SOC 2 is the report US buyers ask for in B2B procurement. It's an attestation by an auditor that your controls meet the Trust Services Criteria, either at a point in time (Type I) or over a period (Type II).
Who it applies to
SaaS and service companies selling to US customers, or to Nordic enterprises that have adopted SOC 2 in their procurement. If your sales team keeps getting asked for "your SOC 2", this is the framework.
What OptiTech provides
- The Trust Services Criteria as controls: security plus the optional criteria (availability, confidentiality, processing integrity, privacy) you choose to include
- Cross-mapping from your existing program: a working ISO 27001 or NIS2 program satisfies most of SOC 2's security criteria on day one
- Continuous evidence for the audit period: Type II audits cover months of operation. OptiTech's evidence log means the period runs in the background instead of as a project.
- Auditor collaboration: your audit firm reviews evidence through the read-only portal on the Enterprise plan
OptiTech doesn't perform the audit itself; you engage an audit firm, and OptiTech provides the evidence they review.
What non-compliance costs
Lost US deals. Without a SOC 2 report, US enterprise procurement usually stops at the security review.
Cross-mapping
SOC 2's security criteria overlap heavily with ISO 27001. Companies typically add SOC 2 as a second or third framework and start most of the way done.
Get started
SOC 2 is available on every plan. Book a free gap analysis or compare plans.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.