Skip to content

SOC 2 — Audit and Trust Services Criteria Compliance

A two-day training on preparing for a SOC 2 audit: the five Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy), the difference between a Type I and Type II report, and building an audit-ready control environment.

SOC 2 as a gateway to the enterprise market

For a SaaS or cloud provider, a SOC 2 report has stopped being a differentiator and become an entry condition — enterprise clients increasingly demand it before entrusting their data. The training starts by explaining exactly what SOC 2 is, who expects it, and how to scope the report to the nature of the service, before the organization invests in a costly audit process.

From control design to evidence of effectiveness

The key difference between a Type I and Type II report is the difference between “controls are designed” and “controls operated throughout the observation period.” The workshop walks through building a control environment mapped to the five TSC and through gathering and maintaining the evidence the auditor will require during the observation period.

Synergy with existing implementations

Organizations that have already implemented ISO 27001 don’t start from scratch — many controls can be reused. The final module of the training shows how to map existing security implementations onto SOC 2 requirements and build a realistic timeline to the audit, avoiding duplicated work.

Benefits

  • Understand the structure of SOC 2 and the five Trust Services Criteria (TSC)
  • Distinguish between SOC 2 Type I and Type II reports and select the right one for the organization
  • Design and document controls that satisfy the security criterion (Common Criteria)
  • Prepare the organization for the audit: gathering evidence, the observation period, and working with the auditor

Who is this training for?

Compliance officers and security managers at SaaS and cloud service providers
Teams responsible for preparing the organization for a SOC 2 audit
CISOs and IT leaders building a control environment to meet enterprise client requirements
Consultants and internal auditors supporting compliance processes

Prerequisites

  • Basic familiarity with IT processes and information security management

Training program

01

Introduction to SOC 2 and the Trust Services Criteria

  • SOC 2 as an AICPA standard — its purpose and the report's audience
  • The five TSC: security, availability, processing integrity, confidentiality, privacy
  • The security criterion (Common Criteria) as the mandatory foundation of every report
  • Scoping: which criteria to include depending on the nature of the service
02

Type I vs Type II reports

  • Type I — an assessment of control design at a point in time
  • Type II — an assessment of operating effectiveness over an observation period (usually 3-12 months)
  • Which report to start with and how to plan the path to Type II
  • Enterprise client expectations and the report's role in the procurement process
03

Building the control environment

  • Mapping controls to the TSC and identifying gaps
  • Access controls, change management, monitoring, and incident response
  • Managing vendor and subcontractor risk (subservice organizations)
  • Policy and procedure documentation required by the auditor
04

Audit preparation and process

  • Gathering evidence and maintaining it throughout the observation period
  • Working with an independent auditor (CPA) and the scope of their examination
  • Common exceptions in a report and how to reduce them
  • Maintaining compliance between audits and preparing for the next cycle

Delivery Methods

Online

  • Convenience of participating from anywhere
  • Interactive live sessions with trainer
  • Materials available for 30 days
  • No travel costs

On-site

  • Direct contact with trainer and group
  • Intensive hands-on workshops
  • Networking with other participants
  • Full focus on learning

Frequently asked questions

What is SOC 2, and who needs it?

SOC 2 is a reporting standard developed by the AICPA (American Institute of Certified Public Accountants) that assesses a service organization's controls against five Trust Services Criteria. It is a de facto requirement for SaaS and cloud providers serving enterprise clients, especially in the US market — clients demand a SOC 2 report before entrusting their data. In the training we determine whether and what kind of SOC 2 report your organization needs.

What is the difference between SOC 2 Type I and Type II?

A Type I report assesses whether controls are suitably designed at a point in time, whereas Type II assesses whether controls actually operated effectively throughout an observation period (usually 3 to 12 months). Type II carries far more value for clients because it confirms operating effectiveness, not just design. In the training we help you decide which to start with.

Which of the five TSC do we need to include?

The security criterion (Common Criteria) is mandatory in every SOC 2 report. The other four — availability, processing integrity, confidentiality, and privacy — are optional and included depending on the nature of the service and client expectations. In the workshop we help you select the right scope so the report is credible without unnecessarily broadening the range of controls.

How long does SOC 2 audit preparation take?

It depends on the maturity of your existing control environment, but a typical path to a Type II report spans several months: designing and implementing missing controls, followed by an observation period (usually 3-12 months) during which the auditor assesses their effectiveness. In the training we help build a realistic timeline to the audit matched to the organization's starting point.

How does SOC 2 differ from ISO 27001?

Both standards concern information security but differ in approach: ISO 27001 is an internationally recognized certification of an information security management system (ISMS), whereas SOC 2 is a report from an independent assessment of controls, particularly expected in the US market. Many organizations pursue both. In the training we cover how to leverage an existing ISO 27001 implementation to accelerate SOC 2 preparation.

Przemysław Wojdak
Przemysław Wojdak Opiekun szkolenia

Request a quote

Funding Options

Check funding options for your company

Up to 80%

Development Services Database

Up to 80% funding for SMEs from EU funds

Check availability
Up to 100%

National Training Fund

Up to 100% funding for employers

Learn more

Trusted by

We train teams at Poland's largest companies

ING Bank - EITT client
mBank - EITT client
PKO Bank Polski - EITT client
PZU - EITT client
Allianz - EITT client
T-Mobile - EITT client
KGHM - EITT client
PGE - EITT client
IKEA - EITT client
InPost - EITT client
Leroy Merlin - EITT client
ZUS - EITT client

Interested in this training?

Contact us - we'll prepare an offer tailored to your organization's needs.

500+ experts
2500+ trainings available
ISO 9001 quality certified
Request Training
Call us +48 22 487 84 90