SOC 2 Compliance: What It Is and How It Works
As an authorized CMMC Third-Party Assessment Organization (C3PAO) and ISO 27001, ISO 20000, and ISO 9001-certified organization, we hold our operations to the same standards we help our clients meet.
SOC 2 (System and Organization Controls 2) is an auditing standard developed by the American Institute of Certified Public Accountants (AICPA). In short, it evaluates how well a service organization protects customer data based on five Trust Services Criteria:
- Security - protection against unauthorized access (required in every SOC 2).
- Availability - systems are available for operation and use as agreed.
- Processing Integrity - processing is complete, accurate, and timely.
- Confidentiality - information designated as confidential is protected.
- Privacy - personal information is handled in line with commitments.
Security is mandatory; the other four are included based on what's relevant to the services being provided. The result is not a pass/fail certificate but instead a report that describes an organization's controls and whether they operate effectively.
How SOC 2 Works
A SOC 2 examination is performed by an independent, licensed CPA firm. There are two types of reports:
- Type I assesses whether controls are sufficiently designed at a single point in time.
- Type II goes further, testing whether those controls operated effectively over a period of time, typically 3 to 12 months. Type II carries more weight because it proves operational consistency.
During the examination, the auditor reviews policies, interviews staff, and collects evidence that each control is working as described. The final report is confidential and is usually shared with customers and prospects under a non-disclosure agreement.
How SOC 2 is Maintained
SOC 2 isn't a one-and-done exercise. A Type II report covers a defined window, so organizations renew their examination on a recurring basis, most commonly once a year, to demonstrate continuous coverage.
Between audits, maintaining SOC 2 means running the controls every day: monitoring systems, managing access, tracking changes, collecting evidence, remediating issues, and reviewing policies on a regular cadence. In practice, SOC 2 is less a document than an operating discipline.
How We Use SOC 2 at MNS Group
At MNS Group, SOC 2 works two ways. First, we hold our own SOC 2 report, which means the security controls we rely on to protect client information are examined by an independent third party, not just asserted by us.
Second, we help clients make sense of SOC 2 as part of a broader compliance picture, mapping it alongside frameworks like NIST SP 800-171, CMMC, and the CIS Controls so that overlapping requirements are met efficiently rather than duplicated.
For organizations evaluating a partner, a current SOC 2 report is one of the fastest ways to move from "trust us" to "here's the evidence."
Want to Learn More?
Our ISO certificates and other documentation are available on request through the MNS Group Trust Center.
