by Assurion Services | Sep 2, 2026 | SOC 2
Somewhere in the middle of almost every SOC report there is a table that readers skim past on their way to the test results. It lists things the customer is expected to do. Those are complementary user entity controls, and they are the part of the report that quietly...
by Assurion Services | Sep 2, 2026 | SOC 2
Your SOC 2 Type 2 covers 1 January to 31 December. It is now March, a prospect is in a security review, and their vendor risk team wants to know what happened in the eleven weeks since the period ended. The usual answer is a bridge letter, and it will probably satisfy...
by Assurion Services | Sep 2, 2026 | SOC 2
If your platform runs on a cloud provider, uses a managed data centre, or hands part of the service to a specialist partner, your SOC report has to say something about them. You have two options for how. The carve-out method names the vendor, describes what you rely...
by Assurion Services | Aug 24, 2026 | SOC 2
For a first SOC 2 Type 2, three months is the usual answer when a deal is waiting and six months is the usual answer when it is not. After that, almost everyone settles into twelve-month periods that repeat annually. Choosing your SOC 2 observation window is really a...
by Assurion Services | Aug 24, 2026 | SOC 2
Every SOC 2 includes the Security criteria. The other four — Availability, Confidentiality, Processing Integrity and Privacy — are optional, and you choose them. The right way to choose is to look at what you have promised customers in writing, not at what sounds...