SOC 2 Compliance
For SaaS companies and service providers

Delivered by a cybersecurity firm, not a compliance shop.
Led by security practitioners, not checklist consultants.
Assessment. Remediation. Readiness. Audit. Report.
Now including the 2026 SOC 2 AI requirements.
SOC 2 basics

What is SOC 2?

SOC 2 is an attestation framework created by the American Institute of Certified Public Accountants (AICPA) to evaluate how well a service organization safeguards customer data. An independent auditor examines your controls against the Trust Services Criteria and reports on how those controls are designed and, in a Type II examination, how they actually operate over time. As of 2026, AICPA guidance also expects your report to address AI whenever AI is part of your service or your controls.
For SaaS providers, cloud vendors, and any company handling customer data, it has become the standard way to prove security to buyers. Done well, you do the work once and use it many times: one report answers dozens of customer security questionnaires instead of a new one for every deal.
Why companies pursue SOC 2

Trust has become a sales requirement

Faster sales cycles

Unlocks more deals and closes them faster

One report answers the security questionnaire before it slows down an enterprise deal.

Stronger security posture

Tighten real controls, not just paperwork

The work behind the report improves how you actually manage access, monitoring, vendors, and incidents.

Brand credibility

Show the market you take security seriously

Independent, AICPA-recognized evidence valued by security-conscious customers, partners, and investors.

Board and investor confidence

Give leadership independent proof the program works

A third-party opinion on your controls answers the question your board and investors are already asking.
Trust Services Criteria

Five criteria. Security is always in scope

Every SOC 2 report covers Security. The other four are added when they match what you promise customers. We help you choose the scope that buyers expect without taking on criteria you do not need.

Security

Required in every report. Protects systems and data against unauthorized access and disclosure.

Availability

Your system is available for operation and use as committed in your service agreements.

Processing integrity

System processing is complete, valid, accurate, timely, and authorized.

Confidentiality

Information designated as confidential is protected as committed or agreed.

Privacy

Personal information is collected, used, retained, disclosed, and disposed of in line with your commitments.
New for 2026: SOC 2 and AI

Using AI? Your SOC 2 now has to account for it

In September 2026, the AICPA issued new guidance, Q&A Section 9561, on how a service organization’s use of AI affects SOC 1 and SOC 2 examinations. The Trust Services Criteria still apply, but when AI is part of your service or your controls, auditors expect your report to address it.

System description

Disclose how you use AI before your auditor asks
We help you describe the types of AI you use, the models and data behind them, and how AI supports your service.

AI risk assessment

Address the AI risks auditors now look for
We assess accuracy, hallucinations, bias, explainability, data poisoning, prompt injection, and privacy, and design controls for each.

AI governance

Show clear oversight of every AI system
We define AI roles, responsibilities, and accountability, human review of AI output, and policies, and uncover shadow AI use.

AI at your vendors

Cover the AI your vendors use on your behalf
We extend vendor risk management to subservice organizations and providers whose AI affects your service.

Report scope

Choose criteria that hold up when customers rely on AI
If customers depend on AI output, Processing Integrity may be expected. We help you select a scope your auditor will accept.
Report types

SOC 2 Type I or Type II: which is right for you?

SOC 2 Type I: point in time

A fast first milestone

Confirms your controls are suitably designed as of a specific date. Often the first step toward a Type II observation period.
SOC 2 Type II: over time

The report most enterprise buyers expect

Confirms your controls operate effectively over an observation period, typically three to twelve months.
Included at no extra cost

SOC for Cybersecurity, included with every engagement

Every InfoGuard SOC 2 engagement includes a SOC for Cybersecurity report at no additional scope or fee. One engagement, two AICPA-recognized reports: one built for your customers, one built for your board, regulators, and public stakeholders.
SOC 2
SOC for Cybersecurity
Purpose
Reports on controls for security, availability, processing integrity, confidentiality, or privacy.
Reports on your entire cybersecurity risk management program.
Scope
A specific service organization, business unit, or service line.
Your whole organization's cybersecurity program.
Criteria
AICPA Trust Services Criteria.
Can use a recognized framework such as NIST CSF or ISO 27001.
Third-party risk
Subservice organizations can be carved out.
Must be addressed directly; it cannot be carved out.
Distribution
Restricted to customers and partners who need it.
General use; safe to share publicly.
Our SOC 2 approach

Cybersecurity at our core. Compliance built on it

Compliance should validate good cybersecurity, not substitute for it.

For 15+ years, InfoGuard has approached compliance through the lens of cybersecurity. We understand the technology, architecture, threats, controls, and operational realities behind the requirements, not just the checklist.

Cybersecurity at our core

Our expertise goes beyond policies and documents.

Deep technical expertise

Our cybersecurity extends to AI, cloud, applications, infrastructure, identity and access, networks, data protection, governance, risk, and emerging technologies.

Hands-on senior leadership

Our senior cybersecurity experts work alongside your team to implement practical controls and carry out the engagement through readiness, audit, and your final report.

Controls that hold up

We design controls your team can operate day to day across the full observation period, so Type II testing does not surface exceptions.

Your compliance investment should deliver more than checklists and documentation.
It should improve your cybersecurity as well.

How we help

From gap assessment to your final report, and beyond

01

Readiness & Gap Assessment

We evaluate your controls against the Trust Services Criteria that apply to you, identify every gap an examiner will test, and map the system boundary: every application, vendor, and data flow in scope.
02

Scope & Controls Design

We help you select the right criteria, design the technical and administrative controls to satisfy them, and build the policies and procedures your auditor expects to see before testing begins.
03

Build & Remediation

We implement the tooling and operational controls your design calls for, closing gaps in access management, monitoring, encryption, vendor management, and incident response, and assemble the evidence trail.
04

Mock Audit & Readiness

A mock audit that mirrors the real examination confirms your evidence and controls hold up before the clock starts on a Type II observation period.
05

Examination & Report

Our independent audit partner performs the official examination as part of your engagement: one point of contact through your final report.
06

Sustain & Monitor

A SOC 2 report has a shelf life; your controls should not drift in between. Ongoing monitoring, evidence collection, and policy maintenance keep your next period ready.
FAQ

SOC 2 questions, answered

Reports and process

A Type I report evaluates whether your controls are suitably designed as of a single point in time. A Type II report evaluates the same controls over an observation period, typically three to twelve months, and confirms they actually operated effectively throughout it. Most enterprise buyers expect a Type II.
A readiness assessment is a practice run through the evidence and control testing your auditor will perform, done before the official examination begins. It is the most reliable way to catch a gap while it is still inexpensive to fix.
A Type I report can often be issued within weeks once your controls are in place. A Type II report requires an observation period of three to twelve months on top of that, so most organizations budget several months from initial gap assessment to a final report.
Yes, when AI is relevant to your service. In September 2026, the AICPA issued Q&A Section 9561, which explains how a service organization’s use of AI affects SOC 2 examinations. The Trust Services Criteria are unchanged, but auditors now expect AI to be addressed in your system description, risk assessment, AI governance, and vendor oversight.
There is no fixed expiration date, but most enterprise buyers expect a report covering a period that ended within the last twelve months, so organizations typically renew on an annual cycle.
Incomplete evidence and inconsistently followed policies are the most common failure points, not missing technical controls. A readiness assessment before the real examination is the most reliable way to catch this while it is still cheap to fix.

Cost, scope, and fit

Cost depends on your organization’s size, the number of Trust Services Criteria in scope, and how much remediation your environment needs. There is no flat fee. We provide a firm quote after an initial gap assessment.
Possibly, yes. If your product touches customer data and you sell into enterprise or mid-market accounts, a SOC 2 report is frequently a prerequisite to closing the deal, regardless of your company’s size.
Yes. Early-stage and growth-stage companies are often the ones facing their first enterprise security questionnaire with the fewest resources in place to answer it. That is exactly where InfoGuard helps most.
Both evaluate your information security controls, but SOC 2 is an AICPA attestation aimed primarily at U.S. and North American buyers, while ISO 27001 is an internationally recognized certification against a management-system standard. Many organizations pursuing global enterprise deals eventually hold both.
Cybersecurity first

A checkbox compliance provider won't cut it

You need real cybersecurity expertise to earn a report that holds up under an enterprise buyer’s scrutiny.
InfoGuard is a cybersecurity firm first. Explore our cybersecurity services →
Next step

Tell us where you stand

Tell us what you’re trying to accomplish. We’ll reply with next steps, whether that’s a gap assessment, a mock audit, or a straight introduction to our audit partner.