Framework · Service organisation attestation
SOC 2
The AICPA attestation framework for service organisations, evaluating controls against five Trust Service Criteria.
SOC 2 is the default expectation for UK SaaS scaleups and service organisations selling into US enterprise. Type 2 attestation is the standard most US procurement teams expect.
WHERE THIS FRAMEWORK FITS
Where this framework fits at Goldline
Goldline's active service lines are ISO 42001 (AI governance) and ISO 27001 (information security) implementation. SOC 2 is not a service Goldline delivers as a standalone product.
SOC 2 and ISO 27001 share 60 to 70 percent of controls. Organisations approaching SOC 2 typically find that an ISO 27001 implementation programme addresses the majority of SOC 2 requirements while delivering an internationally recognised certificate as a second outcome.
For active engagement, book a free 45 minute diagnostic and we will confirm whether the ISO 27001 Sprint (or, where AI governance is also in scope, the ISO 42001 Sprint) fits your specific circumstances.
Book the Free DiagnosticWhat is SOC 2?
SOC 2 is an attestation framework developed by the American Institute of Certified Public Accountants (AICPA) for service organisations. Unlike a certification, SOC 2 produces an independent attestation report from a licensed CPA firm evaluating controls against five Trust Service Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy. The Security criterion is mandatory; others are selected based on customer commitments. SOC 2 reports come in two types: Type 1 evaluates control design at a point in time; Type 2 evaluates operating effectiveness over an observation period of 3 to 12 months.
What SOC 2 covers
SOC 2 reports evaluate the design and operating effectiveness of controls relevant to the Trust Service Criteria selected for the engagement.
Security (Common Criteria)
The mandatory Trust Service Criterion. Protection against unauthorised access, both physical and logical.
Confidentiality
Information designated as confidential is protected from unauthorised disclosure across its lifecycle.
Availability
Systems are available for operation and use as committed in service-level agreements.
Processing integrity
System processing is complete, valid, accurate, timely, and authorised.
Privacy
Personal information is collected, used, retained, disclosed, and disposed of in conformity with privacy commitments.
Type 1 vs Type 2
Type 1: control design at a point in time. Type 2: operating effectiveness over a 3-12 month observation period.
Why UK organisations adopt SOC 2
SOC 2 adoption is driven by US enterprise procurement expectation, Series B+ investor due diligence, and the efficiency of parallel delivery alongside ISO 27001.
US enterprise procurement teams treat SOC 2 as the default expectation for SaaS supplier evaluation.
UK SaaS scaleups selling into US enterprise face SOC 2 expectations from procurement before contract award.
Investment due diligence at Series B and C now treats SOC 2 status as routine for B2B SaaS.
Substantial control overlap with ISO 27001 makes parallel implementation efficient (60-70% shared controls).
SOC 2 attestation is issued by a licensed CPA firm under AICPA professional standards, providing independent assurance.
Type 2 attestation demonstrates sustained operating effectiveness, the standard most US enterprise buyers expect.
METHODOLOGY
How Goldline delivers SOC 2 readiness
The Goldline Method applied to SOC 2 implementation. Seven phases from Trust Services Criteria selection through ongoing compliance maintenance, calibrated to organisations facing enterprise procurement gates and ongoing audit cycles.
- 01
Phase 1
Trust Services Criteria and scope selection
Senior practitioner-led scoping determines the purpose of the SOC 2 report and selects applicable Trust Services Criteria. Security is mandatory. Confidentiality, Availability, Processing Integrity, and Privacy added based on the data and services in scope. Type 1 versus Type 2 decision finalised.
- TSC selection
- Scope memorandum
- Type 1 or Type 2
- 02
Phase 2
Gap analysis and remediation plan
Senior practitioner gap analysis examines current practices against SOC 2 best practices. Identifies where security posture meets criteria and where remediation is required. Strategic remediation plan structured to address gaps in the most efficient path possible.
- Gap analysis
- Remediation plan
- Effort estimation
- 03
Phase 3
Stage-appropriate control design
Controls calibrated to organisational stage and risk profile. Enterprises and startups require different controls to demonstrate SOC 2 adherence. From logging and monitoring through HR processes and vendor management, the senior practitioner identifies which tools and processes deliver evidence efficiently.
- Control framework
- Tool selection
- Process design
- 04
Phase 4
Control implementation and risk assessment
Technical and operational controls implemented across the selected criteria. Risk assessment performed once controls are approximately 80 percent constructed. Risks identified through growth, geography, or operational change are documented with treatment or acceptance.
- Controls operational
- Risk register
- Treatment plan
- 05
Phase 5
Evidence collection and audit preparation
Evidence of implemented controls gathered and structured against the auditor's request list. Internal team prepared to answer auditor questions. Auditor identified and engaged. GRC platform configured for continuous evidence capture and audit-ready presentation.
- Evidence pack
- Auditor selection
- Walkthroughs prepared
- 06
Phase 6
Audit execution
SOC 2 audit performed by independent licensed CPA firm. Senior practitioner remains accountable through audit completion. Exceptions identified are remediated prior to report issuance.
- Audit fieldwork
- Exception remediation
- Report drafting
- 07
Phase 7
Continuous compliance and annual cycle
SOC 2 audits are performed annually. GRC platform integrations established during implementation collect evidence automatically and monitor practices continuously. This avoids heavy time commitments from operational teams and maintains audit-ready posture through each subsequent annual cycle.
- Continuous evidence
- Annual cycle
- Audit readiness
SOC 2 vs ISO 27001 vs ISO 42001
The three frameworks UK SaaS organisations most commonly evaluate alongside SOC 2.
| SOC 2 | ISO 27001 | ISO 42001 | |
|---|---|---|---|
| Type | AICPA attestation framework. US-developed. | International ISO/IEC standard. | International AI Management System standard. |
| Scope | Five Trust Service Criteria; Security mandatory. | Risk-based ISMS with 93 Annex A controls. | Annex B AI-specific controls and lifecycle governance. |
| Cycle | Annual attestation report from licensed CPA firm. | Three-year certification cycle with annual surveillance. | Three-year certification cycle. |
| Recognition | Recognised primarily in US enterprise procurement. | Globally recognised across procurement, regulatory, and investor audiences. | Most credible independent demonstration of responsible AI governance. |
Why Goldline
Senior practitioner-led delivery
Founder-engaged across every engagement. Thirteen years in UK regulated industries. Active credentials maintained against the standards in scope.
Audit-grade evidence, contract-grade outcome
Implementation produces the board-ready governance and audit continuity that customers, investors, and prime contractors expect.
UK regulatory and defence depth
ISO 27001, ISO 42001, SOC 2, GDPR, Cyber Essentials Plus, Defence Cyber Certification (DCC). Quarterly horizon scanning across FCA, DORA, NIS 2, ICO, and Defence Cyber Certification.
Fixed-scope, fixed-fee model
Productised engagements with transparent inclusions. No timesheet billing, no scope drift. The sequence is fixed. Your timeline is set at the free diagnostic.
Frequently asked
Discuss where this framework fits your programme
Goldline's active service lines are ISO 42001 and ISO 27001 implementation. Book the Free Diagnostic to discuss where SOC 2 fits alongside an ISO 27001 programme for your organisation.
