Independent assurance over the controls your customers are asking about.
A SOC 2 report is an independent CPA opinion on the controls a service organization uses to protect customer data, measured against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. Security is always in scope. The other four are included based on what your customers and contracts require.
Software companies, managed service providers, data processors, and digital-asset businesses are asked for one whenever a larger customer or partner runs vendor due diligence. Having a current report answers the security questionnaire once, for everyone.
Readiness assessment. We map your current controls to the criteria, identify the gaps, and give you a practical remediation list before any opinion is issued. Nothing in the readiness work appears in the final report.
SOC 2 Type 1. An opinion on whether your controls are suitably designed at a point in time. Usually the first report a company obtains.
SOC 2 Type 2. An opinion on whether those controls operated effectively over a review period, typically six to twelve months. This is the report most enterprise customers ultimately require.
We scope the systems and criteria with you, agree a timeline around your sales cycle, and test against evidence pulled from your own tools wherever possible so the work stays light on your team. The same people who plan the engagement perform it and sign the report, and they are reachable directly throughout.
Reports are issued by Kingston Ross Pasnak LLP under Canadian assurance standards and are accepted by Canadian and U.S. customers alike.