SOC 2 preparation for European healthtech
Asteron prepares European healthtech and SaaS companies for an independent SOC 2 examination. We define the system and criteria, build workable controls, establish reliable evidence and prepare management for the CPA firm’s assessment. The service is designed for companies in the Netherlands, Germany and across Europe that sell to US hospitals, insurers, life-science organisations or enterprise customers asking for assurance over security and operational controls.
- Type I or Type II route defined
- Scope and criteria agreed
- Controls operating with evidence
- Independent CPA handoff prepared
What is SOC 2?
SOC 2® is an independent examination of a service organisation's description of its system and the controls relevant to security, availability, processing integrity, confidentiality or privacy.
The examination follows standards established by the American Institute of Certified Public Accountants. The final report is issued by an independent CPA firm and helps customers assess risks associated with using the service.
SOC 2 is not a product certification, security score or legal requirement. It is primarily a customer-assurance mechanism and is frequently requested during enterprise procurement, vendor due diligence and security reviews in the United States.
Who typically needs it?
A company should pursue SOC 2 when customers or its go-to-market strategy justify the cost and operating discipline—not simply because competitors display a badge.
Type I or Type II?
A Type I report is not automatically required before Type II. The appropriate route depends on customer expectations, control maturity and the CPA firm's engagement plan.
The observation period for Type II is agreed with the CPA firm. Preparation, control operation and examination normally make the complete first Type II programme approximately six to nine months, but timing depends on readiness and the selected period.
Trust Services Categories
Security is the foundation of every SOC 2 examination. Other categories should be added only when they reflect actual service commitments and customer expectations.
Adding every category does not automatically create a better report. It expands the assertions, controls, evidence and audit effort. Scope should follow the product and commitments, not marketing ambition.
What is inside the SOC 2 system?
The system description normally covers:
- – Services and principal product functionality
- – Infrastructure, software and data
- – People, teams and responsibilities
- – Procedures and automated processes
- – System boundaries and excluded components
- – Cloud and other subservice organisations
- – Customer responsibilities and complementary user-entity controls
- – Security incidents and significant system changes
An unclear system boundary causes duplicated controls, missing suppliers and unreliable evidence. Scope must be settled before control design is finalised.
What audit-ready controls look like
Governance and risk
Management assigns accountability, approves policies, evaluates risk, reviews performance and tracks material issues to closure.
Access and people
Joiner, mover and leaver processes, privileged access, authentication, access reviews, screening, confidentiality and security training operate consistently.
Product and change
Engineering changes are authorised, reviewed, tested and traceable. Production access, deployment, vulnerability remediation and secure-development responsibilities are controlled.
Operations and resilience
Monitoring, backups, recovery, capacity, incidents, continuity and availability commitments are supported by actual operating evidence.
Suppliers and customer assurance
Critical providers are assessed before use and reviewed thereafter. Contracts, subservice organisations, customer responsibilities and relevant assurance reports are maintained.
SOC 2 and ISO 27001
Existing ISO 27001 governance, risks, policies, suppliers, incidents and internal reviews can be reused. However, the SOC 2 system description, management assertion, criteria mapping and period-specific evidence still need separate preparation.
How Asteron prepares the organisation
Buyer and route assessment
Confirm why the report is needed and choose Type I or Type II based on customer expectations and control maturity.
Scope and criteria definition
Define the service, system boundary, locations, suppliers and Trust Services Categories that will be included in the examination.
Readiness assessment
Map controls and evidence against the proposed examination scope and identify material gaps before preparation begins.
Control implementation
Close material gaps and establish sustainable owners, procedures and automation so that controls can operate over time.
Evidence period
Operate controls, collect time-stamped evidence and correct exceptions promptly during the observation period.
CPA readiness
Prepare the system description, management inputs and evidence pack for the independent examination.
Deliverables
Scope and control design
- – SOC 2 route and scope recommendation
- – System-boundary and subservice-organisation map
- – Trust Services Category rationale
- – Risk and control matrix
- – Control-owner and evidence responsibilities
- – Prioritised remediation plan
Evidence and CPA readiness
- – Evidence calendar and repository structure
- – System-description preparation
- – Control-operation and exception reviews
- – Management readiness pack
- – CPA request-list preparation
- – Independent examination handoff
SOC 2 preparation pricing
Covers SOC 2 preparation for one principal organisation, one defined service and an agreed Type I or Type II route.
Final scope depends on company size, system complexity, selected Trust Services Categories, number of locations and subservice organisations, existing control maturity and the required evidence period.
For a first Type II report, the complete programme normally requires six to nine months. The CPA firm's fees are excluded.
- – 40% at signing
- – 40% after delivery of the scope and readiness baseline
- – 20% after the contracted preparation outcome
Prices exclude VAT where applicable.
Independent CPA examination
Asteron designs and prepares the control environment but does not issue the SOC 2 report.
The examination must be performed by an appropriately qualified independent CPA firm. Keeping preparation and examination separate protects the credibility and independence of the report.
The client selects, contracts and pays the CPA firm directly. External costs may include:
- – CPA examination and readiness procedures requested by the CPA
- – Penetration testing
- – Technical remediation
- – Specialist privacy or legal advice
- – Additional systems, locations or criteria
- – Continued control operation beyond the agreed project
Responsibilities
Asteron
- – Define the proposed route, system and criteria
- – Translate the scope into sustainable controls
- – Prepare the evidence model and system description
- – Review control operation and exceptions
- – Coordinate the agreed CPA handoff
Your organisation
- – Approve the scope and service commitments
- – Assign control owners and operate controls
- – Provide complete and accurate evidence
- – Correct identified gaps and exceptions
- – Make the management assertion
- – Contract and communicate with the CPA firm
Frequently asked questions
What is a SOC 2 report?
A SOC 2 report is an independent examination of a service organisation’s description of its system and the controls relevant to security, availability, processing integrity, confidentiality or privacy. It is issued by an independent CPA firm under standards established by the AICPA and helps customers assess risks associated with using the service.
Is SOC 2 a certification?
No. SOC 2 is an examination and an assurance report, not a certification. There is no certificate or badge issued by a certification body. The output is a report signed by the independent practitioner.
What is the difference between Type I and Type II?
Type I assesses the design and implementation of controls at a specified date. Type II assesses the design and operating effectiveness of controls throughout an observation period agreed with the CPA firm.
Is Security mandatory?
Yes. Security is the foundation of every SOC 2 examination. Availability, processing integrity, confidentiality and privacy are added only when they reflect actual service commitments and customer expectations.
Should we include all five Trust Services Categories?
No. Adding every category does not automatically create a better report. It expands the assertions, controls, evidence and audit effort. Scope should follow the product, its commitments and customer expectations.
Does ISO 27001 replace SOC 2?
No. ISO 27001 certifies an information-security management system, while SOC 2 produces an assurance report about a defined service organisation system. Existing ISO 27001 governance, controls and evidence can be reused, but the SOC 2 system description, management assertion and period-specific evidence still need separate preparation.
How long does a first Type II programme take?
Preparation, control operation and examination normally make the complete first Type II programme approximately six to nine months. Timing depends on readiness, the selected observation period and the CPA firm’s engagement plan.
Can a European company obtain a SOC 2 report?
Yes. SOC 2 is regularly used by European companies serving US customers. The examination must be performed by an appropriately qualified independent CPA firm; the service organisation can be based anywhere.
Who performs the examination?
An independent CPA firm performs the examination and issues the SOC 2 report. Asteron prepares the organisation but does not issue the report; combining preparation and examination would compromise the practitioner’s independence.
Who can receive or read the report?
SOC 2 reports are restricted-use reports intended for management, customers and other parties with sufficient understanding of the service and controls. Distribution is typically governed by non-disclosure arrangements.
Can SOC 2 replace customer questionnaires?
A credible report can reduce repeated evidence requests, but it will not replace every review. Some customers still require specific questionnaires, additional evidence or subject-matter-specific assurance.
How much does SOC 2 preparation cost?
A scoped SOC 2 preparation engagement starts from €12,900. Final scope depends on company size, system complexity, selected Trust Services Categories, number of locations and subservice organisations, existing control maturity and the required evidence period. The CPA firm’s fees are excluded.
Official references
- – AICPA — SOC for Service Organisations overview
- – AICPA — SOC 2 guidance for service organisations
- – AICPA — Trust Services Criteria
- – AICPA — Description Criteria for a service organisation's SOC 2 system description
Last reviewed: July 2026
SOC and SOC 2 are registered trademarks of the AICPA. Asteron is not a CPA firm and is not endorsed by or partnered with the AICPA.
Related services and frameworks
Build evidence that enterprise customers can trust
Define a defensible SOC 2 scope, operate the controls consistently and enter the independent CPA examination with organised evidence and clear ownership.
