SOC 2 Type II

The report your US customers will ask to see.

SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and issues a report with an opinion. For SaaS companies selling into the United States it has become the default security diligence artefact.

security Check your exposure free See pricing

SOC 2 Type II is included from the Shield plan.

Scope

Type I or Type II?

The distinction matters more than anything else on this page, because it determines how early you have to start collecting evidence.

01

Type I is a point in time

Controls suitably designed as at one date. Faster, cheaper, sometimes enough for a first deal.

02

Type II is a period

Controls operating effectively across a 3–12 month window. The one buyers usually mean.

03

Type II is won or lost on records

If a control was not evidenced during the window, it did not happen.

04

Security is mandatory, the rest are optional

Every report covers Security. The other four are added only where relevant.

The criteria

The Trust Services Criteria

Security is the common criteria set — CC1 through CC9 — and is included in every SOC 2 engagement. The other four categories are elective.

SOC 2 Trust Services Criteria: Security (CC1 to CC9) is in every report; Availability, Confidentiality, Processing Integrity and Privacy are added only where relevant to what you promise customers.Security · CC1 to CC9In every SOC 2 report. Not optional.ADD ONLY THE ONES YOU PROMISE CUSTOMERSAvailabilityuptime and resilience commitmentsoptionalConfidentialityprotection of designated confidential dataoptionalProcessing Integritycomplete, accurate, timely processingoptionalPrivacypersonal information lifecycleoptional

Every SOC 2 report covers the Security criteria, CC1 through CC9. The other four categories are optional and added only where relevant to what you promise customers: Availability (uptime and resilience), Confidentiality (protection of designated confidential data), Processing Integrity (complete, accurate and timely processing) and Privacy (personal information lifecycle).

Criteria Requirement What it means in practice
CC1 Control environment Integrity and ethical values, board oversight, organisational structure, competence, and accountability.
CC2 Communication and information Internal and external communication of security commitments, responsibilities and information quality.
CC3 Risk assessment Objectives, identification and analysis of risk, fraud consideration, and assessment of significant change.
CC4 Monitoring activities Ongoing and separate evaluations, and communication of deficiencies to those who can act on them.
CC5 Control activities Selection and development of controls, including technology general controls and deployment through policy.
CC6 Logical and physical access Identity, authentication, authorisation, provisioning and de-provisioning, encryption, and physical access. In practice the heaviest section for a SaaS company.
CC7 System operations Vulnerability detection, monitoring for anomalies, incident response, and recovery from identified incidents.
CC8 Change management Authorising, designing, testing, approving and implementing changes to infrastructure, data, software and procedures.
CC9 Risk mitigation Risk mitigation activities for business disruption and for risks arising from vendors and business partners.
A / PI / C / P Optional categories Availability, Processing Integrity, Confidentiality and Privacy. Add only what you actually commit to customers — each one widens the audit.

The path

What the engagement looks like

A SOC 2 report is issued by a licensed CPA firm. No software can produce one, and any vendor implying otherwise is selling you something that does not exist.

CPA firm

Only a licensed CPA firm can issue the report

3–12 mo

Typical Type II observation window

CC1–CC9

Common criteria covered in every engagement

12 months

How often buyers expect a refreshed report

Readiness

Most teams run a readiness assessment first

How CyberLetics helps

Evidence across the window, not a scramble at the end

CyberLetics ships 18 SOC 2 common criteria from CC1.1 to CC9.2. Because evidence is timestamped and checksummed as it is collected, a Type II observation window builds itself while you work.

How CyberLetics keeps you compliant: connect your systems, signals are collected every six hours, each becomes an immutable SHA-256 evidence snapshot, controls are evaluated against it, and your live score and a read-only auditor view update automatically.Connectyour systemsAWS, M365, devicesSignalscollectedevery six hoursEvidencesnapshotSHA-256, immutableControlevaluatedpass or fail, with proofLivescoreread-only auditor view

Connect your systems (AWS, Microsoft 365, devices). Signals are collected every six hours. Each becomes an evidence snapshot with a SHA-256 checksum that cannot be edited. Controls are evaluated as pass or fail with that proof attached. Your score updates live and your auditor gets a read-only view of the controls, evidence and history.

inventory_2

A pre-loaded control library

18 common criteria, CC1 through CC9, ready to evidence.

verified_user

Evidence that cannot be quietly edited

Every item is snapshotted with a SHA-256 checksum. Nothing changes after the fact.

sync

Evidence collected for you

Connect Microsoft 365 or AWS. Re-checked every six hours, written to the trail.

monitoring

A live score, not an annual scramble

Every control has a status and a history. Watch the number move.

assignment

Policies, risks and remediation in one place

Policy templates, a risk register and remediation tasks tied to controls.

group

Read-only access for your auditor

A scoped read-only view for your assessor. No screenshots by email.

info What CyberLetics does not do

CyberLetics cannot issue a SOC 2 report, and no software can. The report comes from a licensed CPA firm that examines your controls and forms an opinion; we are not that firm and we are not your auditor. We also cannot make a Type II window retroactive — if the evidence was not collected during the period, it is not in the report. What we do is hold the criteria, the controls and a timestamped evidence trail so the examination is straightforward.

Start collecting before the window opens

A Type II report only reflects what you evidenced during the period. Open a 14-day trial and start the trail now.

security Scan my site free Start 14-day trial

Also covered

ISO 27001:2022 →

The international certification. Frequently pursued alongside SOC 2.

DPDP Act 2023 →

India’s data protection law — mandatory, with penalties to ₹250 crore.