Articles
SOC 2
6 minHow long a first SOC 2 actually takesA first SOC 2 Type II usually takes four to eight months from decision to report. The audit itself is a small part of that. Most of the time goes to implementing controls that produce evidence, and to the observation window, which cannot be compressed.6 minWhat an auditor actually wants from a penetration test reportAuditors do not read penetration test reports for the findings. They read them for scope, dates, method and closure, because those are the four things that let a report support a control. Reports that bury those details create audit work rather than removing it.7 minDoes SOC 2 require a penetration test?SOC 2 does not require a penetration test. The AICPA Trust Services Criteria never use the phrase. In practice most auditors accept a penetration test as the evidence for CC4.1 and CC7.1, and a company with no security testing evidence at all should expect questions.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.