Whilst many frameworks and certifications, such as ISO 27001, typically expect you to certify your entire organisation or a key branch of your organisation, the scope of a SOC 2 report is limited to the delivery of specific services that involve processing client data.   For example, if your organisation offers a number of services, but only a few of those services have clients requesting a SOC 2 report, you could undertake a SOC 2 audit purely on those few services and exclude the others.  

Your SOC 2 report is aimed at assuring the system that delivers your service, which  consists of everything you do and utilise to support the delivery of the in-scope service(s).   This will include service-specific elements, such as how the service is developed, the back-office functions that support it, how the service is technically secured, etc.  However, the system will also include wider, governance-related aspects that are relevant to your organisation more broadly, such as information about HR processes, how risk is managed, and how communications are managed.  

From beginning to end URM made achieving PCI compliance incredibly easy & worked with us to educate us on the requirements. They were always available for a call whenever we needed to discuss queries along the way & were always flexible to our internal deadlines. We would highly recommend URM from a consultancy & auditing perspective.
Prize competition business
Contact SOC 2 Experts Today

Preparing for a Successful SOC 2 Audit

Published on
17 Oct
2025

URM’s blog offers key advice on what to expect from your SOC 2 audit in practice, the types of evidence you will need to provide, how best to prepare, and more.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
29/8/2025
SOC 2 Explained

URM’s blog answers key questions about SOC 2, including what it is & who it applies to, why it is beneficial, how SOC 2 reports are structured & more.

Read more
"
We have been using the services provided by URM for a couple of years now. They have been excellent in providing their expertise on ISO 27001 and SOC 2, which was instrumental in guiding us on our compliance and certification journey. Thanks to their professionalism and knowledge, we continue to obtain certifications smoothly and with confidence.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.