Service organization assurance
SOC 2 readiness for service organizations
Build an examinable control environment for the service you actually deliver. We help technology teams define the system, operate controls, and prepare evidence for an independent CPA examination.
Our implementation focus
Make the requirements operational.
- 01
Define the system boundary and reporting goals
- 02
Map risks to applicable Trust Services Criteria
- 03
Implement and assign control owners
- 04
Establish evidence collection and exception handling
- 05
Prepare the system description and auditor handoff
SOC 2 produces an independent attestation report, not a certification. A licensed CPA firm performs the examination.
Questions we hear
Get the distinctions right.
Is SOC 2 a certification?
No. SOC 2 is an attestation examination performed by an independent licensed CPA firm. The outcome is a report on a described system and its controls.
Can a company outside the United States pursue SOC 2?
Yes. The decision is usually driven by customer assurance needs rather than the company’s home country. Reporting scope and criteria should reflect the actual service and its users.
How does SOC 2 relate to ISO/IEC 27001?
The same operating controls can support both efforts, but the outcomes differ: SOC 2 is a report on a service organization system; ISO/IEC 27001 sets requirements for an information security management system.
Market context
The same standard, different buyer questions.
Work with Normstone
Build a defensible path to readiness.
Tell us the outcome you need and the markets involved. We’ll help define the work.