Blog

Brian Johnson
Contributor

How To Stay SOC 2 Compliant | Advice For This Year’s Audit

November 7, 2018

It’s safe to say that not many service providers look forward to soc 2 compliance. I'd guess not many of you have the AICPA on speed dial. Whether you're preparing for a Type 1 or Type 2, audits may be perceived as events that you prepare for and complete, but then eventually they go away - at least for a

Read more
Brian Johnson
Contributor

What Is SOC 2 Type 2 | A Guide To Complete Your First Type 2 Audit

November 1, 2018

There are several different levels of SOC (Service Organization Control) reports and types, so it is easy to get them confused. A SOC 2 Type 1 report looks at an organization’s controls at a point in time concerning its clients’ financial reporting. The SOC 2 Type 2 report measures those same controls over a more extended period. SOC 2 Type

Read more
Brian Johnson
Contributor

How To Speed Up A SOC 2 Report | A Guide To Narrow SOC 2 Scope

October 30, 2018

One of the most critical steps is selecting members to lead the initiative. Many organizations start planning for SOC 2 thinking they can delegate responsibilities solely to members of the IT and information security staff. And although members of those teams will play a big part in the process, your core SOC 2 team will also include HR, legal and other business units as well. This blog will help you understand your core SOC 2 team and how to build it.

Read more
Brian Johnson
Contributor

SOC2 Team | Learn To Define Roles & Responsibilities

October 29, 2018

One of the most critical steps is selecting members to lead the initiative. Many organizations start planning for SOC 2 thinking they can delegate responsibilities solely to members of the IT and information security staff. And although members of those teams will play a big part in the process, your core SOC 2 team will also include HR, legal and other business units as well. This blog will help you understand your core SOC 2 team and how to build it.

Read more

What is SOC 2 Compliance | A Guide To Prepare For Your First Audit

October 5, 2018

If you sell software to businesses, clients will probably start asking if you're SOC 2 compliant? Why? Because it's a convenient way to confirm you have *some* maturity around security best practices. What SOC 2 is not! You should not confuse SOC 2 compliance for actual security best practices. Although it covers the core departments and processes that interact with

Read more

SOC 2 Type 1 Guide | Everything You Need To Know

October 5, 2018

The first time I went through SOC2 I wasted way way too many hours on Google trying to figure out best practices. It drove my nuts how much was written without actually telling me anything actionable. Why wasn't there a simple summary to understand: How long will a SOC 2 Type 1 audit take? How much will SOC 2 Type

Read more

How Much Does SOC 2 Cost | A Guide Budgeting For SOC 2

October 5, 2018

Before our first SOC 2 Type 1 audit, I assumed you pay an auditor, they come in make a few suggestion on how to improve and sign-off. It might take a few months, but the total cost would be some distraction plus the auditor's fee. That could not be farther from the truth. If you want to skip ahead to

Read more

Why We Built Comply | Free SOC 2 Policy Templates

May 21, 2018

SOC 2 can be a daunting process. Policies are subjective; auditors avoid providing much guidance; advice on the internet is incomplete or vague. We decided to create Comply, an open source collection of policy templates that includes best practices. We hope it reduces the stress of SOC 2 and points fellow startups in the right direction. SOC 2 involves every

Read more