Home / Assurance / SOC 2 attestation
SOC 1 · SOC 2 · SOC 3 · Type I & Type II

SOC 2 attestation,
issued by a CPA firm.

We scope tightly, test once, and issue a report that survives your customer's vendor-risk review — led by the practitioner who signs it, not handed down to juniors.

What you receive at issuance
The attestation report
Opinion, system description, criteria, controls, tests performed and results — the document your buyer's security team reads.
A buyer-ready summary
One page your sales team can send under NDA without forwarding the full report.
Bridge letter when you need one
Covers the gap between your report period end and a prospect's diligence date.
A renewal calendar
Dated milestones for the next cycle, so the audit never becomes a fire drill again.

Every deliverable is issued by Assurion Services LLC, a certified public accounting firm enrolled in the AICPA Peer Review Program.

Credentials on the engagement
US CPA licensed AICPA Peer Review CISA certified AT-C 105 & 205 TSP 100 (2017, rev. 2022)
01 — which report

Type I or Type II? It depends who's asking.

If a deal is waiting, most companies start with Type I and roll straight into Type II on the same scope — you get something to send now, and the report buyers really want a quarter later.

Type I

Controls suitably designed, at a point in time.

Unblocks procurement quickly and proves the program exists.

Timeline to signed report 8–10 weeks
Observation window None
Evidence required Design only
Best when A deal is blocked now
Type II
What buyers ask for

Controls operating effectively, over a period.

The report enterprise security teams and investors treat as sufficient.

Timeline to signed report Window + 8–10 weeks
Observation window 3–6 months
Evidence required Design + operation
Best when Selling to enterprise
02 — scope

Five criteria. You almost certainly don't need all five.

Security is mandatory. The rest are elective, and each one you add costs evidence and time — so we scope to what your buyers actually request, not to the maximum.

Required

Security

Access control, change management, monitoring, incident response, vendor risk.

Elective

Availability

Add it when you sell an SLA. Capacity, backup, recovery, incident tracking.

Elective

Processing integrity

For transaction processors and anyone whose output is the product.

Elective

Confidentiality

Commonly requested where you hold commercially sensitive client data.

Elective

Privacy

Notice, choice, retention and disposal of personal information.

03 — how it runs

Five stages, run under AICPA attestation standards.

Walkthroughs first, then a fixed period, then testing — with evidence requested in batches so your team is never blocked twice.

01 Week 1

Scoping call

A call with the practitioner who would lead the work. You leave with criteria, boundary, timeline and fee.

02 Weeks 2–5

Readiness & gap review

We walk through each process with its owner, document the system description and agree the evidence for every control.

03 Type II only

Observation window

Controls run for 3–6 months. We check in monthly so evidence is collected as you go, not scrambled at the end.

04 8–10 weeks

Fieldwork & testing

Inquiry, inspection, observation and re-performance on your systems, on a schedule that doesn't stall engineering.

05 Issuance

Report & renewal

Signed report, buyer-ready summary, bridge letter when needed, and dated milestones for next cycle.

04 — readiness

The six gaps we find most often.

None of these are hard to fix — they're just easier to fix before the observation window starts than during it. If you recognize three or more, start with a readiness review rather than an audit.

Ask for a readiness review →
Access reviews aren't evidenced

They happen, but nobody keeps the artefact that proves they happened.

Offboarding lags

Access removal isn't tied to the HR trigger, so timing can't be demonstrated.

Change management is informal

Approvals live in chat threads instead of the pull request or ticket.

Vendor risk is a spreadsheet

Subservice organizations aren't assessed, and their SOC reports aren't reviewed.

Incident response is untested

A policy exists; no tabletop or post-incident review has ever been run.

Scope is drawn too wide

All five criteria and every system in boundary, when two criteria would satisfy the buyer.

05 — audit once

One engagement can carry SOC 2, ISO 27001 and HIPAA.

Most of the control set overlaps. We map it once, test it once, and report against each framework separately — materially cheaper and far less disruptive than running the audits back to back.

SOC 2 + ISO 27001
Annex A controls and trust services criteria share most evidence.
one test cycle
SOC 2 + HIPAA
Security rule safeguards map to the security criteria almost line for line.
one test cycle
SOC 2 + penetration test
Not mandatory, but expected by most enterprise buyers alongside the report.
runs in parallel
What you can hold us to
You meet the engagement lead before the letter is signed
Evidence requested in batches on a published schedule
Exceptions raised as we find them, never saved for the draft
One business day to answer any question in writing
06 — who leads it

You meet the person who signs the report.

Before the engagement letter, you'll have spoken to the US CPA or CISA who leads the fieldwork and puts their name on the opinion. Junior staff support them; they never lead your engagement, and they don't own your scope.

Named lead on the engagement letter, not a resourcing pool.

Same lead through readiness, fieldwork and issuance — no handoffs.

One engagement lead from scoping through to the signed report.

07 — questions

What buyers ask us first.

Anything not covered here, email us — we usually reply the same business day.

contact@assurionservices.com
Can you audit us if we've never had a SOC 2 before?

Yes, and that's most first engagements. We start with a readiness review so the gaps are fixed before the observation window opens — auditing first and remediating after is how companies end up with exceptions in the report.

Will exceptions in the report lose us the deal?

Rarely, if they're explained. Security teams expect a small number of deviations and read management's response closely. What loses deals is a report with no detail on population sizes, or one that quietly avoids testing something in scope.

Do we need a compliance automation platform?

Not necessarily. If you already run one we'll pull evidence from it. If you don't, we won't make you buy one — for a first Type I the tooling rarely pays for itself, and a spreadsheet plus your existing ticketing is usually enough.

Who can we share the report with?

It's a restricted-use report: your user entities, their auditors, business partners and prospects with sufficient understanding of the system, usually under NDA. That's why we also issue a summary you can share more freely.

How much of our engineering team's time does this take?

Expect a few hours a week during readiness, then roughly a day a week across fieldwork, concentrated in one or two people. We schedule evidence requests in batches rather than trickling them out.

Can you take over from another auditor mid-cycle?

Yes. We'll review the prior report and workpaper scope, confirm the control set still matches your system, and pick up the period without restarting the observation window where the evidence supports it.

Fees

What a SOC 2 costs.

Quoted individually, in writing, before anything is payable. We do not publish a rate card, because the same report can mean very different work depending on what you run and what your buyer asked for.

What determines your fee

Criteria you select

Security is required. Each additional trust services criterion adds scope and cost.

Systems and environments

How many products, cloud accounts and environments the report covers.

Type I or Type II

A point-in-time opinion is materially less work than a 3–12 month observation period.

Subservice organizations

Whether third parties are carved out or tested inside your report.

State of your evidence

Whether controls are already monitored, or need establishing before testing.

First cycle or renewal

Renewals cost materially less; the matrix and evidence sources carry over.

Submitting a request and the scoping call are both free, and no card details are taken at either point. You receive a written fixed-fee proposal within three business days of the call — a single amount in US dollars, exclusive of applicable taxes, covering a stated scope and timeline. You are invoiced only after signing an engagement letter, and only for the fee stated in it. No subscriptions, no automatic renewals.

See how we price, our fees, payment, refunds and cancellation policy and terms of service. Please read both before submitting a request or making a payment.

Scope my engagement

Tell us the deadline. We'll tell you what's achievable.

A call, not a pitch. You'll leave with the criteria you actually need, a boundary, a timeline and a fee — whether or not you engage us.

Phone · Mon–Fri, 9–6 ET
+1 (307) 393-9419
SOC 2