AsteronAsteron

    SOC 2 preparation for European healthtech

    Asteron prepares European healthtech and SaaS companies for an independent SOC 2 examination. We define the system and criteria, build workable controls, establish reliable evidence and prepare management for the CPA firm’s assessment. The service is designed for companies in the Netherlands, Germany and across Europe that sell to US hospitals, insurers, life-science organisations or enterprise customers asking for assurance over security and operational controls.

    View SOC 2 pricing
    • Type I or Type II route defined
    • Scope and criteria agreed
    • Controls operating with evidence
    • Independent CPA handoff prepared

    What is SOC 2?

    SOC 2® is an independent examination of a service organisation's description of its system and the controls relevant to security, availability, processing integrity, confidentiality or privacy.

    The examination follows standards established by the American Institute of Certified Public Accountants. The final report is issued by an independent CPA firm and helps customers assess risks associated with using the service.

    SOC 2 is not a product certification, security score or legal requirement. It is primarily a customer-assurance mechanism and is frequently requested during enterprise procurement, vendor due diligence and security reviews in the United States.

    Who typically needs it?

    European healthtech selling to US hospitals
    Procurement teams want independent assurance over the service and its controls.
    SaaS processing sensitive customer data
    Buyers need more evidence than policies and questionnaires provide.
    A company moving upmarket
    Larger customers expect repeatable access, change, incident and supplier controls.
    Existing ISO 27001 organisation
    SOC 2 may provide the US-oriented assurance report requested by customers.
    A company repeatedly answering security questionnaires
    One credible report can reduce repeated evidence requests, although it will not replace every review.

    A company should pursue SOC 2 when customers or its go-to-market strategy justify the cost and operating discipline—not simply because competitors display a badge.

    Type I or Type II?

    What is assessed
    Control design and implementation at a specified date
    Control design and operating effectiveness throughout an observation period
    Best suited to
    A company establishing its first formal control environment or facing an immediate buyer request
    A company that needs stronger assurance that controls operated consistently
    Evidence required
    Evidence that controls are suitably designed and in place
    Repeated, time-stamped evidence covering the complete review period
    Commercial strength
    Useful first assurance milestone
    More commonly expected by mature enterprise buyers

    A Type I report is not automatically required before Type II. The appropriate route depends on customer expectations, control maturity and the CPA firm's engagement plan.

    The observation period for Type II is agreed with the CPA firm. Preparation, control operation and examination normally make the complete first Type II programme approximately six to nine months, but timing depends on readiness and the selected period.

    Trust Services Categories

    Security is the foundation of every SOC 2 examination. Other categories should be added only when they reflect actual service commitments and customer expectations.

    Security
    Protection against unauthorised access, disclosure or system damage; included in every SOC 2 scope.
    Availability
    The service makes contractual or operational commitments about uptime, recovery and capacity.
    Processing integrity
    Complete, valid, accurate, timely and authorised processing is central to the service.
    Confidentiality
    The company receives information designated as confidential and must protect it accordingly.
    Privacy
    The examination needs to address the collection, use, retention, disclosure and disposal of personal information.

    Adding every category does not automatically create a better report. It expands the assertions, controls, evidence and audit effort. Scope should follow the product and commitments, not marketing ambition.

    What is inside the SOC 2 system?

    The system description normally covers:

    • Services and principal product functionality
    • Infrastructure, software and data
    • People, teams and responsibilities
    • Procedures and automated processes
    • System boundaries and excluded components
    • Cloud and other subservice organisations
    • Customer responsibilities and complementary user-entity controls
    • Security incidents and significant system changes

    An unclear system boundary causes duplicated controls, missing suppliers and unreliable evidence. Scope must be settled before control design is finalised.

    What audit-ready controls look like

    Governance and risk

    Management assigns accountability, approves policies, evaluates risk, reviews performance and tracks material issues to closure.

    Access and people

    Joiner, mover and leaver processes, privileged access, authentication, access reviews, screening, confidentiality and security training operate consistently.

    Product and change

    Engineering changes are authorised, reviewed, tested and traceable. Production access, deployment, vulnerability remediation and secure-development responsibilities are controlled.

    Operations and resilience

    Monitoring, backups, recovery, capacity, incidents, continuity and availability commitments are supported by actual operating evidence.

    Suppliers and customer assurance

    Critical providers are assessed before use and reviewed thereafter. Contracts, subservice organisations, customer responsibilities and relevant assurance reports are maintained.

    A policy alone is not evidence that a control operated. The organisation needs dated approvals, tickets, logs, reviews, test results and follow-up records that match the control description.

    SOC 2 and ISO 27001

    Certifies an information-security management system
    Produces an assurance report about a defined service organisation system
    Uses an accredited certification body
    Uses an independent CPA firm
    Certification follows a multi-year surveillance cycle
    A new report covers a specified date or observation period
    Commonly recognised internationally
    Frequently requested by US enterprise customers

    Existing ISO 27001 governance, risks, policies, suppliers, incidents and internal reviews can be reused. However, the SOC 2 system description, management assertion, criteria mapping and period-specific evidence still need separate preparation.

    How Asteron prepares the organisation

    1. Buyer and route assessment

      Confirm why the report is needed and choose Type I or Type II based on customer expectations and control maturity.

    2. Scope and criteria definition

      Define the service, system boundary, locations, suppliers and Trust Services Categories that will be included in the examination.

    3. Readiness assessment

      Map controls and evidence against the proposed examination scope and identify material gaps before preparation begins.

    4. Control implementation

      Close material gaps and establish sustainable owners, procedures and automation so that controls can operate over time.

    5. Evidence period

      Operate controls, collect time-stamped evidence and correct exceptions promptly during the observation period.

    6. CPA readiness

      Prepare the system description, management inputs and evidence pack for the independent examination.

    Deliverables

    Scope and control design

    • SOC 2 route and scope recommendation
    • System-boundary and subservice-organisation map
    • Trust Services Category rationale
    • Risk and control matrix
    • Control-owner and evidence responsibilities
    • Prioritised remediation plan

    Evidence and CPA readiness

    • Evidence calendar and repository structure
    • System-description preparation
    • Control-operation and exception reviews
    • Management readiness pack
    • CPA request-list preparation
    • Independent examination handoff

    SOC 2 preparation pricing

    Scoped preparation project
    From €12,900

    Covers SOC 2 preparation for one principal organisation, one defined service and an agreed Type I or Type II route.

    Final scope depends on company size, system complexity, selected Trust Services Categories, number of locations and subservice organisations, existing control maturity and the required evidence period.

    For a first Type II report, the complete programme normally requires six to nine months. The CPA firm's fees are excluded.

    Typical milestones
    • 40% at signing
    • 40% after delivery of the scope and readiness baseline
    • 20% after the contracted preparation outcome

    Prices exclude VAT where applicable.

    Asteron guarantees completion and correction of its agreed preparation deliverables. It cannot guarantee an unmodified CPA opinion, prevent reported exceptions or control decisions made by the independent practitioner.
    View full pricing

    Independent CPA examination

    Asteron designs and prepares the control environment but does not issue the SOC 2 report.

    The examination must be performed by an appropriately qualified independent CPA firm. Keeping preparation and examination separate protects the credibility and independence of the report.

    The client selects, contracts and pays the CPA firm directly. External costs may include:

    • CPA examination and readiness procedures requested by the CPA
    • Penetration testing
    • Technical remediation
    • Specialist privacy or legal advice
    • Additional systems, locations or criteria
    • Continued control operation beyond the agreed project

    Responsibilities

    Asteron

    • Define the proposed route, system and criteria
    • Translate the scope into sustainable controls
    • Prepare the evidence model and system description
    • Review control operation and exceptions
    • Coordinate the agreed CPA handoff

    Your organisation

    • Approve the scope and service commitments
    • Assign control owners and operate controls
    • Provide complete and accurate evidence
    • Correct identified gaps and exceptions
    • Make the management assertion
    • Contract and communicate with the CPA firm

    Frequently asked questions

    What is a SOC 2 report?

    A SOC 2 report is an independent examination of a service organisation’s description of its system and the controls relevant to security, availability, processing integrity, confidentiality or privacy. It is issued by an independent CPA firm under standards established by the AICPA and helps customers assess risks associated with using the service.

    Is SOC 2 a certification?

    No. SOC 2 is an examination and an assurance report, not a certification. There is no certificate or badge issued by a certification body. The output is a report signed by the independent practitioner.

    What is the difference between Type I and Type II?

    Type I assesses the design and implementation of controls at a specified date. Type II assesses the design and operating effectiveness of controls throughout an observation period agreed with the CPA firm.

    Is Security mandatory?

    Yes. Security is the foundation of every SOC 2 examination. Availability, processing integrity, confidentiality and privacy are added only when they reflect actual service commitments and customer expectations.

    Should we include all five Trust Services Categories?

    No. Adding every category does not automatically create a better report. It expands the assertions, controls, evidence and audit effort. Scope should follow the product, its commitments and customer expectations.

    Does ISO 27001 replace SOC 2?

    No. ISO 27001 certifies an information-security management system, while SOC 2 produces an assurance report about a defined service organisation system. Existing ISO 27001 governance, controls and evidence can be reused, but the SOC 2 system description, management assertion and period-specific evidence still need separate preparation.

    How long does a first Type II programme take?

    Preparation, control operation and examination normally make the complete first Type II programme approximately six to nine months. Timing depends on readiness, the selected observation period and the CPA firm’s engagement plan.

    Can a European company obtain a SOC 2 report?

    Yes. SOC 2 is regularly used by European companies serving US customers. The examination must be performed by an appropriately qualified independent CPA firm; the service organisation can be based anywhere.

    Who performs the examination?

    An independent CPA firm performs the examination and issues the SOC 2 report. Asteron prepares the organisation but does not issue the report; combining preparation and examination would compromise the practitioner’s independence.

    Who can receive or read the report?

    SOC 2 reports are restricted-use reports intended for management, customers and other parties with sufficient understanding of the service and controls. Distribution is typically governed by non-disclosure arrangements.

    Can SOC 2 replace customer questionnaires?

    A credible report can reduce repeated evidence requests, but it will not replace every review. Some customers still require specific questionnaires, additional evidence or subject-matter-specific assurance.

    How much does SOC 2 preparation cost?

    A scoped SOC 2 preparation engagement starts from €12,900. Final scope depends on company size, system complexity, selected Trust Services Categories, number of locations and subservice organisations, existing control maturity and the required evidence period. The CPA firm’s fees are excluded.

    Official references

    • – AICPA — SOC for Service Organisations overview
    • – AICPA — SOC 2 guidance for service organisations
    • – AICPA — Trust Services Criteria
    • – AICPA — Description Criteria for a service organisation's SOC 2 system description

    Last reviewed: July 2026

    SOC and SOC 2 are registered trademarks of the AICPA. Asteron is not a CPA firm and is not endorsed by or partnered with the AICPA.

    Build evidence that enterprise customers can trust

    Define a defensible SOC 2 scope, operate the controls consistently and enter the independent CPA examination with organised evidence and clear ownership.

    View pricing