Whilst many frameworks and certifications, such as ISO 27001, typically expect you to certify your entire organisation or a key branch of your organisation, the scope of a SOC 2 report is limited to the delivery of specific services that involve processing client data.   For example, if your organisation offers a number of services, but only a few of those services have clients requesting a SOC 2 report, you could undertake a SOC 2 audit purely on those few services and exclude the others.  

Your SOC 2 report is aimed at assuring the system that delivers your service, which  consists of everything you do and utilise to support the delivery of the in-scope service(s).   This will include service-specific elements, such as how the service is developed, the back-office functions that support it, how the service is technically secured, etc.  However, the system will also include wider, governance-related aspects that are relevant to your organisation more broadly, such as information about HR processes, how risk is managed, and how communications are managed.  

The whole gap analysis process was very informative for all departments of the business. Our URM consultant was great at explaining the SOC2 audit process and what evidence may be required for each area. As a business, it has really assisted us in our implementation strategy and improving our compliance programme as a whole.
Cyber security services provider
Contact SOC 2 Experts Today

SOC 2 Explained

Published on
27 Mar
2025

URM’s blog answers key questions about SOC 2, including what it is & who it applies to, why it is beneficial, how SOC 2 reports are structured & more.

Read more
"
We would like to pass on our gratitude to our consultant for all his hard work and advice during our 3-year re-certification and assessment against the new Standard. After seven days of auditing, we have two OFIs that the assessors have put forward from the audits. This pays testament to our URM consultant, his hard work, eye for detail and advice given, both during the audits and during all the works beforehand.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.