home / frameworks / soc-2 / preparing-for-a-soc-2-audit

// SOC 2 hub

Preparing for a SOC 2 audit

Readiness, scoping, choosing a CPA firm, the observation period, and bridge letters for a first SOC 2 examination.

Start with a readiness assessment

A readiness assessment compares current practices with the Trust Services Criteria before any formal testing begins. Gaps are normal. It usually produces a control list, a gap list, and a plan to close the gaps. Common gaps in first-time companies include missing access reviews, informal change approval, no written risk assessment, untested backups, and no vendor review process.

Readiness can be done internally, by a consultant, or by a CPA firm. Independence matters here. If the same firm will later issue the report, check its independence rules first. An auditor can't design and run your controls and then give an opinion on them, so firms limit the advice they give to their own audit clients.

Scope the system

The scope is the system that delivers a defined service to customers, made up of its infrastructure, software, people, procedures, and data. Keep it focused. Draw the boundary around what customers rely on, not around the whole company, but make sure it matches what customers think they're buying.

Most Canadian SaaS companies run on a public cloud provider. That provider is a subservice organization. In the usual carve-out method, its controls are excluded from testing and the report explains what the company expects the provider to do, so readers can check the provider's own SOC 2 report. The inclusive method tests the provider's controls too, which is uncommon with large cloud providers.

The report also lists complementary user entity controls. These are things each customer must do, such as managing its own user accounts in the application, for the controls to work as described.

Choose a CPA firm

Only a licensed CPA firm can issue a SOC 2 report. In Canada, public accounting is regulated by province, and only practitioners licensed for that work may sign assurance reports. Ask early. Confirm with the firm whether it will report under AICPA standards or under the Canadian standard CSAE 3000 using the Trust Services Criteria, and check that your main customers will accept the one chosen.

Ask about the team's experience with your type of service, the evidence tools they use, the expected timeline, and the fee for the first and later years. The AICPA has publicly warned about very fast, low-effort SOC engagements, so a quote that seems too quick deserves questions.

Run the observation period

For a Type 2, controls must operate for the full period before testing can confirm them. Weekly, monthly, and quarterly controls need to happen on schedule and leave evidence each time, because the auditor will sample from across the whole period. Keep everything findable. Tickets, screenshots, logs, and sign-offs should sit in one place.

Many companies choose a first period of 3 to 6 months, then move to 12 months. Fieldwork and report drafting typically take several weeks after the period ends.

Bridge letters and continuous coverage

A bridge letter, sometimes called a gap letter, covers the time between the end of the last report period and today. Management signs it, not the auditor. It states that there have been no material changes to the system or controls, or describes any that occurred.

Customers generally accept bridge letters for a few months after a period ends, but the longer the gap, the more likely they are to push for the next report. Planning back-to-back periods avoids the problem.

Keep it running

After the first report, the work becomes routine control operation and annual testing. It gets easier. Assign an owner for each control, review exceptions with management, and update the system description when products or infrastructure change. A missed quarterly access review in month 4 will still show up as an exception when the auditor tests the period in month 12.

Resources

All SOC 2 resources

References

  1. SOC 2: SOC for Service Organizations: Trust Services Criteria, AICPA and CIMA
  2. 2017 Trust Services Criteria (With Revised Points of Focus - 2022), AICPA and CIMA
  3. Reports on Controls at Service Organizations FAQs, Chartered Professional Accountants of British Columbia