This includes knowing which systems are in scope for the audit, developing policies and procedures, and putting new security controls in place to reduce risks.
When ready, an organization will engage the service of a licensed CPA auditor to carry out the audit. The real process involves scoping, artifact document collection, and an on-site visit. The time commitment is usually several hours of introductory phone conversations and two days in-person in the office. While in the office, the auditor will carry out interviews and review the material submitted. When starting to scope a SOC 2 audit, some key decisions that will need to be made ahead of. First, what type of audit do you want; Type I or Type II?
A lot of newbies may find this terminology confusing - so many numbers and Roman numerals threw around.
Here’s a simple way to remember:
If the decision about choosing a SaaS provider comes down to you and a competitor, having SOC 2 Type II compliance will boost your chances of being the preferred choice. Emphasizing the fact that you are SOC 2 compliant and stating the type of audit can be a game-changer, especially as companies that know better will look for Type II.
Eighty-eight percent of consumers research their options online before making a purchase, so make sure you remember to highlight your SOC 2 compliance on your website.
For example, Intercom has a page on their website set aside for their security measures, which has details of their SOC 2 compliance.
So, like Intercom, when you get your SOC 2 Type II report, add the following information to your website:
Since about 77% of the U.S. population have a social media account, go a step further by sharing your SOC 2 status on platforms such as Twitter and Facebook. That way, as your potential customers research their options on platforms where they spend most of their time, your announcement gets noticed and it invites them in to get more information about your data-security standards.
Be creative in the way you share your compliance. You want it to be seen by your audience, so research where they spend the most time online and place it there for them to see. Your promotion strategy should therefore include industry platforms and social media.
Meeting the needs of customers is crucial to your success, so use their insights to make sure your SOC 2 compliance is relevant to them.
There are several ways to know the needs of customers. Here are a few examples to try:
Review follower comments on social media. Use your Facebook business page to see the types of comments your audience leaves on posts, the types of content they share on your page and their own, and the type of positive or negative feedback they leave.
As technology continues to evolve and threats—both known and unknown—continue to increase as well, it’s important to carry out regular audits of the principles your business focus on.
Let’s take Auth0 as an example once again; they’re always deploying new releases—about three to four times a day. The implication of that is that they have processes in place to track each of the releases. To adhere to the procedures they committed to in the Security principle of their SOC 2 Type II report, Auth0 requires that another team member approve updates before moving anything from staging to production.
Also, Auth0 continues to run three types of tests—function, function, and HTTP—to make sure the code, user interface, and APIs are operating as they should. And since these tests are done using Slack integrations, there’s also a historical log of what had run, and when.
When you come up with policies and procedures for your SOC 2 Type II report and audit, use the following questions as a guide. Bear in mind that these questions apply to all principles:
The answers provided to such questions as these lay the foundation for your SOC 2 report and help you look forward to and plan for threats.
There are four steps to take as you get ready for your audit:
Between the two types of SOC 2 compliance audits, SOC 2 Type II usually takes more time. Begin your preparation months before your scheduled audit to give yourself adequate time to find and fix issues, and to make sure that your procedures fully support your principles. Take time to find opportunities to step up on security, upgrade documentation, and let your team know about the updates.
While preparing for your SOC 2 audit, here are five traps to be careful of:
1. Scoping poorly the audit report to set the boundaries and services of the data system.
A critical mistake most companies make is forgetting to specifically define which services will be used or removed from the system that’s defined in the SOC 2 report.
2. Insufficient documentation on the major internal controls that are in scope
The company management or the CTO must come up with a description of the main internal controls of a system. This should sufficiently explain the following:
3. Beginning the audit test without conducting a readiness assessment
Starting the SOC 2 compliance audit before your organization is ready will result in a lengthy audit process. Time will be wasted and that will cost the company. Make sure you request a readiness assessment from your audit partner. This will open up issues and help you resolve them before the SOC 2 audit.
4. Not clearly setting audit boundaries between your company’s environment and third parties
Most companies make use of external vendors to perform services. An example is a cloud service provider. You should make sure to separate compliance within their company and their service provider.
5. Not consolidating your different compliance requirements into one SOC report.
Don’t miss the opportunity to consolidate other compliance requirements into your SOC report. SOC 2 reports can include related subject matter, an approach that can reduce your costs and resource efforts.
Data security is the key to business success. Companies like Intercom and Auth0 have demonstrated the value of SOC 2 compliance. While all of their growth and success isn’t purely a result of the certification, it’s played a role in helping them attract large enterprise businesses. SMB and enterprises that rely on your services need to be confident that you are prepared for security threats. These customers are more likely to choose you and refer you to their network.
It’s a good idea to consider becoming SOC 2 compliant early in your company’s journey if you know you are going to be selling technology services to enterprises and will be storing and/or accessing sensitive customer data of any sort.
While it can be challenging to undertake a SOC 2 compliance exercise while you are small and under-resourced, it can be even harder to do once you grow larger. The larger your company is and the further along you are in your growth, the harder it is to change culture, processes, tools, and more.
When you are smaller, you may not have an IT or security owner, but as soon as you do hire someone in a role like that, you may want to begin thinking about preparing for SOC 2 compliance. Sooner is better, since it will help you integrate the processes and controls into your team’s culture from the get-go.
Subscribe for the latest news