Enterprise customers and investors ask for Type II. We coordinate the network infrastructure controls your auditor will test - access, monitoring, encryption, and availability.
SOC 2 is an auditing standard from the AICPA. A report demonstrates that your systems are designed and operating to meet one or more Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
A Type I report confirms controls were suitably designed at a point in time. Type II confirms they operated effectively over a period, typically six to twelve months. Most enterprise customers require Type II. That means monitoring, logging, and change management have to run continuously, not just be configured correctly on audit day.
We are an independent advisor, not a CPA firm. We do not issue the report and we cannot certify anyone. We source and oversee the network infrastructure controls in your scope, make sure they are documented, and work alongside whichever auditor you engage.
Security is required in every SOC 2. The rest depend on what you sell and to whom.
| Criterion | What it covers | Typical relevance |
|---|---|---|
| Security (Common Criteria) | Logical and physical access, system operations, change management, risk mitigation | Required in every SOC 2 audit |
| Availability (A) | Uptime and performance commitments, SLAs, monitoring, incident response, redundancy | Common when you carry uptime SLAs with customers |
| Confidentiality (C) | Protecting confidential information from disclosure - encryption, access control, classification | Common when you handle sensitive customer data |
| Processing Integrity (PI) | Processing is complete, valid, accurate, and authorized | Mostly financial and transaction systems |
| Privacy (P) | Collection, use, retention, and disposal of personal information | Less common; overlaps GDPR and CCPA |
The Common Criteria sections most affected by network infrastructure are CC6 through CC9.
We review the systems in scope, evaluate existing network controls against the Common Criteria, and produce a written gap report. We coordinate with your auditor or CPA firm so the assessment matches their expectations.
The missing controls get built - access management, monitoring, change control, encryption, failover. Each one is configured and documented the way testing procedures require.
Type II requires controls to operate over time. We keep the logs, handle exceptions, and document the evidence your auditor will sample during the observation window.
Your auditor gets direct access to monitoring dashboards, log exports, and control documentation. We answer network questions so your team is not translating between technical and audit language.
Free gap assessment against the Common Criteria - written, independent, no advisory fee.