SOC 2 Type II
Service Organisation Controls report Type II — an AICPA-defined audit of the design AND operating effectiveness of controls at a service organisation, over a specified period (typically 6-12 months). The standard procurement-readiness attestation for cloud services serving regulated customers.
SOC 2 vs SOC 1 vs SOC 3
SOC 1 covers financial-reporting controls. SOC 2 covers operations and security controls relevant to service users — the typical "is this cloud service trustworthy?" question. SOC 3 is a public-facing version of SOC 2 without the detailed evidence. For cloud providers, SOC 2 is the meaningful attestation.
The five Trust Services Criteria
- Security — required; covers access controls, change management, system operations.
- Availability — uptime, incident handling, recovery.
- Processing integrity — operations complete correctly, timely, accurate.
- Confidentiality — confidential data is protected.
- Privacy — personal data is handled per the organisation's commitments.
Organisations choose which criteria the report covers. Cloud providers typically include Security, Availability, and Confidentiality at minimum.
Type I vs Type II
Type I is a point-in-time attestation: "as of date X, controls are designed appropriately." Type II is over a period: "from date X through date Y, controls are designed AND operating effectively." Type II carries substantially more weight; most enterprise procurement requires Type II.
The continuous-evidence question
SOC 2 Type II audits require evidence collected over the report period — typically 6-12 months. Organisations whose evidence is reconstructed at audit time face long, expensive engagements with high risk of findings. Organisations with continuous, signed, automated evidence collection sail through.
SkyeConnex's posture
The audit-log infrastructure is SOC 2 Type II-aligned from the architecture up. Dual-signed reports (HMAC-SHA-256 + ML-DSA-87) make evidence externally verifiable. Continuous control monitoring is delivered through the provider heartbeat infrastructure. Compliance preset packs encode SOC 2 evidence-collection patterns.
SOC 2 + ISO 27001
Many organisations pursue both SOC 2 and ISO 27001 because they answer overlapping but distinct customer questions. SkyeConnex's architecture is amenable to both.