Compliance & Regulations/North America/SOC 2
Sector · United States — globally recognised

SOC 2 Type II

The Trust Services Criteria attestation that has become the de-facto B2B SaaS security baseline globally.

Regulator
American Institute of CPAs (AICPA)
Jurisdiction
United States — globally recognised
Status
Active — TSC 2017 with 2022 points of focus update.
In force since
Active
Regulator's source
Who it applies to

Service organisations whose customers want assurance over Security, Availability, Confidentiality, Processing Integrity, or Privacy.

Audit / certification status

Safeguard maintains a current SOC 2 Type II report; available under NDA.

What it requires

What SOC 2 actually requires.

These are the obligations a regulated entity owes — the things an assessor or supervisor will ask about.

01

Security (Common Criteria) is mandatory; the other four are optional and chosen by management.

02

Type II covers a defined audit period (typically 12 months) with operational effectiveness testing.

03

Designed and operating controls aligned to the COSO Internal Control framework.

04

Sub-service organisation reliance — either inclusive or carve-out method.

05

Independent licensed CPA firm performs the engagement.

How Safeguard maps to it

Pre-mapped controls. Continuous evidence.

Each requirement above is bound to live telemetry — not screenshots. The mapping below is what your auditor or regulator sees.

Common Criteria (CC1–CC9) mapped to live telemetry with control owners and testing cadence.

Pre-built crosswalks to ISO 27001, HIPAA, and PCI-DSS — one evidence base, four reports.

Auditor portal: read-only auditor access with evidence sampling and download.

Continuous control monitoring replaces evidence sprint at year-end.

Evidence we produce

Artifacts your auditor accepts.

Each evidence artifact is signed and timestamped. Auditors can verify integrity without trusting Safeguard.

Control matrix with testing procedure and sample population.

Auditor evidence portal — sampled artifacts retrievable by control reference.

Sub-service organisation reliance documentation.

Annual SOC 2 Type II report, exported as bridge letters at quarter boundaries.

Ready for SOC 2?

Bring the framework. We'll walk the controls with you — section by section, evidence packet by evidence packet, with the regulators you actually have to answer to.

Safeguard | Software Supply Chain Security Platform | Zero CVE + Self-Healing