SOC 2 Compliance and Attestation for SaaS Companies
Accelerate US enterprise contracts and investor confidence with SOC 2 Type 2 attestation. Security Brigade delivers platform-driven compliance with continuous monitoring evidence, structured gap analysis, and end-to-end audit support.
SOC 2 has become the de facto trust standard for SaaS companies selling to US enterprises. Whether you are a fintech raising from US investors, a B2B SaaS company pursuing enterprise deals, or a technology platform expanding into North America, SOC 2 readiness removes procurement friction and accelerates revenue. Security Brigade combines deep compliance expertise with proprietary platform capabilities to help you achieve and maintain SOC 2 readiness efficiently.
Trusted by India's leading enterprises
What it is
SOC 2 produces an opinion about a period, not a pass mark
A SOC 2 engagement ends with a report written by an independent CPA firm, describing the controls you said you operate, what the auditor did to test them, and what the auditor found, including anything that did not work. That is a different object from a certificate, and the difference decides how the whole programme should be run. There is no pass mark, so a report can contain exceptions and still be entirely usable; what matters to the enterprise buyer reading it is which Trust Services Categories were in scope, what the system description covers, whether the exceptions touch anything they care about, and what the auditor concluded. The other decision that shapes everything is Type 1 against Type 2. A Type 1 opines on whether controls were suitably designed at a single date. A Type 2 opines on whether they operated effectively across an observation window, typically three to twelve months, and it is what enterprise procurement almost always means when it asks for SOC 2. The practical consequence is that a Type 2 cannot be bought in a hurry: the window has to elapse with the controls genuinely running and generating evidence. Organisations that start by choosing an auditor instead of starting the clock lose a quarter, so our readiness work is built around getting controls operating and evidenced early enough that the window is not wasted.
Choosing scope
Five categories, and only one of them is not a choice
Each category you add extends the control set, the evidence burden and the audit fee. Adding one to look thorough is the most common avoidable cost on a SOC 2 programme.
| State | What it means | What follows |
|---|---|---|
| Security | The common criteria, included in every SOC 2 engagement. Governance, access control, change management, risk assessment, vendor management, incident response, monitoring. | Not optional, and the bulk of the work. For most organisations a Security-only Type 2 is exactly what their buyers are asking for. |
| Availability | Commitments about uptime, resilience and recovery, tested against what you actually promise contractually. | Worth including where you publish an SLA and customers hold you to it. It brings capacity planning, backup and recovery evidence into the audit. |
| Confidentiality | How information designated as confidential is protected through its life, including disposal. | Commonly added, and reasonable where customers entrust you with commercially sensitive material. The retention and deletion evidence is where it bites. |
| Processing Integrity | That system processing is complete, valid, accurate, timely and authorised. | Genuinely relevant to payments, billing and data pipelines; an expensive irrelevance for most other products. Include it because a buyer asked, not to look complete. |
| Privacy | Collection, use, retention, disclosure and disposal of personal information against your stated notice. | The heaviest to add, and it overlaps substantially with DPDP and GDPR work you may already be doing. Sequence it with that programme instead of running it twice. |
- Always in scope
- Include when a commitment exists
- Heaviest; sequence with privacy work
Who does what
The engagement has three parties, and only one of them can issue the report
| Party | What they do | What sits elsewhere |
|---|---|---|
| You | Define the system description and the commitments it makes, own the controls, and operate them through the observation window. The description is your assertion, and the auditor reports on it. | Cannot be assured by a party that built the controls for you without independence being considered |
| Security Brigade | Readiness: gap assessment against the criteria in scope, control design, policy and process build, technical testing, evidence collection through Lemon, and running the internal cadence so the observation window produces what the auditor needs. | Does not issue the report and does not express the opinion |
| Security Brigade is not a CPA firm and does not issue SOC 2 reports. We are the readiness and technical testing partner; we coordinate with your auditor, respond to queries and keep the evidence base current between windows. | ||
| The CPA firm | Performs the examination and issues the SOC 2 report with its opinion. Licensed to do so; independent of the control environment it is reporting on. | Engaged by you, coordinated by us |
You
- What they do
- Define the system description and the commitments it makes, own the controls, and operate them through the observation window. The description is your assertion, and the auditor reports on it.
- What sits elsewhere
- Cannot be assured by a party that built the controls for you without independence being considered
Security Brigade
- What they do
- Readiness: gap assessment against the criteria in scope, control design, policy and process build, technical testing, evidence collection through Lemon, and running the internal cadence so the observation window produces what the auditor needs.
- What sits elsewhere
- Does not issue the report and does not express the opinion
Security Brigade is not a CPA firm and does not issue SOC 2 reports. We are the readiness and technical testing partner; we coordinate with your auditor, respond to queries and keep the evidence base current between windows.
The CPA firm
- What they do
- Performs the examination and issues the SOC 2 report with its opinion. Licensed to do so; independent of the control environment it is reporting on.
- What sits elsewhere
- Engaged by you, coordinated by us
How we run it
Start the clock early, because the window is the long pole
-
Weeks 1-3
Scope, system description and gap assessment
Decide which categories are genuinely in scope against what you commit to contractually, draft the system description, and assess current controls against the criteria. This is where the cost of the whole programme is set.
-
Weeks 3-10
Build controls that can produce evidence
Policy and process build, technical control implementation, and the part most readiness work skips: wiring each control so that operating it leaves a record. A control with no artefact is an exception waiting to be written up.
-
Throughout
Technical testing that doubles as evidence
Penetration testing and vulnerability management run inside the programme, so the results answer the relevant criteria directly instead of arriving as a separate report nobody maps back.
-
The window
Operate, monitor, and correct before the auditor arrives
Through the observation period we track control operation in Lemon and surface drift while it can still be fixed. An exception found in month two is a correction; the same exception found by the auditor is in the report.
-
And after
Stay ready for the next window
SOC 2 is annual by nature: a report covers a period, and the period after it starts immediately. The organisations that find their second year cheap are the ones that never stopped collecting evidence.
Methodology
How a compliance engagement runs
Every engagement follows this process through Lemon, our proprietary audit management platform.
Security Brigade does not simply hand you a checklist. We work as an extension of your compliance and engineering teams, using our Lemon audit management platform to track every control, evidence artefact, and remediation task. Our methodology is informed by experience across 6,700+ security assessments, ensuring nothing is missed and your audit proceeds smoothly.
Scoping and Readiness Assessment
We define your SOC 2 system boundaries, identify applicable Trust Services Criteria, evaluate existing controls against SOC 2 requirements, and deliver a detailed gap analysis report highlighting what needs to change. Duration: 1 to 2 weeks.
Control Design and Policy Development
We help you design and document controls that satisfy each applicable criterion. This includes drafting information security policies, access control procedures, incident response plans, change management processes, and vendor risk management frameworks. Duration: 2 to 4 weeks.
Control Implementation and Evidence Collection
We work with your engineering and IT teams to implement technical controls, configure monitoring, establish logging and alerting, and set up continuous evidence collection mechanisms. Our B-52 platform capabilities satisfy CC7.1 and CC7.2 requirements for system monitoring, while Lemon manages CC5.3 and CC7.3 for control activities and change management. Duration: 3 to 6 weeks.
Penetration Testing from Customer Perspective
We conduct penetration testing of your SaaS application from the customer perspective, validating that security controls work as designed. This testing generates direct evidence for the SOC 2 audit and identifies any remaining vulnerabilities before the observation period begins. Duration: 2 to 3 weeks.
Observation Period and Continuous Monitoring
For Type 2 attestation, controls must operate effectively over an observation period of three to twelve months. We help you maintain continuous monitoring, generate evidence artefacts automatically via our platform, and conduct periodic reviews to ensure controls remain effective throughout. Duration: 3 to 12 months.
Audit Coordination and Attestation
We prepare your complete evidence package, coordinate with the CPA firm conducting the SOC 2 attestation, respond to auditor queries on your behalf, and support you through the final audit process until the SOC 2 Type 2 report is issued. Duration: 2 to 4 weeks.
"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
Continuous Compliance with ShadowMap
The audit gives you a snapshot. ShadowMap gives you the always-on view.
An annual audit proves your posture at a single point in time. Between audits, attack surfaces drift, credentials leak, sub-domains get added, vendors get breached. ShadowMap watches the boundary continuously so the next audit isn't a surprise.
Attack Surface
Continuous discovery of internet-facing assets: sub-domains, APIs, cloud resources, open ports, SSL certificates, technology stack.
Audits are point-in-time. ShadowMap watches your boundary daily.
Explore on ShadowMapDark Web Monitoring
12B+ breach records indexed; monitors Telegram, paste sites, criminal forums, and ransomware leak sites for credentials, leaked data, and threat actor mentions.
Find leaked data before regulators do.
Explore on ShadowMapThe platform underneath
The instrument sets the cadence. B-52 is what runs at it.
SOC 2 is an attestation about controls operating over a period, so evidence that accumulates across the period is worth more than evidence gathered at the end of it. That is the argument for running the testing continuously.
FAQ
SOC 2, answered before you pick an auditor
Type, scope and timing decide the cost. Talk to our team about what your buyers are actually asking for.
Contact usDoes Security Brigade issue the SOC 2 report?
Type 1 or Type 2?
Which Trust Services Categories should we include?
How does this relate to ISO 27001?
Do we need penetration testing for SOC 2?
What if the report comes back with exceptions?
Ready to Achieve SOC 2 readiness?
Start with a readiness assessment. Our compliance team will evaluate your current posture and provide a clear roadmap to attestation.
Typically responds within 1 business day · No commitment required