// SOC2.jsx — Verigo Global: dedicated SOC 2 examination + support page const { V: SV, MAXW: SMW, FONT: SFT } = window; /* ── DATA ─────────────────────────────────────────────────── */ const TSC = [ ['lock', 'Security', 'Required', 'The mandatory Common Criteria — logical and physical access, change management, risk mitigation, and monitoring. Every SOC 2 examination includes it.'], ['gauge', 'Availability', 'Optional', 'Whether the system meets the uptime and performance commitments made to customers, including capacity, backup, and recovery.'], ['check', 'Processing Integrity', 'Optional', 'Whether processing is complete, valid, accurate, timely, and authorized — the data goes in and comes out correctly.'], ['shield', 'Confidentiality', 'Optional', 'How information designated as confidential is protected across its lifecycle, from collection through disposal.'], ['users', 'Privacy', 'Optional', 'How personal information is collected, used, retained, disclosed, and disposed of in line with your privacy notice.'], ]; const EXAM_TYPES = [ { badge: 'Type I', icon: 'file', tone: 'subtle', headline: 'Design, at a point in time.', body: 'A Type I examination reports on whether your controls are suitably designed to meet the selected Trust Services Criteria as of a single date — a snapshot of how the system is built.', points: [ ['Point-in-time opinion', 'Assesses control design on one specific date.'], ['Faster to issue', 'No multi-month observation window required.'], ['A natural first step', 'Often used to enter the market before a Type II.'], ], best: 'Best when you need a credible report quickly, or are publishing your first SOC 2.', }, { badge: 'Type II', icon: 'refresh', tone: 'brand', headline: 'Operating effectiveness, over time.', body: 'A Type II examination reports on whether those controls were not only designed well but operated effectively across an observation window — typically three to twelve months of evidence.', points: [ ['Period-of-time opinion', 'Tests controls across a 3–12 month window.'], ['Evidence of operation', 'Auditor samples real activity, not just policy.'], ['The market expectation', 'What most enterprise buyers now require.'], ], best: 'Best when customers and vendor-risk teams expect proof your controls actually run.', }, ]; const DELIVERY = [ { step: '01', icon: 'search', overline: 'Assess', title: 'Readiness Assessment', lead: 'Scope the examination and find the gaps before the auditor does.', desc: 'We help you define the right system boundary and Trust Services Criteria, then benchmark your current controls against them — scoring gaps by risk and effort and handing you an independent remediation roadmap.', deliverables: ['Scope & criteria selection', 'Control gap analysis against the TSC', 'Risk-scored remediation roadmap', 'Type I vs Type II recommendation'], link: 'services', linkLabel: 'About readiness assessments', }, { step: '02', icon: 'layers', overline: 'Implement', title: 'Implementation Toolkit', lead: 'Build the controls and the evidence engine the examination will test.', desc: 'A practitioner-led program that stands up the policies, controls, and procedures behind each criterion — and the evidence-collection routines that make a Type II observation window run quietly in the background.', deliverables: ['Policy & control implementation', 'Evidence collection procedures', 'Vendor & access review cadence', 'Control owner enablement'], link: 'toolkit:soc2', linkLabel: 'Explore the SOC 2 toolkit', }, { step: '03', icon: 'clipboard', overline: 'Prepare', title: 'Pre-Examination Preparation', lead: 'Walk into the examination knowing the opinion will be clean.', desc: 'A mock examination run by a lead reviewer independent of your implementation team — testing evidence against the criteria, surfacing exceptions while there is still time to remediate, and coaching your control owners for auditor walkthroughs.', deliverables: ['Mock examination & evidence test', 'Exception log & corrective actions', 'Control-owner walkthrough coaching', 'Auditor-request (PBC) readiness'], link: 'services', linkLabel: 'About pre-audit preparation', }, { step: '04', icon: 'award', overline: 'Examine & Sustain', title: 'Examination & Renewal Support', lead: 'Get the report issued — and keep earning it every year.', desc: 'We coordinate with the licensed CPA firm that performs the independent examination, manage the evidence and exceptions through to a clean opinion, then keep your evidence engine running so each annual renewal is a non-event.', deliverables: ['CPA examination coordination', 'Evidence & exception management', 'Report review & remediation', 'Annual renewal support'], link: 'contact', linkLabel: 'Talk to a practitioner', }, ]; const PROCESS = [ ['search', 'Readiness', '2–4 wks', 'Gap analysis against the chosen Trust Services Criteria.'], ['layers', 'Remediate', '2–4 mo', 'Build controls, policies, and the evidence routine.'], ['clipboard', 'Prepare', '2–4 wks', 'Mock examination and auditor-request readiness.'], ['refresh', 'Observation', '3–12 mo', 'Type II window — controls operate and evidence accrues.'], ['shield', 'Examination', '3–6 wks', 'Independent CPA firm tests controls and evidence.'], ['award', 'Report issued', '—', 'SOC 2 opinion delivered; renew on an annual cycle.'], ]; const OUTCOMES = [ ['doc', 'A shareable independent report', 'The deliverable is a licensed CPA firm\u2019s opinion on your controls — a report you can share under NDA to answer security due diligence in one document instead of a hundred emails.'], ['zap', 'Faster, unblocked sales', 'Security review is one of the most common reasons enterprise deals stall. A current SOC 2 report removes that blocker and shortens the path from interest to signature.'], ['shield', 'Less vendor-risk friction', 'Procurement and vendor-risk teams accept a SOC 2 report in place of bespoke questionnaires, so your team answers diligence once rather than for every prospect.'], ['refresh', 'A repeatable evidence engine', 'Because controls are embedded into how you operate, each annual renewal draws on evidence the business already generates — the second examination is far lighter than the first.'], ['network', 'A foundation you can reuse', 'The controls behind your SOC 2 map directly onto ISO 27001, HIPAA, and NIST — so the work you do here accelerates every framework that comes next.'], ['gauge', 'A genuinely stronger posture', 'Beyond the report, the discipline of continuous evidence and monitoring leaves your organization measurably more resilient — not just certified on paper.'], ]; const SOC_FAQ = [ ['What exactly is a SOC 2 examination?', 'SOC 2 is an attestation examination performed by a licensed CPA firm under AICPA standards. The firm examines the controls relevant to your selected Trust Services Criteria and issues an independent report containing its opinion. It is an examination and opinion — not a pass/fail certification or a checklist audit.'], ['Should we start with Type I or Type II?', 'It depends on your timeline and what customers are asking for. A Type I examination reports on control design at a point in time and can be issued quickly, which is useful for entering the market. A Type II examination tests operating effectiveness over a 3–12 month window and is what most enterprise buyers ultimately expect. Many clients publish a Type I first, then move into a Type II observation window.'], ['Which Trust Services Criteria do we need?', 'Security (the Common Criteria) is mandatory in every SOC 2 examination. Availability, Processing Integrity, Confidentiality, and Privacy are optional — you select the ones that match the commitments you make to customers. We help you scope the right set in the readiness assessment so the examination is neither thin nor needlessly broad.'], ['Can Verigo perform the examination itself?', 'No — and that independence is the point. The examination and opinion must be issued by an independent licensed CPA firm. Verigo guides you through readiness, implementation, and preparation, and coordinates the examination, but we keep our pre-examination reviewer independent of your implementation team to protect the integrity of the result.'], ['How long is a SOC 2 report valid?', 'A SOC 2 report covers a stated period and customers generally expect one issued within the last twelve months. That is why we build a continuous evidence engine: rather than scrambling each year, your controls keep producing the evidence the next examination needs, making annual renewal routine.'], ]; /* ── BREADCRUMB ───────────────────────────────────────────── */ const SCrumb = ({ onNav }) => (
/ / SOC 2
); const sCrumbBtn = { background: 'none', border: 'none', cursor: 'pointer', color: '#7A7A8A', fontSize: 13, fontWeight: 600, padding: 0, fontFamily: "'DM Sans', system-ui, sans-serif" }; /* ── HERO ─────────────────────────────────────────────────── */ const SHero = ({ onNav }) => (
AICPA Attestation SOC 2 Type I & Type II

SOC 2 examinations, delivered end to end.

The baseline trust attestation for US and India-based SaaS and IT service providers. Verigo takes you from first gap analysis to a clean SOC 2 opinion — and keeps the evidence engine running so every annual examination is a non-event.

onNav('contact')}>Start a Conversation document.getElementById('delivery')?.scrollIntoView({ behavior: 'smooth', block: 'start' })}>See how we help
At a glance
{[ ['globe', 'Scope', 'United States & India'], ['layers', 'Criteria', '5 Trust Services Criteria'], ['file', 'Report types', 'Type I & Type II examinations'], ['gauge', 'Type II window', '3–12 month observation'], ].map(([ic, k, val], i) => (
{k}
{val}
))}
); /* ── STATS STRIP ──────────────────────────────────────────── */ const SStats = () => (
{[ ['76%', 'Adoption among audited orgs (2025)'], ['5', 'Trust Services Criteria'], ['Type I & II', 'Point-in-time & period reports'], ['12 mo', 'Typical report validity window'], ].map(([v, l], i) => (
{v} {l}
))}
); /* ── WHAT IT IS / TRUST SERVICES CRITERIA ─────────────────── */ const SOverview = () => (
What a SOC 2 examination is

An independent opinion, not a checklist.

SOC 2 is an attestation examination performed by a licensed CPA firm under AICPA standards. The firm examines the controls relevant to your selected criteria and issues an independent report stating its opinion on them.

The examination is built on the five Trust Services Criteria. Verigo’s Compliance by Design approach embeds those controls into how you already operate — so the evidence the examination needs is generated by the process, not assembled in a panic before each window.

{[ 'Security is mandatory; the other four criteria are selected to fit your commitments', 'Type I examines design; Type II examines design and operating effectiveness', 'The natural hub for ISO 27001, HIPAA, and NIST evidence reuse', ].map((t, i) => (
{t}
))}
The five Trust Services Criteria

One required. Four by choice.

{TSC.map(([ic, name, req, desc], i) => (

{name}

{req}

{desc}

))}
); /* ── TYPE I vs TYPE II ────────────────────────────────────── */ const ExamTypes = () => (
{EXAM_TYPES.map((t) => { const brand = t.tone === 'brand'; return (
SOC 2
{t.badge}

{t.headline}

{t.body}

{t.points.map(([h, d], j) => (
{h}
{d}
))}
{t.best}
); })}
); /* ── DELIVERY MODEL (CORE) ────────────────────────────────── */ const SDelivery = ({ onNav }) => (
Four service lines, mapped
to the SOC 2 examination lifecycle.} sub="Engage any single stage or move through the whole journey with one accountable, senior-led team — coordinating the independent examination, with a peer-review quality gate on every deliverable." maxSub={660} />
{DELIVERY.map((s) => (
{s.step}
{s.overline}

{s.title}

{s.lead}

{s.desc}

What you receive
{s.deliverables.map((d, j) => (
{d}
))}
))}
); /* ── PROCESS TIMELINE ─────────────────────────────────────── */ const SProcess = () => (
{PROCESS.map(([ic, t, dur, d], i) => (
{dur}
{t}
{d}
))}
); /* ── OUTCOMES ─────────────────────────────────────────────── */ const SOutcomes = () => (
{OUTCOMES.map(([ic, t, d], i) => (

{t}

{d}

))}
); /* ── FAQ ──────────────────────────────────────────────────── */ const SFAQ = ({ onNav }) => { const [open, setOpen] = React.useState(0); return (
SOC 2 questions

Good to know before we start.

Questions on scope, criteria, or the difference between a Type I and Type II examination? A senior practitioner will walk you through it.

onNav('contact')}>Start a Conversation
{SOC_FAQ.map(([q, a], i) => { const isOpen = open === i; return (
{isOpen && (

{a}

)}
); })}
); }; /* ── PAGE ─────────────────────────────────────────────────── */ const SOC2Page = ({ onNav }) => (
); Object.assign(window, { SOC2Page });