SOC 2 Frequency: What You Should Know

How often should you get a SOC 2 audit? Learn ideal audit periods for Type 1 & Type 2 reports, why annual audits matter, and how to avoid coverage gaps.

SOC 2 Audit Frequency: Types 1 & 2

When you start the audit process with an auditor, you will need to decide on the first audit period. While your auditor might give you some guidance as to when to start your audit period, it is up to you when the audit period starts and when it ends. In this blog, we will discuss the how frequently a SOC 2 audit should be performed.

For a SOC 2 Type 1 you will choose the earliest date that all the controls are in place. You normally only do a SOC 2 Type 1 report once. You might do it again if you have significant changes and need a report to show customers those changes. From the Type 1 report, you will move to a SOC 2 Type 2 report.  

For a SOC 2 Type 2, you will want to choose a start date when all the controls are in place and you are following them.

With the creation of compliance platforms like Vanta and Secureframe a minimum audit period for a SOC 2 Type 2 is usually 3 months. Clients usually do a shortened period of 3-6 months the first time and then move to a 12-month period after that.

That schedule will get you a SOC 2 Type 2 report sooner to show prospective clients and close deals. From there you usually move to a 12-month audit period to show them that you continue to stay compliant.

READ MORE: What is the difference between SOC 2 Type 1 and SOC 2 Type 2

A SOC 2 report or attestation doesn’t really expire but, your customers will be looking for a new report annually. Often you will be asked for a bridge letter to cover the period since the last audit report.

READ MORE: What is a SOC 2 Bridge Letter?

One of the most important things to know is that once you start the SOC 2 audit process, you should always be under an audit period or window.

Once your initial audit period is over and you have received your report, it is important to stay on top of your controls and begin preparing for your next audit period in accordance with SOC 2 frequency. Any gaps between reporting periods could result in having to explain to your clients what happened, which can be avoided by consistent and timely audits.

Related articles

Feb 20, 2023

Why SOC 2 Auditing Is Essential for SaaS Businesses

Why SOC 2 Auditing Is Essential for SaaS Businesses

SOC 2

SaaS companies are becoming more and more popular, but not all of them are able to stay compliant. The truth is that if you run a SaaS business, there's no way around it: you have to be SOC 2 certified.

What are the requirements for SaaS?

SaaS is a model of software distribution that provides access to applications over the internet. SaaS is an acronym for Software as a Service, but it's also used to refer to the business model itself.

The acronym has been around since at least 1999 when it was defined as "the delivery of software applications via the Internet." However, the idea behind it dates back much further: The first commercial use of SaaS was in 1979 with CompuServe's CBIS system (Computer Based Information Services), which allowed users access to databases and email through their computers' modems. In recent years, we've seen this model grow enormously thanks largely due to its low cost compared with traditional on-premises solutions like Oracle or SAP--and because customers don't need expensive hardware or software licenses from vendors like Microsoft or Adobe anymore!

Is SOC 2 mandatory for SaaS?

SOC 2 is not mandatory for SaaS. However, SOC 2 is a standard for service providers and has been adopted by many companies as a good practice. There are several benefits of SOC 2 compliance:

  • It increases trust in your brand among customers and partners
  • It gives you more credibility in the market (especially when dealing with other businesses)
  • It allows you to demonstrate compliance with data protection laws

Why SOC 2 Auditing Is Essential for SaaS Businesses

A SOC 2 audit is a requirement for all SaaS companies. The reason why? Because it's the only way to prove that you are using security controls that meet the standards set by the industry and your customers.

In order to be SOC 2 compliant, a third-party auditor must verify that you have implemented specific security controls in accordance with an accepted framework such as NIST or ISO/IEC 27002.

By completing an annual SOC 2 audit and issuing an attestation report, you can demonstrate that your organization has met these standards of protection for its customers' data (and their own).

How to stay compliant as a SaaS business

A SOC 2 audit is an ongoing process. It's not a one-time thing, and it's not just about security. SOC 2 compliance means you're staying compliant with all five of these criteria:

  • Security: You have appropriate physical, technical, and administrative controls in place to ensure the confidentiality, integrity, and availability of your data;
  • Privacy: You protect the privacy rights of individuals whose personal information is involved in processing;
  • Integrity: You follow policies for preventing unauthorized modification or destruction of information; * Availability: Your system must be available 99% of the time with no more than 5 minutes of downtime per month; * Compliance Reporting (if applicable): Your organization must provide evidence that it has met required standards through regular self assessments conducted by qualified personnel

READ MORE: What is the difference between SOC 2 Type 1 and SOC 2 Type 2

Why SaaS Companies Choose SOC 2 Compliance

SaaS companies can choose to be audited for SOC 2 compliance, which is why it's important to understand what this means. The SSAE 16 report is a document that verifies the security of your company and its data. It's one of the main reasons why many businesses choose to undergo an audit: because it lets them show clients that they're doing everything they can to protect their information from hackers and other threats. This can help you attract new clients who want their data handled safely--and even keep current ones from jumping ship!

SOC 2 for SaaS

If you're a SaaS company, SOC 2 compliance is essential. You must be able to prove the security of your systems and data to customers who demand it--and if they don't get what they want, they might take their business elsewhere.

Additionally, being SOC 2 compliant gives your business a boost in terms of its reputation and reliability in the eyes of potential clients. If you want to keep growing as an organization and earning new clients every year (or month), then becoming SOC 2 audited should be at the top of your agenda for 2019!

If you run a SaaS company, you must consider SOC 2 compliance

If you run a SaaS business, then SOC 2 compliance is essential. There are two main reasons for this:

  • SOC 2 compliance is not mandatory, but it's recommended by many in the industry. If you want to build trust with customers and partners, then SOC 2 compliance can help. It provides them with proof that your company takes security seriously.
  • In addition to this, many banks require that their vendors have undergone an independent audit before they do business with them--and if your software handles sensitive customer data like credit card information or social security numbers (SSNs), then banks may require an audit as part of their due diligence process before signing contracts with these vendors.

SaaS is a growing industry, and it's important for companies in this space to be SOC 2 compliant. If you run a SaaS business, then you should consider getting your company audited by an independent third party that can verify that your data security practices are up-to-date and working properly. An audit will also help ensure that your company remains compliant with regulations such as GDPR or HIPAA.

Aug 21, 2023

What is a SOC 2 Bridge Letter?

How do you provide assurance to your employees, stakeholders and potential customers and partners in between compliance audit review periods?

Reporting
SOC 2

What is a SOC 2 Bridge Letter?

How do you assure your employees, stakeholders, and customers of your SaaS company that their information is private and secure between compliance audit review periods?

Provide them a SOC 2 Bridge Letter.

A SOC 2 bridge letter is issued after your company or organization's SOC 2 report audit period has ended. It bridges the gap between the end of your last SOC 2 report audit and when you're ready to conduct your next audit, which is why it's also referred to as a 'gap letter.'

Usually, SOC 2 reports cover a user entity for 6 months to a year, but if your company follows a calendar year, then your report’s validity may leave you uncovered.

Does a SOC 2 bridge letter provide any coverage? In its most simple form, the answer would be:  No.

Bridge letters aren’t meant to take the place of another SOC 2 report, but to provide coverage of your company and trustworthiness to your customers and clients.

What Does a SOC 2 Bridge Letter Look Like & What is Included?

What a SOC 2 bridge letter should include:

  • Significant changes to any systems or controls since the audit

OR

  • A statement that the organization or company is unaware of any material changes from the latest SOC 2 report to its expiration.


What a SOC 2 bridge letter should NOT Include:

Remember, a bridge letter is sent to cover the gap between SOC 2 audit reports. It isn’t meant to take the place of the actual audit, therefore it shouldn’t include specific details like

  • Test procedures
  • Test results
  • System descriptions

Here's an example of a SOC 2 Bridge letter template Johanson Group provides to our clients:

Who Writes and Issues a SOC 2 Bridge Letter?

Management of the company that received the previous SOC 2 report completes and sends the SOC 2 Bridge Letter to its stakeholders (not the auditor).

The letter intends to assure all intended recipients that there have been no significant changes to your SaaS company's controls between audit renewal periods. If there have been material changes, the SOC 2 bridge letter is where you would explain changes to your controls — if any— and assure your customers or clients how they wouldn't affect the results of your SOC 2 report.

The CPA firm conducting the SOC 2 audit is not involved in the writing or disbursement of a SOC 2 bridge letter. Why?

The entire purpose of the SOC 2 bridge letter is to attest that client, stakeholder, and employee privacy and security are still in compliance. If something were to change with the company's security services after a SOC 2 is complete, the CPA firm that conducted the audit could not speak to the passing of any new changes after the audit expires.

Why are Bridge Letters Important?

As you can see, bridge letters are an essential part of your SOC 2 compliance program. The written assurance to your customers and stakeholders that you are still in compliance after your SOC 2 report helps bring confidence and peace of mind that their information is secure and private and trust service commitments and requirements are being met.

LEARN MORE: Why Saas Start-Ups Should Prioritize SOC 2 Compliance

As we have seen, SOC 2 bridge letters are critical to your SOC 2 compliance. They help you to demonstrate that your controls are appropriately designed and operating effectively and can be relied upon by all stakeholders.

We encourage all organizations who use IT services to consider applying for a SOC 2 report and getting the letter as soon as possible, if they haven’t already done so.Remember, a bridge letter is a temporary coverage for your trust services compliance. Schedule your subsequent SOC 2 audit examination today with Johanson Group, your trusted CPA for SaaS organizations.