Skip to main content
FRAMEWORK

Get SOC 2 ready — continuously, not in a scramble.

SOC 2 is not a regulation but an attestation. An independent CPA firm examines a service organization's controls against the AICPA's Trust Services Criteria — security required, with availability, processing integrity, confidentiality and privacy scoped to what the service actually does — and issues the report your customers ask for. The report is the output; the evidence underneath it is the work.

For a service organization this is an operating problem, not a documentation problem. The examination asks whether controls operated across a window; the controls mostly did operate — what fails is proving it afterwards, from memory and screenshots. Evidence collected as a by-product of operations makes the audit an export rather than a reconstruction.

Who it applies to

Service organizations — any company whose customers, or customers' auditors, need assurance about how their data is handled. The examination is performed and the report issued by an independent CPA firm; TruSecure automates the evidence collection the audit runs on, and does not perform the attestation itself.

The audit cycle, without the scramble

A Type I report describes controls at a point in time; a Type II examines whether they operated across a period — commonly an annual window. Each cycle asks the same thing: for each control in scope, evidence that it existed and that it operated. Collected continuously, that evidence is a by-product of operations; assembled at the end of a window, it is a project. The difference is not diligence — it is when the evidence is produced.

What it asks, in operating terms

Read as an audit requirement rather than a report deadline, SOC 2 reduces to a handful of standing asks — each answerable from a live control state, not reconstructed in the final month.

SOC 2 requirements · how TruSecure answers them
What SOC 2 asksWhere it is answered
Scope the criteria and map controls to eachControl library · every control cited by the criterion it satisfies
Show controls operated across the windowEvidence automation · continuous, provenance-tracked
Carry exceptions honestly — open, owned, datedRisk management · exceptions with expiry and re-review
Show what changed and who approved itAudit trail · every change, approval and AI proposal logged
Give the CPA firm what it samples, quicklyAuditor export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what an evidence file is made of:

SOC 2 evidence file · excerptSample data
Criteria in scope
Security · Availability · Confidentiality
Controls mapped
61 · each tied to a criterion
Evidence freshness
continuous · provenance tracked
Open exceptions
1 · closes before the window ends
Export
sealed · sha256:2d94…7be1

Where teams usually start

With a demo walked through by TruSecure — the criteria mapped onto controls you already operate, the evidence file opened to a single control, the export your CPA firm samples from. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

SOC 2 is an AICPA attestation covering security, availability, processing integrity, confidentiality, and privacy criteria, issued by an independent CPA firm. TruSecure automates the continuous evidence collection a SOC 2 audit requires; it does not perform the attestation itself.