SOC 2 Type II
The report your US customers will ask to see.
SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report with an opinion. For SaaS companies selling into the United States it has become the default security diligence artefact.
SOC 2 Type II is included from the Shield plan.
Scope
Type I or Type II?
The distinction matters more than anything else on this page, because it determines how early you have to start collecting evidence.
Type I is a point in time
Controls suitably designed as at one date. Faster, cheaper, sometimes enough for a first deal.
Type II is a period
Controls operating effectively across a 3–12 month window. The one buyers usually mean.
Type II is won or lost on records
If a control was not evidenced during the window, it did not happen.
Security is mandatory, the rest are optional
Every report covers Security. The other four are added only where relevant.
The criteria
The Trust Services Criteria
Security is the common criteria set — CC1 through CC9 — and is included in every SOC 2 engagement. The other four categories are elective.
Every SOC 2 report covers the Security criteria, CC1 through CC9. The other four categories are optional and added only where relevant to what you promise customers: Availability (uptime and resilience), Confidentiality (protection of designated confidential data), Processing Integrity (complete, accurate and timely processing) and Privacy (personal information lifecycle).
| Criteria | Requirement | What it means in practice |
|---|---|---|
CC1 |
Control environment | Integrity and ethical values, board oversight, organisational structure, competence, and accountability. |
CC2 |
Communication and information | Internal and external communication of security commitments, responsibilities and information quality. |
CC3 |
Risk assessment | Objectives, identification and analysis of risk, fraud consideration, and assessment of significant change. |
CC4 |
Monitoring activities | Ongoing and separate evaluations, and communication of deficiencies to those who can act on them. |
CC5 |
Control activities | Selection and development of controls, including technology general controls and deployment through policy. |
CC6 |
Logical and physical access | Identity, authentication, authorisation, provisioning and de-provisioning, encryption, and physical access. In practice the heaviest section for a SaaS company. |
CC7 |
System operations | Vulnerability detection, monitoring for anomalies, incident response, and recovery from identified incidents. |
CC8 |
Change management | Authorising, designing, testing, approving and implementing changes to infrastructure, data, software and procedures. |
CC9 |
Risk mitigation | Risk mitigation activities for business disruption and for risks arising from vendors and business partners. |
A / PI / C / P |
Optional categories | Availability, Processing Integrity, Confidentiality and Privacy. Add only what you actually commit to customers — each one widens the audit. |
The path
What the engagement looks like
A SOC 2 report is issued by a licensed CPA firm. No software can produce one, and any vendor implying otherwise is selling you something that does not exist.
Only a licensed CPA firm can issue the report
Typical Type II observation window
Common criteria covered in every engagement
How often buyers expect a refreshed report
Most teams run a readiness assessment first
How CyberLetics helps
Evidence across the window, not a scramble at the end
CyberLetics ships 18 SOC 2 common criteria from CC1.1 to CC9.2. Because evidence is timestamped and checksummed as it is collected, a Type II observation window builds itself while you work.
Connect your systems (AWS, Microsoft 365, devices). Signals are collected every six hours. Each becomes an evidence snapshot with a SHA-256 checksum that cannot be edited. Controls are evaluated as pass or fail with that proof attached. Your score updates live and your auditor gets a read-only view of the controls, evidence and history.
A pre-loaded control library
18 common criteria, CC1 through CC9, ready to evidence.
Evidence that cannot be quietly edited
Every item is snapshotted with a SHA-256 checksum. Nothing changes after the fact.
Evidence collected for you
Connect Microsoft 365 or AWS. Re-checked every six hours, written to the trail.
A live score, not an annual scramble
Every control has a status and a history. Watch the number move.
Policies, risks and remediation in one place
Policy templates, a risk register and remediation tasks tied to controls.
Read-only access for your auditor
A scoped read-only view for your assessor. No screenshots by email.
info What CyberLetics does not do
CyberLetics cannot issue a SOC 2 report, and no software can. The report comes from a licensed CPA firm that examines your controls and forms an opinion; we are not that firm and we are not your auditor. We also cannot make a Type II window retroactive — if the evidence was not collected during the period, it is not in the report. What we do is hold the criteria, the controls and a timestamped evidence trail so the examination is straightforward.
Start collecting before the window opens
A Type II report only reflects what you evidenced during the period. Open a 14-day trial and start the trail now.
Also covered