About soc2pentest.org
soc2pentest.org covers SOC 2 as a European software or service company actually meets it: through a customer contract, on somebody else's calendar, and around a report the company is not permitted to issue for itself. Readers making procurement decisions deserve to know where guidance like this comes from, so it is set out here.
Publisher
The site is published by SEQ SIA (registration number 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a penetration testing and security consulting company. Contact: support@offseq.com.
Authorship
SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than individual bylines. Every source is listed so a reader can check the basis for a statement instead of taking it on trust.
How the guidance is sourced
- Statements about SOC reports are sourced to AICPA material or to the Journal of Accountancy, the AICPA's own publication, and quoted where the wording is the point.
- Statements about the international assurance standards are sourced to the IAASB pronouncement itself.
- Statements about EU law cite the instrument on EUR-Lex, article by article.
- The trust services criteria are not reproduced here. They are published by the AICPA behind an account, and paraphrasing copyrighted criteria into quotation marks would be worse than describing them, so this site describes them and links to the source.
- The tender figures on the home page are our own measurement against the public TED search API, with the query, corpus and date stated so anyone can repeat it.
- The "Updated" date moves only when the text changes. An automated content-hash ledger reverts unearned bumps.
Commercial interest
We sell readiness work and the penetration test this site describes. That is a direct interest in you concluding that you need them, and it should color how you read every recommendation here.
- Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers.
- No CPA firm, certification body, compliance platform or tool vendor pays for a mention. There is no advertising and no affiliate revenue.
- Where the honest answer is that you do not need a SOC 2, or that ISO/IEC 27001 would serve your buyers better, the site says so. That answer costs us work and it is still the right one.
- We do not receive a commission for referring you to a CPA firm.
Not advice
Nothing here is legal advice, and it is not a substitute for the judgment of the CPA firm that will perform your examination or the counsel who reviews your customer contracts. Scope, criteria selection and evidence sufficiency are decisions for you and your service auditor.
Corrections
Send corrections to support@offseq.com, ideally with the source. Substantive changes are made and re-dated in the open.