The Home Loving Wife

How to Organize SOC 2 Evidence Without Giving a Vendor Standing System Access

Compliance software is intended to facilitate audits. Smaller companies often find themselves stuck in an awkward situation. Before they can implement their SOC 2 controls they must first install, set up and understand an extensive compliance system. It raises a good question. What is the point at which the tool designed to reduce compliance tasks become a new initiative of its own?

CertAssist was born out of that frustration. Its developers had worked on compliance audits and implementations in SOC 2, ISO 27001 and various frameworks. The developers of this software were constantly confronted by platforms with a variety of features and integrations, while the organizations they worked for used spreadsheets to write important audit pieces. SOC 2 software that is simple can be better for smaller enterprises.

Start with the task you need to complete

Remove the terms used in software and the fundamental requirement will become easier to understand. An organization must work through the pertinent Trust Services Criteria, establish proper controls, create policies, collect evidence, monitor progress, and then make the information available for independent audit. Platforms can be used to organize these processes without needing to connect them with every cloud service and identity system the company has in place.

Integrations that are automated are extremely beneficial. Automating the collection of evidence by large corporations in a world that changes constantly can save time. That doesn’t automatically make the same architecture necessary for SOC 2 for startups. Startups that have a small technology environment may choose to gather evidence by hand instead of managing a number of integrations.

The Software and the Audit are two different costs.

The process of budgeting can become confusing when companies treat every compliance expense as one number. SOC 2 includes more than only software. Internal employees are involved in preparing policies, addressing the issues with control, arranging evidence, and collaborating together with the auditor. The independent audit also has its own fee.

When looking into SOC 2 cost, businesses must be aware of one fundamental distinction in terminology. SOC 2 produces a report that is independent and not a formal certification as defined by ISO 27001. But, “certification cost” is often used by businesses searching for pricing data. Whatever term is used in the budget, the software doesn’t replace the independent audit.

The Middle Ground Doesn’t Need to Be an Excel Spreadsheet

Spreadsheets are cheap and easy to use However, they can be a bit awkward when guidelines, controls evidence, ownership and audit communication begin spreading across multiple documents.

The alternative doesn’t need be a enterprise-level platform. CertAssist consolidates the SOC2 controls and lets you edit policies and templates for evidence. It also provides auditors with progress management as well as access to read-only. Multi-factor authentication is mandatory to ensure access to the platform. The advertised launch price of $225 will be followed by regular pricing at $375 per month, or $3,999 annually.

The absence of integration also means A Less Exposed

CertAssist deliberately doesn’t connect to the company’s operational systems. The compliance platform is not provided access to the cloud or the identity environment.

The method is a compromise. It is the obligation of the company to provide proof that could have been collected automatically. If the team is small however, the manual work may be reasonable in exchange for a simpler set-up, lower cost of software and less connections to third party sources.

Purchase Complexity When Complexity Resolves the problem

A growing organization may eventually reach a point at which manual evidence gathering becomes inefficient. The cost of continuous monitoring and integration could be justifiable by the increase in effectiveness.

The purpose of a compliance stack isn’t to be the most technological one on the market. It’s about getting the compliance work done, preserve solid evidence, and enable the independent audit to be manageable. A well-designed software system should make this process easier. If the installation of the compliance tool feels like it’s taking more time than preparing for SOC 2 in itself, then the tool may not be enough.