SOC 2 is a voluntary framework until one of your clients requires it. Then it is a condition of doing business. BoTech builds and maintains your SOC 2 program and manages the evidence collection throughout the observation period.
Every SOC 2 audit covers Security. Availability, Confidentiality, Processing Integrity, and Privacy are selected based on what is relevant to your organization's services.
The common criteria — logical and physical access controls, risk management, change management, monitoring, and incident response. Every SOC 2 audit includes all CC criteria.
Systems are available for operation as committed. Relevant for SaaS companies with uptime commitments, cloud services, or mission-critical systems with defined availability levels.
Information designated as confidential is protected. Common for legal firms, financial advisers, and professional services organizations that handle sensitive client data under NDA.
System processing is complete, valid, accurate, timely, and authorized. Most relevant for payroll processors, financial data processors, and transaction handling systems.
Personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments and relevant regulations. Relevant for organizations that collect consumer personal data.
Security criteria (CC1–CC9) plus Confidentiality is the most common scope for professional services firms, law firms, and financial services organizations. BoTech scopes your audit based on your services.
Discuss your scope →BoTech builds and maintains SOC 2 programs for professional services firms in the Kansas City metro. Contact us to discuss your scope and timeline.
Or call (913) 601-8810