Loading template…
From a gap assessment to a Type II report: policies, controls, a Type I audit and the observation window between them.
Free account — your copy is a fresh private board you own.
The path to a SOC 2 Type II report for a small software company: a gap assessment, written policies, the controls themselves, a Type I audit, and the observation window a Type II covers. Share the link with the customers asking for the report, and they can see how far along you are without another call.