What SOC 2 actually is
SOC 2 (System and Organization Controls 2) is an AICPA framework. Reports are issued by independent CPA firms against the Trust Services Criteria: Security, which every SOC 2 covers, plus optionally Availability, Processing Integrity, Confidentiality, and Privacy. The Security category is built on the Common Criteria, CC1 through CC9, and a large share of those criteria are technical controls you configure in Microsoft 365, Intune, and Entra ID.
Who needs SOC 2
SOC 2 is voluntary, but it is usually buyer-driven: your customers ask for it before they will trust you with their data.
SOC 2 Type I and Type II
SOC 2 comes in two report types. Buyers increasingly want Type II, because it proves the controls actually held up.
How Siemserva supports the SOC 2 technical controls
The Security category's Common Criteria map closely to Microsoft 365 configuration. Siemserva by Senserva assesses these controls, ranks the gaps, fixes them with validated remediation, and produces the evidence. Each area links to where it is covered.
SOC 2 covers people, process, and technology. Siemserva addresses the Microsoft 365 technical and configuration controls and the evidence for them. It does not write your policies, run your HR, or perform the audit.
Working with a partner that does not have SOC 2
A vendor or partner without a SOC 2 report is not automatically a dealbreaker, but their risk becomes your risk. You can still work with them safely, and you can document it for your own SOC 2.
Frequently asked
Does Siemserva make me SOC 2 compliant?
No. SOC 2 is an attestation issued by an independent, licensed CPA firm. Siemserva by Senserva gets the Microsoft 365 technical security controls in shape and produces the evidence behind them, which is a large part of the SOC 2 Security criteria.
What is the difference between SOC 2 Type I and Type II?
Type I checks that controls are designed appropriately at a point in time. Type II tests that they operated effectively over a period, typically 3 to 12 months. Most buyers want a Type II report.
Who needs SOC 2?
SaaS and cloud vendors, MSPs and MSSPs, and any company whose customers run vendor security reviews or ask for a SOC 2 report before trusting them with data.
How do I work with a partner that does not have SOC 2?
Assess the partner directly, limit the data and access you grant them, apply and verify compensating controls in your own Microsoft 365 tenant, monitor continuously, and document the gap and your mitigations for your own auditor.
Does Siemserva help with SOC 2 Type II evidence over time?
Yes. Continuous scanning and configuration drift detection show your Microsoft 365 controls stayed in place across the audit period, with audit-ready evidence on every scan.
Helpful links
Authoritative references on SOC 2. Each opens in a new tab.
Get your SOC 2 technical controls in shape
Scan your Microsoft 365 tenant, fix the gaps behind the Security criteria, and produce audit-ready evidence, in minutes. 501(c)(3) nonprofits get the full version free.
Get a key and get going