SOC 2 audit for SaaS and IT companies

Independent SOC 2 audits for service organizations in the Netherlands. From scoping and readiness to Type I and Type II assurance reporting.

Need a SOC 2 audit?

From customer demand to an accepted report, without detours

Has a large customer or prospect asked for a SOC 2 report? Then you want to know two things: what exactly is coming your way, and how to get to a report your customers will accept. Secure Audit performs independent SOC 2 audits for SaaS companies, cloud providers and other service organizations. Dutch IT auditors, a fixed quote up front and an audit platform that lets you follow the entire engagement.

#1
Most requested standard by enterprise customers
Type I & II
Both report types, with a fixed quote up front
AICPA
International attestation standard
The basics

What is a SOC 2 audit?

With a SOC 2 report, a service organization demonstrates that the controls around its services operate reliably. An independent auditor tests those controls against the AICPA Trust Services Criteria and records the opinion in an assurance report you share with customers. Formally, SOC 2 is an attestation rather than a certification; in practice the report plays the same role as proof towards your customers.

The five Trust Services Criteria

Security is always in scope. The other four categories are included when they fit your services and your customers' expectations. We determine the scope together with you during the scoping phase.

Always required
Security
Availability
Confidentiality
Processing Integrity
Privacy

Deep dives: what is SOC 2? and the Trust Services Criteria in detail.

Two variants

SOC 2 Type I versus Type II

For a first report, a Type I is often a practical starting point: you show where you stand before the longer assessment period of a Type II begins. Enterprise customers ultimately almost always ask for a Type II.

Point in time
Type I
  • Design and existence of controls
  • Assessment at one specific moment
  • No test of operation over time
  • Good starting point for a first audit
Duration: 1 day (point in time)
Most requested
Period
Type II
  • Design and operating effectiveness
  • Tested over a period of 3 to 12 months
  • More assurance for customers
  • The most requested variant in practice
Duration: 3 to 12 months

Not sure which type fits? Read about the difference between Type I and Type II or put your situation to us.

Audience

Who is SOC 2 for?

SOC 2 is relevant for any organization that delivers services involving the processing, storage or management of customer data. In the Netherlands, demand comes mainly from SaaS companies serving enterprise customers or US-based partners: there, the report is increasingly a condition for qualifying as a vendor.

SaaS providersCloud providersData centersManaged Service ProvidersFintechHR tech

How that customer demand arises in practice is covered in SOC 2 for SaaS companies.

Approach

How a SOC 2 audit works at Secure Audit

For each applicable Trust Services Criterion we perform a risk analysis on the relevant points of focus. The medium and high risks determine the key controls in the work program. We test those through interviews, documentation review, system configuration inspections and evidence.

1
Intake and quote
We discuss your services, your customers and why they are asking for SOC 2. You receive a fixed quote for the entire engagement.
2
Scoping
Together we determine which systems, processes and Trust Services Criteria are in scope. No more and no less.
3
Readiness assessment
We assess your current controls against the criteria and spell out exactly what still needs to happen before the audit starts.
4
Implementing controls
You implement the missing measures. Our readiness findings serve as your work list.
5
Audit
We test design and existence (Type I) and, for Type II, operating effectiveness over the observation period, through interviews, documentation review and evidence in our audit platform.
6
Assurance report
You receive the SOC 2 report with system description, controls, test results and our independent opinion, ready to share with customers.
The result

A formal assurance report with a description of your system, the relevant controls, the test results and our independent opinion. You share that report with customers, prospects and other stakeholders.

After that: an annual cycle

A SOC 2 Type II report covers a period. Customers therefore expect a new report every year. We set up the engagement so that the annual repeat becomes predictable and manageable, with evidence you build up in the platform throughout the year.

Preparing yourself?

Read how to prepare for a SOC 2 audit and what you can arrange today.

Investment

What does a SOC 2 audit cost?

A fixed rate without knowing your situation would be a shot in the dark. Four factors drive the price.

01

Scope

How many Trust Services Criteria do you include besides Security, and how many systems and processes fall within the report?

02

Report type

A Type II requires more audit hours than a Type I, because operating effectiveness over the observation period is also tested.

03

Maturity

The more controls and documentation you already have in place, the less readiness work is needed before the audit can start.

04

Complexity

The number of locations, teams and subservice organizations and the design of your infrastructure determine the size of the work program.

Fixed quote after scoping
After the intake and scoping you receive a fixed price for the entire engagement. No surprises halfway through.
Request a quote →
Why Secure Audit

Dutch auditors, our own platform

Our own audit platform

Work program, evidence, findings and communication in one place. Throughout the engagement you can see where you stand and what remains open. See the platform

Dutch team

You deal directly with the IT auditors doing the work, with knowledge of the Dutch market and of international customer requirements.

More than compliance

Where needed we support the design of controls, so you do not just obtain a report but come out of the engagement stronger.

Combinable

Also need ISAE 3402, ISO 27001 or DigiD? We combine engagements where possible, so you only submit evidence once. All IT audit services

FAQ

Frequently asked questions about SOC 2

Ready to start your SOC 2 engagement?

Schedule a no-obligation intake call. You will get an honest picture of the scope, the timeline and the cost for your situation, with a fixed quote after scoping.