Audit and compliance
SOC 2 report
Also called: SOC 2, service organization control report
A SOC 2 report is an attestation issued by a licensed CPA firm on a service organization's controls against the Trust Services Criteria. A Type I addresses control design at a point in time; a Type II addresses design and operating effectiveness across a period.
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.