Skip to main content

Framework · Service organisation attestation

SOC 2

The AICPA attestation framework for service organisations, evaluating controls against five Trust Service Criteria.

SOC 2 is the default expectation for UK SaaS scaleups and service organisations selling into US enterprise. Type 2 attestation is the standard most US procurement teams expect.

WHERE THIS FRAMEWORK FITS

Where this framework fits at Goldline

Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. SOC 2 is not a service Goldline delivers as a standalone product.

SOC 2 and ISO 27001 share 60 to 70 percent of controls. Organisations approaching SOC 2 typically find that an ISO 27001 implementation programme addresses the majority of SOC 2 requirements while delivering an internationally recognised certificate as a second outcome.

For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.

Book the Free Diagnostic

Browse all frameworks

What is SOC 2?

SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA) for service organisations. Unlike a certification, SOC 2 produces an independent attestation report from a licensed CPA firm evaluating controls against five Trust Service Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy. The Security criterion is mandatory; others are selected based on customer commitments. SOC 2 reports come in two types: Type 1 evaluates control design at a point in time; Type 2 evaluates operating effectiveness over an observation period of 3 to 12 months.

What SOC 2 covers

SOC 2 reports evaluate the design and operating effectiveness of controls relevant to the Trust Service Criteria selected for the engagement.

Security (Common Criteria)

The mandatory Trust Service Criterion. Protection against unauthorised access, both physical and logical.

Confidentiality

Information designated as confidential is protected from unauthorised disclosure across its lifecycle.

Availability

Systems are available for operation and use as committed in service-level agreements.

Processing integrity

System processing is complete, valid, accurate, timely, and authorised.

Privacy

Personal information is collected, used, retained, disclosed, and disposed of in conformity with privacy commitments.

Type 1 vs Type 2

Type 1: control design at a point in time. Type 2: operating effectiveness over a 3-12 month observation period.

Why UK organisations adopt SOC 2

SOC 2 adoption is driven by US enterprise procurement expectation, Series B+ investor due diligence, and the efficiency of parallel delivery alongside ISO 27001.

US enterprise procurement teams treat SOC 2 as the default expectation for SaaS supplier evaluation.

UK SaaS scaleups selling into US enterprise face SOC 2 expectations from procurement before contract award.

Investment due diligence at Series B and C now treats SOC 2 status as routine for B2B SaaS.

Substantial control overlap with ISO 27001 makes parallel implementation efficient (60-70% shared controls).

SOC 2 attestation is issued by a licensed CPA firm under AICPA professional standards, providing independent assurance.

Type 2 attestation demonstrates sustained operating effectiveness, the standard most US enterprise buyers expect.

METHODOLOGY

How Goldline delivers SOC 2 readiness

The Goldline Method applied to SOC 2 implementation. Seven phases from Trust Services Criteria selection through ongoing compliance maintenance, calibrated to organisations facing enterprise procurement gates and ongoing audit cycles.

  1. 01

    Phase 1

    Trust Services Criteria and scope selection

    Senior practitioner-led scoping determines the purpose of the SOC 2 report and selects applicable Trust Services Criteria. Security is mandatory. Confidentiality, Availability, Processing Integrity, and Privacy added based on the data and services in scope. Type 1 versus Type 2 decision finalised.

    • TSC selection
    • Scope memorandum
    • Type 1 or Type 2
  2. 02

    Phase 2

    Gap analysis and remediation plan

    Senior practitioner gap analysis examines current practices against SOC 2 best practices. Identifies where security posture meets criteria and where remediation is required. Strategic remediation plan structured to address gaps in the most efficient path possible.

    • Gap analysis
    • Remediation plan
    • Effort estimation
  3. 03

    Phase 3

    Stage-appropriate control design

    Controls calibrated to organisational stage and risk profile. Enterprises and startups require different controls to demonstrate SOC 2 adherence. From logging and monitoring through HR processes and vendor management, the senior practitioner identifies which tools and processes deliver evidence efficiently.

    • Control framework
    • Tool selection
    • Process design
  4. 04

    Phase 4

    Control implementation and risk assessment

    Technical and operational controls implemented across the selected criteria. Risk assessment performed once controls are approximately 80 percent constructed. Risks identified through growth, geography, or operational change are documented with treatment or acceptance.

    • Controls operational
    • Risk register
    • Treatment plan
  5. 05

    Phase 5

    Evidence collection and audit preparation

    Evidence of implemented controls gathered and structured against the auditor's request list. Internal team prepared to answer auditor questions. Auditor identified and engaged. GRC platform configured for continuous evidence capture and audit-ready presentation.

    • Evidence pack
    • Auditor selection
    • Walkthroughs prepared
  6. 06

    Phase 6

    Audit execution

    SOC 2 audit performed by independent licensed CPA firm. Senior practitioner remains accountable through audit completion. Exceptions identified are remediated prior to report issuance.

    • Audit fieldwork
    • Exception remediation
    • Report drafting
  7. 07

    Phase 7

    Continuous compliance and annual cycle

    SOC 2 audits are performed annually. GRC platform integrations established during implementation collect evidence automatically and monitor practices continuously. This avoids heavy time commitments from operational teams and maintains audit-ready posture through each subsequent annual cycle.

    • Continuous evidence
    • Annual cycle
    • Audit readiness

SOC 2 vs ISO 27001 vs ISO 42001

The three frameworks UK SaaS organisations most commonly evaluate alongside SOC 2.

 SOC 2ISO 27001ISO 42001
TypeAICPA attestation framework. US-developed.International ISO/IEC standard.International AI Management System standard.
ScopeFive Trust Service Criteria; Security mandatory.Risk-based ISMS with 93 Annex A controls.Annex B AI-specific controls and lifecycle governance.
CycleAnnual attestation report from licensed CPA firm.Three-year certification cycle with annual surveillance.Three-year certification cycle.
RecognitionRecognised primarily in US enterprise procurement.Globally recognised across procurement, regulatory, and investor audiences.Most credible independent demonstration of responsible AI governance.

Why Goldline

Senior practitioner-led delivery

Founder-engaged across every engagement. Thirteen years in UK regulated industries. Active credentials maintained against the standards in scope.

Audit-grade evidence, contract-grade outcome

Implementation produces the board-ready governance and audit continuity that customers, investors, and prime contractors expect.

UK regulatory and defence depth

ISO 27001, ISO 42001, SOC 2, GDPR, Cyber Essentials Plus, Defence Cyber Certification (DCC). Quarterly horizon scanning across FCA, DORA, NIS 2, ICO, and Defence Cyber Certification.

Fixed-scope, fixed-fee model

Productised engagements with transparent inclusions. No timesheet billing, no scope drift. The sequence is fixed. Your timeline is set at the free diagnostic.

Frequently asked

Discuss where this framework fits your programme

Goldline's active service lines are ISO 42001 and ISO 27001 implementation. Book the Free Diagnostic to discuss where SOC 2 fits alongside an ISO 27001 programme for your organisation.

We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.