Cyberwall Blog · December 7, 2023

SOC 2 Announcement

Cyberwall has completed SOC 2 certification, confirming our security, availability, and confidentiality controls meet an independently audited standard.

By Alex Plotkin, CEO

Update: Cyberwall has since completed its next SOC 2 Type II audit cycle — see Cyberwall Successfully Passes SOC 2 Type II Audit for the most current audit.

Cyberwall has completed its SOC 2 Type II examination, the widely recognized standard developed by the American Institute of Certified Public Accountants (AICPA) for evaluating how service organizations manage data. The certification confirms our controls hold up against five trust principles: security, availability, processing integrity, confidentiality, and privacy.

The Type II designation matters on its own. A Type I report only confirms that an organization’s controls are designed correctly as of a single point in time, essentially a snapshot. A Type II report goes further: it confirms those same controls were actually operating effectively over an extended observation period, typically several months to a year, based on evidence an independent CPA firm reviewed directly rather than took on faith. That distinction is the difference between a policy document that looks good on paper and proof that the policy was actually followed, day after day, under real operating conditions.

For a managed security provider, this isn’t optional. It’s table stakes for being trusted with someone else’s environment. An MSSP typically has some level of access into a client’s network, endpoints, or logs in order to do its job, which means a client is extending trust that goes beyond a typical vendor relationship. Asking that provider to prove, through an independent third-party audit, that it handles access, incident response, change management, and data handling the way it says it does isn’t an unusual request. It’s a reasonable baseline. Our CEO, Alex Plotkin, put it simply: this is proof of a commitment we intend to keep raising the bar on, not a milestone we consider finished.

What the audit actually looks at is broader than most people expect. It’s not just “do you have a firewall.” Auditors examine access control policies and whether they’re enforced in practice, how changes to production systems get approved and tracked, how incidents get detected and escalated, how employee onboarding and offboarding handle system access, and how the organization’s own vendors and subprocessors are managed. Each of those areas has to hold up not just in a written policy but in the evidence: access logs, change tickets, training records, and incident documentation collected across the entire audit window. That’s what makes a Type II report meaningfully harder to earn than a self-attestation or a marketing claim of “bank-level security.”

A SOC 2 report also isn’t a one-time achievement in the way a certificate on a wall might suggest. It’s tied to a specific audit period, and it has to be renewed on a recurring basis, typically annually, with a fresh examination covering the months since the last one. That’s a deliberate design choice in the framework: controls that were operating effectively last year can quietly drift, whether through staff turnover, a new tool that wasn’t fully integrated into existing processes, or a policy that stopped matching how the team actually works day to day. An organization that lets its SOC 2 report go stale, or that points to one from several years ago, isn’t really offering current proof of anything.

It’s also worth knowing where SOC 2 fits relative to other frameworks that come up in vendor conversations, since they get compared often but aren’t interchangeable. ISO 27001 is an international standard focused specifically on information security management systems and results in a certification; SOC 2 is an American Institute of Certified Public Accountants attestation framework covering the five trust principles above and results in a detailed audit report rather than a certificate. Some organizations pursue both because different customers or regions ask for different proof, but neither one substitutes for the other, and a vendor claiming one when they actually hold the other is a red flag worth following up on directly.

If you’re vetting vendors as part of your own compliance program, this is exactly the kind of independent verification you should be asking every provider for, not just us. A vendor’s SOC 2 report (specifically the Type II version, and specifically one covering a recent audit period, not one that’s aged out) is one of the fastest ways to separate a provider that has actually built a security program from one that’s describing an aspiration. It’s also worth checking which trust principles are in scope; not every SOC 2 report covers all five, and for a security-focused vendor, security and confidentiality should always be included. A responsible provider will also generally share the report itself, under a standard confidentiality agreement, rather than just asserting that one exists.

It’s also the standard our own compliance services help clients meet for their own audits, whether that’s a first SOC 2 examination, a renewal, or preparing for the kind of vendor security questionnaire that increasingly shows up in procurement, cyber insurance renewals, and board-level risk reviews. The bar keeps moving upward across every industry we serve, and treating a certification as a finish line rather than a floor is exactly the mindset that causes organizations to fall behind it.

Related reading: Cyberwall Successfully Passes SOC 2 Type II Audit

Not ready to wait on a blog post?

Book a preparedness call and get a straight answer for your specific situation, no searching required.