Harmonization with the US regulatory and normative framework is increasingly becoming a need for European companies that must be aware of the obligations and expectations of the US market. In this sense, Boost has many years of experience in complying with a number of US regulations and standards and knows the expectations of US clients.
Some of the regulations that the Boost team does well are:
- SOC2
- NIST
- HIPAA
- HITRUST
- CCPA
EXAMPLE OF THE IMPLEMENTATION OF SOC2 REQUIREMENTS AND ATTESTATION (EACH REGULATION DIFFERS IN THE DETAILS OF IMPLEMENTATION)
1) Selecting the SOC 2 Trust Services Criteria and defining the scope
- Define business processes, services, systems, applications, locations, and teams that fall within the scope of SOC 2 reports.
- Determine which Trust Services Criteria (TSC) will apply:
- Security (mandatory criterion)
- Availability
- Processing Integrity
- Confidentiality
- Privacy
- Identify regulatory, contractual, and customer requirements that affect the SOC 2 scope.
- Define system boundaries and key vendors and service providers involved in service delivery.
2) Defining the project plan and project team
- Define the project plan (deadlines, goals, responsibilities, risks, resources and expected results).
- Appoint persons responsible for information security, compliance and coordination of the SOC 2 project.
- Ensure management support and involvement throughout the process.
- Educate the project team on SOC 2 requirements and expectations of an independent auditor.
- Make an assessment of the current compliance status (SOC 2 GAP analysis).
3) Risk assessment and definition of controls
- Identify and assess the risks associated with service delivery and data protection.
- Analyze existing safety, operational, and management controls.
- Define additional controls required to meet the SOC 2 criteria.
- Establish processes to manage risks, incidents, change, and business continuity.
- Define controls for access management, infrastructure security, activity monitoring, and vendor management.
4) Preparation and establishment of documentation
- Create or update policies, procedures, and guidelines related to SOC 2 requirements.
- Document risk, access, incident, change, security monitoring, and business continuity management processes.
- Define the roles, responsibilities and powers of all relevant participants.
- Ensure the management of documentation and records of performed controls.
- Put in place mechanisms to collect evidence of the implementation of controls.
5) Implementation of controls and employee education
- Implement defined technical and organizational controls in your daily business.
- Conduct training of employees on information security, data protection and internal procedures.
- Establish processes to continuously implement and record controls.
- Ensure monitoring of the effectiveness of controls and timely elimination of identified deficiencies.
- Conduct tests and exercises as needed (incident response, backup and disaster recovery tests, etc.).
6) Evidence gathering and operational period
- Gather evidence of the implementation and functioning of controls.
- Record records of accesses, changes, security events, trainings, and other relevant activities.
- Ensure that controls are carried out continuously during the observed period.
- For SOC 2 Type II, it is necessary to prove the operational effectiveness of controls over a certain period of time (usually 3-12 months).
7) Internal review and preparation for audit
- Conduct an internal SOC 2 audit readiness assessment.
- Check the compliance of documentation, processes and records.
- Identify any deficiencies and carry out corrective actions.
- Conduct an assessment of the management on the state of the control and risk management system.
- Confirm the organization's readiness for an independent SOC 2 audit.
Applying for SOC 2 Attestation
- Selection of an independent audit firm authorized to issue SOC 2 reports.
- Define the scope and type of report (SOC 2 Type I or SOC 2 Type II).
- Agreeing on the audit implementation plan and the necessary documentation.
- Submission of documentation and evidence to the audit team.
SOC 2 attestation procedure (by an independent audit firm)
SOC 2 Type I
- It evaluates whether the controls are properly designed and implemented on a specific date.
- The auditor checks policies, procedures, processes and technical controls.
- The organization's responsibilities and compliance with the selected Trust Services Criteria are analyzed.
- The result is a SOC 2 Type I report that shows the status of controls on a specific date.
SOC 2 Type II
- It assesses whether the controls have functioned effectively over a period of time.
- The auditor reviews evidence of the day-to-day implementation of controls.
- Interviews, review of documentation and testing of samples are conducted.
- Incidents, changes, system accesses, monitoring, and activity logs are analyzed.
- The result is a SOC 2 Type II report that confirms the effectiveness of controls during the observed period.
Continuous Compliance
- Regularly carry out risk assessments and update controls.
- Stay abreast of regulatory, business and technological changes.
- Conduct internal audits, training, and employee awareness activities.
- Continuously collect evidence of the implementation of controls.
- Prepare for future SOC 2 audits and report updates as per customer and market requirements.
Timeframe, resources and costs (indicative)
- Smaller organizations: 3-6 months to prepare a SOC 2 Type I report.
- Organizations targeting SOC 2 Type II typically require 6-12+ months, including an operational period to demonstrate the effectiveness of the controls.
- Required resources: management, IT team, security team, process owners, HR, legal department, external consultants and audit company.
- Costs depend on the size of the organization, the complexity of the system, the number of locations, the number of criteria included in the scope, and the audit firm chosen.
The most common mistakes and what to avoid
- Focusing solely on documentation without actually implementing controls.
- Insufficient collection of evidence on the day-to-day functioning of controls.
- Incomplete definition of the scope of systems and services.
- Lack of support from management and unclear responsibilities.
- Relying on manual processes that are not carried out consistently.
- Inadequate management of suppliers and external service providers.
- Lack of continuous monitoring of security events, changes and approaches.
- Starting a SOC 2 Type II audit without enough time to prove the effectiveness of the controls.
Note
Unlike ISO certification and NIS2 regulatory compliance, SOC 2 is an independent attestation issued by a certified audit company. The result is not a certificate, but a SOC 2 report (Type I or Type II) that an organization uses as proof to its customers, partners, and other stakeholders that it applies appropriate safety and management controls.
It is recommended to automate SOC2 compliance. If we talk about SOC 2 compliance automation, the following platforms are most used today:
Tier 1 (most commonly in SaaS and tech companies)
- It boasts
- Drata
- Secureframe
- Spritz
- Thoropass (bivsi Time)
These platforms automate:
- Evidence Collection (Evidence Collection)
- integrations with Microsoft 365, Google Workspace, AWS, Azure, GitHub, Jira, etc.
- Managing policies and procedures.
- Continuous monitoring of the control
- preparation for SOC 2, ISO 27001, HIPAA, GDPR and other frameworks
Indicative annual costs
For a company of 20-100 employees:
Platform | Typical annual cost |
Sprinto | 6.000-15.000 USD |
Secureframe | 7.500-20.000 USD |
Drata | 10.000-25.000 USD |
Vanta | 10.000-30.000 USD |
Thoropass | 15.000-35.000 USD |
Hyperproof | 20.000+ USD |
AuditBoard / Optro | 25.000-100.000+ USD |
Approximate market value, although the final price depends on the number of employees, framework (SOC 2, ISO 27001, HIPAA...), number of cloud systems and the desired level of support
The cost of the entire SOC 2 project
It is important to distinguish:
- Platform
- 000-30.000 USD/god
- Audit
- SOC 2 Type I: 8.000-20.000 USD
- SOC 2 Type II: 15.000-40.000 USD
- Consultants (if applicable)
- 000-50.000+ USD
For a typical SaaS company of 30-100 employees running SOC 2 Type II for the first time:
- Platform (Span/Right): $10,000-20,000
- Audit: 15.000-25.000 USD
- Consultant: $10,000-$30,000
Total: $35,000-$75,000 for the first year, after which the maintenance cost usually drops to around $20,000-$40,000 per year
BOOST d.o.o.
- Oreškovićeva 13
10 020 Zagreb, Croatia