Skip to content
Radcore Security

SOC 2

Close the gaps between your control dashboard and a clean Type II.

SOC 2 is an attestation, not a certificate. Here's what it actually covers, what it costs in calendar time, and which parts we do.

What SOC 2 actually is

SOC 2 is an attestation report. A licensed CPA firm examines your controls and issues an independent opinion on whether they're designed and operating effectively. It is not a certificate, and no one "passes" SOC 2 in the way you'd pass an exam. There's no logo you're handed at the end. What you get is a report, and what your buyers actually want is to read it.

Radcore prepares you for that examination. We don't perform it, and we can't: independence rules prohibit the same firm from both preparing a company's controls and attesting to them. A separate, independent CPA firm does the actual audit. We introduce you to one and sit on your side of the table through it.

Type I vs Type II

Type I is a snapshot: the auditor confirms your controls are designed correctly as of one point in time. It's faster to get, and most enterprise buyers will accept it as a bridge while you work toward Type II.

Type II is the one buyers actually want. It confirms your controls operated effectively over a window of time: a minimum of three months, not negotiable, not something we or anyone else can compress. Most teams reach audit-ready in eight to ten weeks, then hold the observation window while the controls run for real.

The five Trust Services Criteria

A SOC 2 report is scoped to one or more of five criteria. Most B2B SaaS companies scope to Security alone: it's the only one required in every report, and it's what buyers are actually screening for.

  • Security The one almost everyone scopes to. Required in every SOC 2 report.
  • Availability Add it if uptime is a contractual promise you make to customers.
  • Processing Integrity Relevant if you're processing transactions or financial data for others.
  • Confidentiality Add it if you hold customer data under an explicit confidentiality agreement.
  • Privacy Rare to add, usually superseded by dedicated privacy law compliance instead.

A realistic timeline

1–2 wks

Assessment against the criteria you're scoping to

4–8 wks

Remediation: access, policies, evidence

3+ mo

Type II observation window

Who does what

  • Radcore

    Closes the flagged gaps: access reviews, MDM enrollment, written policy, control monitors, evidence prep, and sitting with you through fieldwork.

  • The CPA firm

    Independently tests your controls and issues the attestation report. Not us: independence rules require it.

  • Your team

    Operates the controls day to day. The report attests to what you actually do, not what we tell an auditor.

How our platform fits

A GRC platform automates evidence collection and control monitoring. It doesn't write your policies or close the gaps it finds. That's the work Radcore does, on our own proprietary GRC tooling and included in the engagement so there's no separate subscription: configuring monitors correctly, writing the policies automation can't, and translating what it flags into what an auditor actually expects to see.

Find out which gaps are actually blocking your report.

Book a gap review

Thirty minutes with Luke, our security lead. No charge.