Governance, risk & compliance
SOC 2 2024
SecurityGlobal
SOC 2 Trust Services Criteria — Type I (point-in-time design assessment) and Type II (operating effectiveness over a period, typically 6-12 months). Covers Security (required), plus optional Availability, Processing Integrity, Confidentiality, and Privacy criteria. Type I verifies controls are suitably designed. Type II verifies controls operated effectively over the audit period.
Official reference: https://www.aicpa.org/soc4so
Assessment tiers & levels Lavawall supports
Lavawall assesses SOC 2 at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Security (Common Criteria) | The system is protected against unauthorized access, use, or modification. Required for all SOC 2 reports. | — |
| SOC 2 Type I | Point-in-time assessment of whether security controls are suitably designed. Evaluates the design of controls as of a specific date. Faster to achieve (typically 1-3 months preparation). Good starting point for organizations new to SOC 2. | — |
| Availability | The system is available for operation and use as committed or agreed. | — |
| SOC 2 Type II | Operating effectiveness assessment over a period (typically 6-12 months). Evaluates that controls not only exist but are working as intended over time. Required by most enterprise customers and partners. Must demonstrate consistent control operation with evidence over the audit window. | Yes |
| Processing Integrity | System processing is complete, valid, accurate, timely, and authorized. | — |
| Confidentiality | Information designated as confidential is protected as committed or agreed. | — |
| Privacy | Personal information is collected, used, retained, disclosed, and disposed of in conformity with the commitments in the entity's privacy notice. | — |
How Lavawall® helps you get to SOC 2 compliance
Most of SOC 2 comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to SOC 2, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against SOC 2 in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Ready to tackle SOC 2?
Assess, remediate, and stay audit-ready for SOC 2 — and every other framework you carry — from one Lavawall® console.
Lavawall® supports SOC 2 as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.