Find out why Strike Graph is the right choice for your organization. What can you expect?
Find out why Strike Graph is the right choice for your organization. What can you expect?
You just got your final SOC 2 report back from the auditor. You sent the report off to the customer who wanted it and a big deal has just been signed (congrats!). You also breathe a sigh of relief because you are fully compliant with specific contract terms. You are official!
But there is more to do!
A SOC 2 report is intended to be confidential, despite the fact that you may see a handful of reports posted online. Some prospective customers may want to see your report, and this is appropriate. Some organizations will have prospects sign an NDA prior to sharing their SOC 2 report. Whether or not to ask your customers to sign an NDA is your choice, but know that the report should not be widely distributed.
You should also limit the number of employees who can access the report internally. Just as you don’t want to share it publicly, you want to treat it as confidential within your organization. Only provide access to those employees who need to know, or need access to perform their job. For example, sales executives may need access so they can efficiently navigate your customers’ vendor onboarding processes.
Did you know you can brag about receiving your SOC 2? Get ready to brag by following these steps:
Register and download the Official Logo from the AICPA. Note that there are very specific Guidelines for using the Logo. The Terms and Conditions are short, so make sure you read the SOC 2 sections. Do not alter the logo in any manner except for size. You can use the logo almost anywhere as long as it is hyperlinked to www.aicpa.org/soc4so.
You just spent considerable time and effort not only establishing (or refining) a cyber security practice but also traversing the audit process. A SOC 2 is not just a trophy you dust off right before the auditor returns next year. You want to maintain the good compliance habits you’ve developed year-round.
Here are a few tips for operationalizing your hard work:
The security landscape is ever changing. Sign up for our newsletter to make sure you stay abreast of the latest regulations and requirements.
Strike Graph offers an easy, flexible security compliance solution that scales efficiently with your business needs — from SOC 2 to ISO 27001 to GDPR and beyond.
© 2024 Strike Graph, Inc. All Rights Reserved • Privacy Policy • Terms of Service
Find out why Strike Graph is the right choice for your organization. What can you expect?
Find out why Strike Graph is the right choice for your organization. What can you expect?