Solutions /  The situation

SOC 2 for Israeli companies selling into the US.

The American buyer asked for a report, not a certificate, and the two are not the same thing. SOC 2 is an attestation by a US CPA firm about controls you operated over a period of time, which means the report cannot be produced faster than the period it describes. That single fact reorders your entire plan.

Get your free exposure assessment

US enterprise procurement treats SOC 2 as the price of entry, and their security review will not open an exception for a foreign vendor. If your product touches their customer data, someone on their side has a checklist with SOC 2 on it and no authority to skip it.

What it is costing you

  • A US deal, usually your largest, sits unsigned while a report gets produced.
  • Choosing Type II first when the deal needed a Type I now can cost you months of runway on the pipeline.
  • A report full of exceptions is worse than no report: you have handed the customer a documented list of what you do not do.
  • Do it twice (once for SOC 2, again for ISO 27001) and you pay for the same evidence two times.

What we do

01

We pick the right report and the right Trust Services Criteria

Type I (design, at a point in time) unblocks a deal fast; Type II (operating effectiveness, over a period) is what they will ask for next. Security is mandatory; Availability and Confidentiality are added only if your contract actually needs them. Most companies over-scope here.

02

Readiness assessment against the criteria

We map what you already do to the Trust Services Criteria and produce the exception list before the auditor does, while it is still cheap to fix.

03

We build and operate the controls

Access reviews, change management, vendor management, incident response, monitoring. These have to run for real during the observation window; there is no way to reconstruct them afterwards.

04

We manage the audit firm

SOC 2 is issued by a licensed CPA firm. We handle the auditor relationship, the evidence requests and the PBC list, so your engineers are not fielding sampling questions.

05

We map it once, use it twice

SOC 2 and ISO 27001 overlap heavily. We build one evidence base so the second framework is an extension, not a second project.

How long it takes. Type I is realistic in roughly three to four months. Type II requires an observation window (commonly three to twelve months of the controls running) plus the audit itself. No one can compress the window.

What is the difference between SOC 2 Type I and Type II?

Type I attests that your controls are suitably designed at a single point in time. Type II attests that those controls actually operated effectively across a period, commonly three to twelve months. Type I can be produced in a few months and is often enough to unblock a stalled deal; Type II is what the customer will ask for at renewal, and it cannot be produced faster than the observation window it covers, because the auditor is sampling evidence from that period.

Do Israeli companies need SOC 2 or ISO 27001?

It depends on the buyer. US enterprise customers ask for SOC 2; European and Israeli customers ask for ISO 27001. Companies selling into both eventually need both. The controls overlap substantially, so the right move is to build one evidence base and map it to both frameworks rather than run two separate projects.

Can a SOC 2 report have exceptions and still be useful?

Yes. An unqualified opinion with noted exceptions is common, and buyers read the exceptions. What harms a deal is a report that documents a control you claimed to your customer that you do not actually run. That is why the readiness phase matters: identify the exceptions before the audit period starts, while they can still be fixed, rather than publishing them to every prospect who reads the report.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.