Managed security and compliance for regulated small businesses — Kansas City metro and nationally · (913) 601-8810
AICPA · Trust Service Criteria · SOC 2

SOC 2 — what enterprise clients actually mean when they say "show me your security."

SOC 2 is a voluntary framework until one of your clients requires it. Then it is a condition of doing business. BoTech builds and maintains your SOC 2 program and manages the evidence collection throughout the observation period.

Type I vs Type II — the real difference
SOC 2 TYPE I
Controls are designed correctly
Point-in-time snapshot. CPA confirms your controls are appropriately designed as of a specific date. Faster — typically 3 to 6 months. Good first step for organizations new to SOC 2.
SOC 2 TYPE II · What clients request
Controls operated effectively over time
Observation period of at least 6 months. CPA confirms controls operated continuously. Enterprise clients, insurance companies, and government contractors require Type II — not Type I. Cannot be shortened.
Trust Service Criteria

Five criteria. Security is always required.

Every SOC 2 audit covers Security. Availability, Confidentiality, Processing Integrity, and Privacy are selected based on what is relevant to your organization's services.

CC1–CC9 · ALWAYS REQUIRED
Security

The common criteria — logical and physical access controls, risk management, change management, monitoring, and incident response. Every SOC 2 audit includes all CC criteria.

A1 · OPTIONAL
Availability

Systems are available for operation as committed. Relevant for SaaS companies with uptime commitments, cloud services, or mission-critical systems with defined availability levels.

C1 · OPTIONAL
Confidentiality

Information designated as confidential is protected. Common for legal firms, financial advisers, and professional services organizations that handle sensitive client data under NDA.

PI1 · OPTIONAL
Processing Integrity

System processing is complete, valid, accurate, timely, and authorized. Most relevant for payroll processors, financial data processors, and transaction handling systems.

P1–P8 · OPTIONAL
Privacy

Personal information is collected, used, retained, disclosed, and disposed of in conformity with commitments and relevant regulations. Relevant for organizations that collect consumer personal data.

For most small businesses

Security criteria (CC1–CC9) plus Confidentiality is the most common scope for professional services firms, law firms, and financial services organizations. BoTech scopes your audit based on your services.

Discuss your scope →
What BoTech delivers

The full SOC 2 program — not just the audit prep.

Control Framework
All CC criteria mapped and implemented
System and Organization Controls policies written
Access controls — role-based, reviewed semi-annually
Change management and release procedures
Vendor risk management program documented
Evidence & Audit Preparation
Evidence collection configured from day one
Evidence organized per Trust Service Criteria
No gaps during 6-month observation period
CPA audit evidence package prepared
Workforce training documented per employee
Start the conversation

Build your SOC 2 program with BoTech.

BoTech builds and maintains SOC 2 programs for professional services firms in the Kansas City metro. Contact us to discuss your scope and timeline.

Or call (913) 601-8810