Trust Services Criteria · AICPA

SOC 2 Audit
under SSAE 18

Security · Availability · Confidentiality · Privacy

We evaluate security, availability, confidentiality, processing integrity, and privacy controls at service organizations. We demonstrate that your company protects your clients' data — strengthening trust and opening new opportunities.

SaaSCloud Provider FintechHealthTechISAE 3000
SOC 2
AICPA Member
CPA Licensed Firm
SSAE 18 · Trust Services
USA & LATAM
Equivalent to ISAE 3000
Report Types

SOC 2 Type I vs SOC 2 Type II

Understanding the difference helps you choose the right assessment based on the maturity of your controls and the requirements of your clients, investors, and external auditors.

Swipe to see the full table

CriteriaSOC 2 Type I — DesignSOC 2 Type II — Effectiveness
Main FocusAssesses whether the security, availability, confidentiality, integrity, and privacy controls are properly designed and implemented.Assesses the design and verifies the operating effectiveness of controls over a defined period.
Time DimensionPerformed as of a specific date to validate the implementation of controls.Covers a continuous period, typically between 3 and 12 months of operation.
Type of EvidenceDemonstrates that controls exist and are designed to meet the applicable Trust Services Criteria.Provides evidence through sampling that controls operated consistently throughout the period.
Ideal Use CaseOrganizations starting their compliance program or that need to quickly demonstrate the existence of controls.Organizations with mature controls that need to demonstrate ongoing operation to clients, investors, or strategic partners.
Estimated Timeline1 to 1.5 months from kickoff to report issuance.Observation period + 1.5 to 2.5 months for execution and issuance.
Demand LevelEntry point — useful for demonstrating that controls exist and are implemented.Most requested ⭐ Popular among corporate clients, investors, and auditors.
Industries We Serve

What types of companies need a SOC 2 report?

Organizations that store, process, or transmit sensitive client information are the primary candidates for a SOC 2 audit under SSAE 18.

Swipe to see the full table

Company TypeService ProvidedHow It Handles Sensitive InformationWhy It Needs SOC 2
SaaS CompaniesSoftware as a service and cloud platformsStore and process client data in digital environmentsDemonstrate proper controls to protect information and manage risk.
Cloud ProvidersInfrastructure, storage, and cloud servicesManage critical systems and data for multiple clientsBuild trust by demonstrating the security and availability of their services.
Fintech CompaniesDigital payments, credit, and financial servicesProcess financial information and sensitive personal dataDemonstrate strong controls to protect information and meet regulatory expectations.
AI CompaniesAI-based solutionsUse large volumes of data to train and operate modelsDemonstrate secure data management, processing, and protection practices.
MSPsInfrastructure management and technical supportHave privileged access to clients' systems and environmentsValidate that effective controls exist to manage access and critical operations.
Data CentersHosting and operating technology infrastructureSafeguard systems and data essential to third-party operationsDemonstrate physical and logical security controls.
HealthTechTechnology applied to the healthcare sectorManage medical records and sensitive personal dataStrengthen trust with patients, clients, and regulators.
E-CommerceOnline sales and digital marketplacesProcess user data, payments, and transactionsDemonstrate that they properly protect customer information and operations.
Data ProcessingAnalysis, storage, and management of informationContinuously handle third parties' critical dataDemonstrate security, confidentiality, and availability controls.
Tech StartupsDevelopment of digital products and servicesManage client information and third-party integrationsFacilitate sales processes and meet the security requirements demanded by enterprise clients.
Frequently Asked Questions

Everything you need to know about SOC 2

What is a SOC 2 audit?+
A SOC 2 audit is an attestation report under the AICPA's SSAE 18 standard, based on the Trust Services Criteria. It evaluates security, availability, confidentiality, processing integrity, and privacy controls. It demonstrates that your company protects its clients' data with sound practices.
What's the difference between SOC 2 Type I and Type II?+
SOC 2 Type I evaluates the design and implementation of controls as of a specific date. SOC 2 Type II also evaluates operating effectiveness over 3 to 12 months — it's the most requested by corporate clients, investors, and external auditors.
How long does a SOC 2 audit take?+
A SOC 2 Type I can be completed in 1 to 1.5 months from kickoff. A SOC 2 Type II requires the observation period (3 to 12 months) plus an additional 1.5 to 2.5 months for execution and issuance. Reports are valid for one year.
Who can issue a valid SOC 2 report?+
Only a registered CPA firm with an active license from a State Board of Accountancy can issue a valid SOC 2 report under SSAE 18. Next Assurance meets all of these requirements and has coverage across the U.S. and all of Latin America.
Is SOC 2 recognized internationally?+
Yes. SOC 2 under SSAE 18 is widely recognized in the U.S. and internationally. Its content is substantially equivalent to the IAASB's ISAE 3000. Next Assurance can issue dual-use SOC 2 + ISAE 3000 reports for clients with international requirements.
What evidence is requested in a SOC 2?+
Security policies and procedures, control matrices, access monitoring evidence, incident logs, encryption configurations, continuity controls, and samples of control operation throughout the audited period (Type II). Scope varies according to the selected Trust Services Criteria.

Need a SOC 2 report?

Our team reviews your service structure and recommends the most appropriate type and scope — at no cost.