SOC 2 Type II
A SOC 2 report is issued by an independent CPA firm after it examines a service organization’s controls against the AICPA Trust Services Criteria.
A Type I report describes controls at a single point in time. A Type II report tests whether those controls operated effectively across a period of time, called the observation window. The auditor samples evidence from the whole window, and the report states the dates it covers. A control that held in the first month and failed in the third appears in the report as an exception.
The first report is the initial issuance of a rolling twelve-month report. After it, each report covers the twelve months that follow the previous one.
FedRAMP 20x Class C
FedRAMP 20x assesses a cloud service against Key Security Indicators. Each indicator is a security outcome that the provider demonstrates with evidence, instead of a control described in a narrative document.
The Class C certification we are pursuing covers controlled unclassified information, measured against the Class C indicator set. Controlled unclassified information is government information that requires safeguarding but is not classified.
The indicators are validated continuously by automation. FedRAMP calls this persistent validation.
The authorization boundary
The authorization boundary covers stateless inference. Data arrives, gets processed, and nothing persists.