Back to Services
Certifications & Standards

SOC 2

SOC 2 readiness work prepares a service organization for an independent CPA firm's attestation against the AICPA's Trust Services Criteria.

This means a readiness assessment against the relevant criteria (Security is mandatory; Availability, Confidentiality, Processing Integrity, and Privacy are added based on what the product needs), closing control gaps, and designing the evidence-collection process the attesting firm will examine. A Type I report covers a single point in time; a Type II report — which carries more weight with enterprise buyers — covers control effectiveness over a 3-12 month observation period.

See how LumiGRC handles SOC 2

Get a Demo
I & II

Report types supported

0%
Typical engagement profile
Technical Depth63%
Engagement Length72%
Ongoing Support Need70%
Issued & Enforced By

AICPA

AICPA Trust Services Criteria

Key Points

  • Readiness assessment against the AICPA Trust Services Criteria
  • Control gap remediation ahead of the formal attestation
  • Evidence-collection process designed for the observation period
  • Type I (point in time) vs. Type II (over a period) support