attests to them is what gives the report its value.
What an engagement includes
We scope to where you are — a first SOC 2, a move from Type I to Type II, or a recurring annual cycle — and cover the work end to end up to the attestation.
System-and-boundary definition for the SOC 2 examination
Trust Services Category selection
Security always; Availability, Processing Integrity, Confidentiality, Privacy as required
Type I vs Type II decision and observation-period planning
Gap assessment against the selected Trust Services Criteria
the Common Criteria CC1–CC9 plus any category-specific criteria
Risk assessment aligned to the criteria
Principal service commitments and system requirements, articulated for the system description
Control design across people, process and technology
Policy and procedure suite mapped to the criteria
Remediation of identified gaps, with a prioritised roadmap
Technical control validation
penetration testing and configuration review that proves the Security / Common Criteria controls actually work
Evidence collection and an audit-ready artifact pack
Remediation retest after fixes
Readiness assessment / mock examination
Support drafting the management system description
Coordination of the independent CPA attestation through our partner, and liaison through the examination
Continuous-compliance monitoring across the Type II observation period
Annual SOC 2 renewal readiness
Evidence discipline as your scope, commitments and controls evolve
We don't just document the control. We test it.
A readiness review confirms that a control is designed and written down. We confirm that it actually holds.
Most readiness work stops at the design
The conventional path to SOC 2 reviews policies, samples records and confirms the controls that have documentation behind them. That satisfies the design question — but a written logical-access policy and an access control an attacker can walk through are not the same thing. The Trust Services Criteria for Security expect controls like logical access, boundary protection, encryption and vulnerability detection to be effective, not just present — and the gap between "documented" and "effective" is exactly what a breach exploits.
We test the control, not just the claim
Intect is CERT-In Empaneled with an offensive-security heritage, so our readiness work is technically validated. Where the Common Criteria expect access control, network segmentation, encryption, boundary protection or vulnerability management to work, our researchers test them — safely, the way an adversary would — and bring you pentest-backed evidence that the control performs. The criteria themselves contemplate this: they call for vulnerability scans and a variety of evaluations, including penetration testing. You walk into the CPA's examination with Security controls that have already withstood a real probe.
The CPA's report attests that your controls are designed and operating. Our testing proves the Security controls actually stop an attacker.
PENTEST-BACKED EVIDENCEWhat you receive
Every engagement produces the artefacts your team needs to operate the control set — and the evidence pack a CPA expects to examine — up to and through the independent attestation we coordinate.
Scope & TSC selection memo
The system boundary, the Trust Services Categories in scope and the Type I / Type II decision, documented and rationalised.
Gap assessment report
Your current controls mapped against the selected Trust Services Criteria, with a prioritised roadmap to attestation-ready.
Risk assessment
A methodology and risk register aligned to the criteria the CPA will examine.
Control design & policy suite
The control set and supporting policy and procedure documentation, mapped to the Common Criteria and any category-specific criteria.
Remediation roadmap
Prioritised, specific remediation guidance with ownership and sequencing.
Audit-ready evidence pack
Collected, organised artefacts that map cleanly to each criterion the CPA will test.
Technical control validation report
Pentest-backed evidence that key Security controls genuinely work, with remediation guidance and retest.
Readiness assessment report
A dry run of the examination, with findings to close before the CPA engagement begins.
System description support
Help articulating the system, principal service commitments and system requirements for the management description.
CPA attestation coordination
We coordinate the independent SOC 2 examination through our licensed CPA partner and support you through it. The CPA issues and signs the report.
Why teams choose Intect for SOC 2
We build and we break — Most consultancies only write policy. We design the controls and then test them like attackers, so your Security evidence is proven, not asserted.
CPA attestation, coordinated — We partner with a licensed CPA firm and coordinate the independent attestation end to end — one engagement from gap assessment to issued report, without you assembling the pieces yourself.
CERT-In Empaneled, researcher-led — Senior practitioners accredited under India's national cybersecurity authority design your controls to your real risk — not a copy-paste documentation kit.
One control set, many frameworks — A SOC 2 built with us maps cleanly to ISO 27001, ISO 27701 and ITGC, so the work compounds instead of repeating.
Frequently asked questions
Does Intect issue the SOC 2 report?
No — and no consultancy can. A SOC 2 report is an attestation issued and signed by a licensed CPA firm. Intect makes you attestation-ready — scope, gap assessment, control design, remediation, evidence and a mock examination — and then coordinates the independent attestation through our licensed CPA partner. Keeping readiness and the attestation separate is exactly what preserves the report's independence, and its value.
Should we do a Type I or a Type II?
A Type I attests that your controls are suitably designed as of a point in time; a Type II attests that they were designed and operated effectively over a period (often several months). Most enterprise buyers ultimately want a Type II, but a Type I is a credible first step you can share while the Type II observation period runs. We help you choose, and we don't start the observation period until your controls will actually pass.
Which Trust Services Categories do we need?
Security is always in scope — its criteria are the Common Criteria shared across all five categories. You add Availability, Processing Integrity, Confidentiality or Privacy based on the commitments you make to customers and what your service actually does. We scope this with you so you address what matters and nothing you don't.
How is SOC 2 different from ISO 27001?
ISO 27001 certifies a management system (an ISMS) against a fixed control catalogue, issued by an accredited certification body. SOC 2 is a CPA attestation against the outcome-based Trust Services Criteria, issued as a detailed report rather than a certificate. They overlap heavily — controls built for one largely serve the other — and many organisations pursue both. We can build to both from one control set.
How long does SOC 2 take?
It depends on the size and complexity of your scope, the categories you select, whether you're going for Type I or Type II, and how mature your current controls are — which is exactly what the gap assessment establishes first. We give you a realistic, evidence-based timeline up front rather than a generic promise, and we sequence the work so the observation period starts only when you're ready.
What happens after the report is issued?
SOC 2 is point-in-time or period-based, so it's maintained on an annual cycle — most organisations run a recurring Type II. Between reports, a bridge (gap) letter can cover the interval for customers. We support continuous-compliance monitoring across the observation period and into each renewal, so the report stays current and the controls keep working.
Build it once, reuse it everywhere
A SOC 2 control set is the foundation for much more than one report.
Build a SOC 2 that's ready to be attested.
Tell us where you are — first SOC 2, Type I to Type II, or an annual renewal — and we'll scope a readiness assessment that fits, then coordinate the independent CPA attestation through our partner.