Security · Availability · Confidentiality · Privacy
We evaluate security, availability, confidentiality, processing integrity, and privacy controls at service organizations. We demonstrate that your company protects your clients' data — strengthening trust and opening new opportunities.

Understanding the difference helps you choose the right assessment based on the maturity of your controls and the requirements of your clients, investors, and external auditors.
Swipe to see the full table
| Criteria | SOC 2 Type I — Design | SOC 2 Type II — Effectiveness |
|---|---|---|
| Main Focus | Assesses whether the security, availability, confidentiality, integrity, and privacy controls are properly designed and implemented. | Assesses the design and verifies the operating effectiveness of controls over a defined period. |
| Time Dimension | Performed as of a specific date to validate the implementation of controls. | Covers a continuous period, typically between 3 and 12 months of operation. |
| Type of Evidence | Demonstrates that controls exist and are designed to meet the applicable Trust Services Criteria. | Provides evidence through sampling that controls operated consistently throughout the period. |
| Ideal Use Case | Organizations starting their compliance program or that need to quickly demonstrate the existence of controls. | Organizations with mature controls that need to demonstrate ongoing operation to clients, investors, or strategic partners. |
| Estimated Timeline | 1 to 1.5 months from kickoff to report issuance. | Observation period + 1.5 to 2.5 months for execution and issuance. |
| Demand Level | Entry point — useful for demonstrating that controls exist and are implemented. | Most requested ⭐ Popular among corporate clients, investors, and auditors. |
Organizations that store, process, or transmit sensitive client information are the primary candidates for a SOC 2 audit under SSAE 18.
Swipe to see the full table
| Company Type | Service Provided | How It Handles Sensitive Information | Why It Needs SOC 2 |
|---|---|---|---|
| SaaS Companies | Software as a service and cloud platforms | Store and process client data in digital environments | Demonstrate proper controls to protect information and manage risk. |
| Cloud Providers | Infrastructure, storage, and cloud services | Manage critical systems and data for multiple clients | Build trust by demonstrating the security and availability of their services. |
| Fintech Companies | Digital payments, credit, and financial services | Process financial information and sensitive personal data | Demonstrate strong controls to protect information and meet regulatory expectations. |
| AI Companies | AI-based solutions | Use large volumes of data to train and operate models | Demonstrate secure data management, processing, and protection practices. |
| MSPs | Infrastructure management and technical support | Have privileged access to clients' systems and environments | Validate that effective controls exist to manage access and critical operations. |
| Data Centers | Hosting and operating technology infrastructure | Safeguard systems and data essential to third-party operations | Demonstrate physical and logical security controls. |
| HealthTech | Technology applied to the healthcare sector | Manage medical records and sensitive personal data | Strengthen trust with patients, clients, and regulators. |
| E-Commerce | Online sales and digital marketplaces | Process user data, payments, and transactions | Demonstrate that they properly protect customer information and operations. |
| Data Processing | Analysis, storage, and management of information | Continuously handle third parties' critical data | Demonstrate security, confidentiality, and availability controls. |
| Tech Startups | Development of digital products and services | Manage client information and third-party integrations | Facilitate sales processes and meet the security requirements demanded by enterprise clients. |
Our team reviews your service structure and recommends the most appropriate type and scope — at no cost.