SECURO CERT

Attestation, assessment and label schemes

SOC 2:TSC 2017 (rev. 2022)

An attestation engagement, not a certification. A CPA firm renders an opinion on whether controls were suitably designed (Type I) and operated effectively over a period (Type II). The deliverable is a report a customer reads, not a wall certificate.

What you receive

Attestation report and opinion letter

Issued only by a licensed CPA firm under AICPA attestation standards. There is no such thing as a SOC 2 certificate.

This scheme does not produce a certificate. If a body has offered you one for SOC 2, that alone tells you what their audit work is worth.

Who needs it

Almost every B2B SaaS company selling into the United States. Frequently requested alongside, not instead of, ISO/IEC 27001.

Prerequisites

A defined observation period for Type II. Controls must have been operating throughout it.

How this engagement is delivered

Delivery mode — Managed

Programme managed by Securo Cert LLC. Audit and certification decision by the appointed partner body.

Securo Cert document not accredited

The partner body is named in the proposal before any work begins, and printed on the resulting document alongside the delivery mode.

Frequent questions

What do we actually receive?

Attestation report and opinion letter. Issued only by a licensed CPA firm under AICPA attestation standards. There is no such thing as a SOC 2 certificate.

How long is it valid?

Type I is a point in time. Type II covers an observation period, normally three to twelve months, repeated annually.

What has to be in place first?

A defined observation period for Type II. Controls must have been operating throughout it.