Effortless Articles

What it Actually Took to get SOC 2 Type II

What it Actually Took to get SOC 2 Type II

Your benefits provider holds some of the most sensitive information your company has: your employees' health data. So how do you know they are protecting it?

You cannot inspect their systems. You cannot interview their developers. However, you can ask them for independent proof, and in our industry the most meaningful proof is a SOC 2 Type II report.

In plain terms: an independent auditor examines how a company protects data, not just its technology but how it hires, how it trains people, how it handles departures and how it responds when something goes wrong, and then watches those practices operate over a period of months to confirm they are real rather than just written down. At the end the auditor issues a formal opinion. That opinion is the report.

We went through that at Effortless Admin. It took longer than we expected, taught us more than we expected, and changed how we run the company. This is the story of why we did it, what it actually took, and how we maintain it today, ending with the three questions we now believe every employer should ask any provider holding their people's data. Including us.

Our clients raised the bar, and they were right

Employers and their advisors have grown less willing to accept "we take security seriously" without any independent evidence, and they have asked harder questions of every partner in their supply chain.

Our clients were part of that shift. In 2022 we put our commitment in writing: we would obtain SOC 2 to meet the growing needs of our clients and advisors. That summer, on July 6, 2022, we signed the engagement letter with our auditor.

To be honest, I assumed we were most of the way there already. We are a technology company after all and we build secure software for a living. How hard could this be?

I was about to find out.

I had the wrong idea about what gets examined

My mental model of a security audit was someone technical poking at our servers and reviewing our code. The reality is much bigger, and understanding why is the key to understanding what SOC 2 really tells you.

Our auditor's job was to draft the initial controls, the specific testable rules we would then be tested against, and to explain exactly how each one would be tested. When the list arrived it was not a list focusing on our servers and our code. It was a list about the company.

Do we run background checks on new hires? Can we prove it, for every hire? When someone leaves, is their access revoked, every time, with a record? Does a second developer review every change before it ships? Does our board oversee any of this?

That is the insight that changed how I think about security. Your data is not protected by technology. It is protected by an organization's habits. A firewall doesn't help if a departed employee's account stays active. Encryption doesn't help if nobody reviews changes.

At the project kick-off on August 22, 2022 our auditor grilled us on questions ranging from how we secured our systems, how our developers reviewed each other's code, how HR handled onboarding, offboarding and job descriptions, how our board of directors operated, and much much more. Sixteen days later they delivered the initial control set.

There I learned that forty-nine of those controls carried an annual review obligation, to be re-performed every year rather than implemented once. That is when I understood we were not preparing for an event. We were opening ourselves up to this on an ongoing basis.

So the work began. Fifteen security policies written from nothing, mapped to six internal audience groups so each employee acknowledged only the policies relevant to their role. A register of every out-of-date software component on our servers, forty-two items, each with an owner and a status, each to be upgraded or removed before the period opened. None of it was exotic. All of it was work.

How much work? In September 2022, in those our early conversations with the auditor, I said our security policies were probably two to three weeks from approval. They were published on January 15, 2024, well over a year later. I no longer make estimates about compliance timelines.

The long middle, when the mountain is just that big

That gap between September 2022 and January 2024 wasn't because because we got distracted, but because the sheer volume of controls to design, implement, and document was simply enormous for a company our size, on top of running the platform our clients depend on every day. Anyone who tells you SOC 2 preparation is a quick project either has an army of consultants or hasn't done it.

But that long middle produced the decision I'm most proud of.

We would not start the clock until we could pass

Here is something most people do not know about SOC 2 Type II. The company being examined chooses when its observation period begins, the window during which the auditor tests whether the controls are actually operating.

We had a simple principle: we would not start that clock until every control was genuinely in place and working. Not mostly in place. Not on track to be in place. Working.

So in late December 2023, three weeks before our window was set to open, we pushed the start date back two weeks to finish the last of our infrastructure updates and give our staff proper time to review and formally accept the security policies. It would have been easy to start on schedule and tidy up along the way. We weren't willing to be examined on work we knew wasn't finished, because then the report wouldn't mean what our clients needed it to mean.

That principle, more than any technology we deployed, is what I'd want a client to know about us.

What the reports say, and how to read one like a skeptic

Our first SOC 2 Type II report covered six months of operations in 2024. The auditor's opinion was unqualified (the strongest opinion available) meaning our controls were suitably designed and operating effectively throughout the period, with no exceptions noted on any control tested. Our second report picked up the day the first ended and covered a full year, with the same result: a clean, unqualified opinion. Together, the two reports cover eighteen continuous months of independently examined operations. Our third examination is underway right now.

One habit worth borrowing from us: read even good reports carefully. Every SOC 2 report defines its own scope... which criteria were examined, what period was covered, what was excluded. Ours cover security and privacy, the criteria that matter most for a company handling employee health data. A report that covers less is a smaller claim wearing the same name. When a vendor hands you a report, the scope section is where the truth lives.

And here's a wrinkle that surprises almost everyone: a SOC 2 report doesn't necessarily tell you what was actually tested. Some reports don't list the specific controls at all, and others describe them so vaguely that you can't tell what practice sits behind the words. Two companies can each hand you a "clean SOC 2 Type II," where one was examined against a rigorous, detailed set of controls and the other against a thin, generic list, and the cover pages look identical. If a vendor won't show you their controls, you're being asked to trust the label without the ingredients.

The report is a byproduct. The discipline is the product.

Here is what nobody told me at the start, and it is the most important thing I learned.

I thought the report was the finish line. It's not. The moment one observation period ends, the next begins. Dozens of controls come due for re-performance every year. Security policies get formally re-reviewed annually. We now audit our own suppliers the way our clients audit us, requesting and reviewing their reports on a recurring cycle. Compliance monitoring runs continuously in the background, every day.

And some of it is gloriously unglamorous. Over the past year and a half, I have personally sent our staff three separate reminders to complete overdue security training. The Chief Technology Officer, chasing training completions. It doesn't sound impressive, and that's exactly why it matters. Security training is the single practice that touches every person in the company, and when it slips, everything else slips behind it.

That's the real story of SOC 2. The report you can hand a client is just the visible artifact. What it actually certifies is that a company has built the habits... the reviewing, the training, the record-keeping, the chasing... and kept them running when no one was watching. A vendor cramming for the exam and a vendor living the discipline can both wave a report at you. The questions below tell them apart.

What to ask any provider holding your people's data

A few facts most buyers do not know. SOC 2 is an attestation examination under AICPA standards, not a certification, and it produces a service auditor's report rather than a certificate. There is no certifying body and no central register. There is no pass or fail either: a report is issued regardless of what the examination finds, so an organization can hold one containing exceptions or a qualified opinion.

And nothing expires, because AICPA imposes no validity period and no authority could revoke a report once issued. "We have SOC 2" can mean almost anything. These three questions make it mean something.

1. What period does your report cover, and when did it end? A SOC 2 report describes a window of time that has already closed. The industry convention is that a report goes stale about twelve months after its period ends. A vendor pointing to a report from two years ago is showing you history, not a current state. (And a vendor whose next examination is "in progress" has a plan, not a report. They should be upfront about which one they're offering you.)

2. Which trust services criteria are in scope? Security alone is the minimum. For anyone handling your employees' health information, ask whether privacy is covered too. The narrower the scope, the smaller the claim.

3. Is it a Type I or a Type II? A Type I says the controls were designed properly on a single day. A Type II says they actually operated effectively over months of real business. One letter, enormous difference.

We would rather you looked for yourself

Earlier I said a SOC 2 report might not tell you which controls were tested. We decided the fix for that is simple: show people.

We publish our controls, openly and in plain language, at our Trust Centre: trust.effortlessadmin.com. There you will find the practices we are examined against, organized across five categories: infrastructure security, organizational security, product security, internal security procedures, and data and privacy. Everything from encryption key access and penetration testing to background checks, disaster recovery testing, and what happens to customer data when a client leaves.

We built this because we are proud of these controls. Each one represents real, ongoing, unglamorous work, and we would rather you see them than take our word for it.

So consider this an open invitation. Go read them. Bring your IT team. Ask us hard questions about any control on the list.

Ask every provider holding your employees' data what period their last report covered, what was in scope, and whether it was a Type II. Then ask for one more thing: to see the actual controls. Ours are waiting for you at trust.effortlessadmin.com. The good ones will love that you asked.