Solutions · SOC 2

SOC 2, audit-ready by design

A SOC 2 report is your service organisation proving, to an independent auditor, that the controls behind the Trust Services Criteria are designed and operating. Acuna runs that programme in one place: the criteria mapped to controls with named owners, evidence collected on a cadence, and audit readiness held as a live state rather than a pre-examination scramble.

Trust Services Criteria on one systemSOC 2 mapped alongside ISO 2700150+ frameworks on one core

In short

SOC 2 is an attestation, defined by the AICPA, in which an independent auditor examines a service organisation’s controls against the Trust Services Criteria (security, and where relevant availability, processing integrity, confidentiality, and privacy). A Type I report assesses the design of controls at a point in time; a Type II report assesses their operating effectiveness over a period. Acuna is a multi-framework GRC platform that maps the criteria once, ties every control to an owner and to evidence collected on a cadence, and keeps you examination-ready.

Turn the examination into a state you hold, not a season you dread

For most service organisations SOC 2 is a sales gate: enterprise customers will not buy without the report. That makes the real cost not the audit fee but the disruption, the weeks your team spends assembling evidence the auditor could have seen all along. The organisations that handle SOC 2 well are the ones where the controls, their owners, and their evidence run continuously, so a Type II period is documented as it happens rather than reconstructed at the end.

One system for the whole SOC 2 programme

SOC 2 is organised around the Trust Services Criteria rather than a fixed control catalogue, so Acuna maps those criteria once across the four core panes, then the access-control depth the criteria demand is carried by the extension your programme needs.

Map the Trust Services Criteria once and crosswalk them to the frameworks you already run, so the security criteria you meet for ISO 27001 carry straight into SOC 2 rather than being rebuilt.

Turn the criteria into controls with named owners, so each Trust Services criterion has an accountable person and a described control, which is what the auditor tests.

Keep the controls operating on a cadence, so a Type II period is evidenced continuously as it runs, not reconstructed the week before the examination.

Give your auditor a live evidence view instead of a shared drive assembled under pressure, so the examination reads what has been running all along.

Framework-specific extension
RBACExtension

The Common Criteria CC6 (logical and physical access controls) are central to every SOC 2 examination. RBAC implements the access restrictions and periodic access reviews CC6 expects, and produces the review records the auditor asks for. See access control for the full capability.

What it unlocks, and what waiting costs

What a running SOC 2 programme unlocks vs What waiting costs
What a running SOC 2 programme unlocksWhat waiting costs
The report your enterprise deals are gated on, produced from a programme that runs continuously.Evidence assembled under deadline, with gaps discovered mid-examination.
A Type II period documented as it happens, so evidence collection is not a quarter-end sprint.The same security control described once for SOC 2 and again for ISO 27001.
Security controls that carry between SOC 2 and ISO 27001 instead of being maintained twice.Access reviews that were meant to happen quarterly and are reconstructed at audit time.
Access reviews that exist as records, not as a promise you scramble to back up.

We are early, so we will not quote a customer count. The mechanism is the argument: a Type II report attests to controls operating over a period. If the controls and their evidence run in one system across that period, the examination reads a record rather than triggering a reconstruction.

The hesitations worth naming

GRC ROI is genuinely hard to prove precisely. Use your own numbers below to build the internal case. These inputs are yours; the output is your estimate, not ours.

Pipeline at risk

Enterprise deal value

typical affected deal, annualised

CHF 200K

CHF 10KCHF 1M

Deals blocked or slowed

per year, your estimate

3 deals

015

Security questionnaires

your team fills out, per month

5 / month

020 / month

Questionnaire overhead

Hours per questionnaire

across all people involved (SIG/CAIQ often run 6–12 hrs)

6 hrs

1 hr40 hrs

All-in hourly cost

fully-loaded: salary + overhead of the person filling it

CHF 125

CHF 25CHF 500
Pipeline at riskCHF 600'000
Questionnaire overhead / year (5×/mo × 6 hrs × CHF 125)CHF 45'000
Total identifiable costCHF 645'000

Acuna starts from

CHF 5'388 / year, all frameworks included

120×

your est. cost

These are your estimates, not ours. GRC ROI is notoriously hard to measure: most of the value is in deals not lost, incidents not escalated, and audits not rebuilt from scratch. Use this to structure the internal conversation, not as a number we stand behind.

Built by people who ran the programmes

Acuna is built and operated by an established Swiss GRC group led by practitioners with decades of combined experience in audit, security, and governance. The platform models how a mature control programme actually runs, which is exactly what a Type II examination rewards.

  1. Trust Services Criteria map once and reuse across ISO 27001 and beyond.

  2. Access reviews produce the CC6 records auditors ask for.

  3. Priced per organisation, so every control owner and auditor is included.

  4. Data hosted in Switzerland and the EU.

SOC 2: common questions.

Related answers

Questions practitioners ask.

What is the difference between SOC 2 Type I and Type II?

SOC 2 Type I evaluates whether controls are suitably designed at a specific point in time. SOC 2 Type II evaluates whether those controls operated effectively over a period, typically 6 to 12 months. Type II is more rigorous because it requires evidence of sustained operation — not just that controls exist on paper. Most enterprise buyers require a Type II report. Acuna is designed for continuous evidence collection during the Type II observation period, with recurring tasks, control health scoring, and audit-ready evidence packs.

What are the SOC 2 Trust Services Criteria?

The Trust Services Criteria (TSC) are the standards the AICPA publishes against which an independent CPA firm evaluates a service organization's controls. There are five categories. Security (Common Criteria, CC) is mandatory and appears in every SOC 2 report. The other four — Availability (A), Processing Integrity (PI), Confidentiality (C), and Privacy (P) — are optional: organizations include them where relevant to the services they provide and to what buyers need to see. Most SaaS companies scope Security as the baseline and add Availability when uptime commitments matter to buyers, Confidentiality when enterprise data handling is a selling point, Privacy when the service processes significant personal data, and Processing Integrity for transactional or financial processing. The Common Criteria are further divided into CC1 through CC9. CC6 covers logical and physical access controls — provisioning, authentication, role-based access, and periodic access review. CC7 covers systems operations and monitoring. CC9 covers risk management and vendor risk, including CC9.2, which requires monitoring of third-party providers and the controls they operate on your behalf. CC6 maps closely to ISO 27001 A.5.15–A.5.18; CC9.2 to A.5.19–A.5.23 — organizations running both frameworks reuse this evidence rather than maintaining separate control sets.

What is a SOC 2 report and who reads it?

A SOC 2 report is the written output of an attestation engagement: an independent CPA firm examines a service organization's controls against the AICPA Trust Services Criteria and issues a formal opinion. The report is a private document — unlike an ISO 27001 certificate, it is not publicly verifiable. It is distributed under NDA to enterprise customers and prospects who request it during vendor due diligence. Procurement and security teams read three things in a SOC 2 report: the auditor's opinion (whether it is unqualified or contains exceptions), the system description (which services and systems were in scope), and the exceptions table (any controls that failed or deviated during the audit period). A narrow scope or a qualified opinion raises questions a buyer will ask about. A Type II report with a clean, unqualified opinion and appropriate scope is the artifact that closes enterprise deals where a vendor security questionnaire alone would not suffice. The report is typically renewed annually — which is why the observation-period cadence is ongoing rather than one-time.

How long does SOC 2 take?

SOC 2 readiness and audit typically take six to eighteen months depending on starting state. The observation period for a Type II report is a minimum of six months — the auditor must see controls operating for at least that long, so the earliest a first-time Type II report is available is roughly six months after controls are operational. Organizations starting from scratch typically spend two to four months on readiness — scoping, control implementation, tooling, and initial evidence collection — before beginning the observation period. That makes the total timeline nine to twelve months for a first-time Type II. Type I moves faster: it is a point-in-time assessment with no observation period, and some organizations use a Type I as a milestone on the way to Type II, getting a report into customers' hands faster while the Type II evidence accumulates. The most common source of delay is not the audit itself but the observation period: controls must run without gaps, and evidence must be collected consistently. Starting continuous evidence collection early — before the formal observation window opens — is the practical way to compress the overall timeline.

SOC 2 vs ISO 27001: what is the difference?

SOC 2 and ISO 27001 both address information security controls, but they are architecturally different. ISO 27001 produces a certificate: issued by an accredited certification body, three-year validity, globally recognized, and publicly verifiable. SOC 2 produces an attestation report: issued by a licensed CPA firm, privately distributed, renewed annually, and standard in US enterprise markets. ISO 27001 requires a formal Information Security Management System (ISMS) with documented scope, risk assessment, and a Statement of Applicability for 93 Annex A controls. SOC 2 is organized around the AICPA Trust Services Criteria — Security (CC) is mandatory, the other four categories are optional. The control overlap is significant: CC6 (logical access controls) maps closely to ISO 27001 A.5.15–A.5.18; CC9.2 (vendor monitoring) maps to A.5.19–A.5.23; CC7 (operations) maps to ISO 27001 A.8.x controls. Organizations running both frameworks map once and reuse evidence across both rather than maintaining parallel control sets. The choice depends on where your buyers are. ISO 27001 is the expectation in EU enterprise and global markets. SOC 2 is the US market standard and is frequently required by US enterprise procurement before a contract is signed. Many organizations operating across both markets pursue both.

Get started

Be SOC 2 ready all year, not all-nighter

See how the criteria, controls, and evidence run in one place.