This SOC 2 consultancy service has been designed to help service organisations rectify the gaps in their compliance with the AICPA (American Institute of Certified Public Accountants) TSC (Trust Services Criteria), as identified by our SOC 2 Readiness Assessment.
Full project pricing depends on the size and complexity of your organisation and the level of assistance you need. Please contact us to discuss your requirements.
SOC 2 audit reports enable service organisations to demonstrate to clients and other stakeholders that they have implemented appropriate controls in relation to security, availability, processing integrity, confidentiality and privacy.
This consultancy service has been designed to help you prepare for and pass a SOC 2 audit. It highlights the corrective actions your organisation must take to ensure its security controls conform to the TSC before seeking a SOC 2 audit.
A SOC 2 audit can only be performed by an independent CPA (certified public accountant) or duly recognised accountancy organisation regulated by the AICPA.
CPA organisations may employ non-CPA professionals with relevant information technology and security skills to participate in preparing for a SOC audit, but the final report must be provided and issued by a CPA. A successful SOC audit carried out by a CPA permits the service organisation to use the AICPA logo on its website.
A SOC 2 audit report provides information and assurances about the suitability of the design and effectiveness of the service organisation’s controls. The report is generally restricted use for existing or prospective clients.
The SOC 2 Remediation Service can help you rectify any compliance gaps identified by our SOC 2 Readiness Assessment.
Remediation consultancy is specific to each organisation but typically could include the following:
A SOC 2 audit:
SOC 2 audits are aimed at organisations that provide services to other organisations.
If, for example, your organisation provides Cloud services, a SOC 2 audit report will go a long way to establishing trust and credibility with customers and other stakeholders, particularly if you process confidential or personal data.
We can help you prepare for a SOC 2 audit by:
If our SOC 2 Readiness Assessment identifies any issues that need to be addressed, we can help you rectify them. Remediation consultancy is specific to each organisation but typically could include:
Additional services, such as penetration testing or advising on integrating your SOC 2 requirements into your ISO 27001-compliant ISMS (information security management system), can also be provided.
IT Governance specialises in international management system standards, IT governance, cyber security, cyber incident response management, risk management and compliance.
Our professional services team has a wealth of consultancy skills and technical expertise. This multi-disciplinary knowledge and experience means we can help you achieve your project objectives wherever you are in the world.