Answers
What is SOC 2?
In short
SOC 2 is an AICPA framework for reporting on a service organisation's controls over security, availability, processing integrity, confidentiality and privacy — typically demanded by US enterprise buyers.
Short answer
SOC 2 is an AICPA framework for reporting on a service organisation's controls over security, availability, processing integrity, confidentiality and privacy — typically demanded by US enterprise buyers.
What this actually means in practice
A Type I report attests that controls are designed correctly at a point in time; Type II attests that controls operated effectively over a period (usually 6-12 months). The hard work is evidence collection: every control needs continuous evidence the auditor can sample.
The most common pitfall
Building a control library that produces evidence nobody samples, and missing the controls the auditor actually wants.
What to do next
Map your evidence pipeline before you scope the audit.
Frequently asked questions
Does Forth Systems help with this?
Yes — Forth Systems works with banks, payment institutions, insurers and infrastructure operators on exactly this kind of work. Engagements start with a fixed-scope assessment so you see the shape before committing.
How experienced is the team?
Engagements are staffed by named, UK-based senior engineers — not a rotating offshore pool. References from the second line of comparable clients are available on request.
Where are you based?
Edinburgh-based, delivering UK-wide with onsite presence in London and across Scotland as required.
How fast can we start?
Most engagements start within 2-4 weeks of a signed SoW, faster where an existing supplier framework is in place.
