
SOC 2 Readiness and Compliance FAQs
Take control of your cyber risk →
Frequently asked questions
What is SOC 2?
SOC 2 is an attestation developed by the American Institute of Certified Public Accountants (AICPA). It evaluates how effectively an organisation protects customer data, focusing on the systems, processes and controls in place. The framework is built around five Trust Services Criteria: Security (mandatory), Availability, Processing Integrity, Confidentiality and Privacy. Achieving SOC 2 demonstrates that your organisation is taking the right steps to safeguard sensitive information and meet growing client expectations.
What are the different SOC 2 report types?
There are two types of SOC 2 reports. A Type I report confirms that, at a specific point in time, the right controls and processes are in place and appropriately designed. A Type II report goes further by testing those controls over a period of time, usually six to twelve months, to demonstrate that they are operating effectively in practice. Many enterprise clients now require Type II reports as part of their due diligence.
Who delivers a SOC 2 attestation?
Only licensed CPA firms are authorised to issue SOC 2 attestation reports. While LRQA does not conduct the audit itself, we provide comprehensive readiness assessments, consultancy and remediation services. Our role is to ensure you are fully prepared, your documentation is in order, and any gaps are addressed before engaging a CPA to carry out the attestation.
Is SOC 2 a certification?
SOC 2 is not a certification. It is an attestation that provides independent assurance about your controls. The outcome is a detailed report that offers clients and stakeholders confidence in how you protect and manage their data. Although not a certification, SOC 2 is often viewed as a market requirement and can be a decisive factor in winning enterprise contracts.
What evidence is required?
Evidence is central to a successful SOC 2 attestation. Organisations must be able to demonstrate that systems, policies, procedures and controls are documented and consistently applied. This includes technical evidence, such as system logs and monitoring reports, as well as organisational evidence, such as policies, training records and incident response processes. LRQA helps you prepare and manage this evidence effectively, so you are confident when entering the audit.
Learn more about how LRQA can support your Cyber security needs
CASE STUDIES
-
McDonald's and LRQA - turning food safety risk into...
Case Study
For over 25 years, McDonald’s has partnered with LRQA, beginning with supplier audits and evolving into a comprehensive,...
Read more -
LRQA Awards ISO 19443 Certification to MHI
Case Study
Learn how LRQA awarded ISO 19443 certification to Mitsubishi Heavy Industries (MHI), marking a significant milestone in nuclear...
Read more -
LRQA partners with Aigens Technology
Case Study
LRQA supported Aigens in achieving critical security compliance, laying the groundwork for future system resilience and showcasing its...
Read more -
Driving confident investment decisions
Case Study
Learn how LRQA helped Goldman Sachs Asset Management (GSAM) portfolio companies to assess risk and build resilience.
Read more -
KSB SAS: Strengthening Nuclear Safety Culture with ISO 19443
Case Study
Learn how KSB SAS partnered with LRQA to strengthen its nuclear safety culture and ensure compliance. Explore their...
Read more -
Repsol ISO 14067 carbon footprint case study
Case Study
Discover how Repsol’s multidisciplinary team worked together to calculate the carbon footprint of High Purity Liquefied Gases (HPLGs),...
Read more