SOC 2

The leading standard for proving security to US buyers

SOC 2 is the report US buyers ask for in B2B procurement. It's an attestation by an auditor that your controls meet the Trust Services Criteria, either at a point in time (Type I) or over a period (Type II).

Who it applies to

SaaS and service companies selling to US customers, or to Nordic enterprises that have adopted SOC 2 in their procurement. If your sales team keeps getting asked for "your SOC 2", this is the framework.

What OptiTech provides

  • The Trust Services Criteria as controls: security plus the optional criteria (availability, confidentiality, processing integrity, privacy) you choose to include
  • Cross-mapping from your existing program: a working ISO 27001 or NIS2 program satisfies most of SOC 2's security criteria on day one
  • Continuous evidence for the audit period: Type II audits cover months of operation. OptiTech's evidence log means the period runs in the background instead of as a project.
  • Auditor collaboration: your audit firm reviews evidence through the read-only portal on the Enterprise plan

OptiTech doesn't perform the audit itself; you engage an audit firm, and OptiTech provides the evidence they review.

What non-compliance costs

Lost US deals. Without a SOC 2 report, US enterprise procurement usually stops at the security review.

Cross-mapping

SOC 2's security criteria overlap heavily with ISO 27001. Companies typically add SOC 2 as a second or third framework and start most of the way done.

Get started

SOC 2 is available on every plan. Book a free gap analysis or compare plans.

Need help?

Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.

Was this page helpful?