Assurance-Driven: “Prove Security, Earn Trust. Stay Compliant”
Protect your data, prove your integrity, and meet regulatory demands with confidence — your path to seamless SOC 1, SOC 2, and SOC 3 compliance starts here. Cianaa supports merchants and service providers across New Zealand, Australia, Asia Pacific, Europe, USA and Canada.
Pillars of SOC compliance
Already know which SOC you need?
Your Guide to the Trusted Services Criteria
Explore the five pillars of SOC compliance — security, availability, processing integrity, confidentiality, and privacy. Securing accreditation means your service has met strict security and privacy standards. Independent evaluators assess your controls against the Trust Services Criteria (TSC).
Security
Protection against unauthorized access, both physical and logical.
Availability
System availability for operation and use as committed or agreed.
Processing Integrity
System processing is complete, accurate, timely, and authorized.
Confidentiality
Information designated as confidential is protected as committed or agreed.
Privacy
Personal information is collected, used, retained, disclosed and disposed of in accordance with commitments.
SOC 1 and SOC 2 Compliance
Cianaa delivers comprehensive assessments across all SOC report types and engagement modes.
Internal Controls over Financial Reporting
Focuses on internal controls relevant to your client’s financial reporting. Critical for service organizations whose services impact their clients’ financial statements.
Trust Services Criteria (TSC)
Assesses controls against the five TSC pillars — security, availability, processing integrity, confidentiality, and privacy. The de-facto standard for SaaS and cloud providers.
General Use Trust Report
A public-facing version of the SOC 2 report — designed to share with customers and the general public to demonstrate trustworthiness.
The Auditor’s Philosophy
During the audit, we evaluate the design (Type I) and operational effectiveness (Type II) of your controls. Our approach is thorough, transparent, and collaborative.
Scoping & Objectives
The auditor defines the scope of the audit, sets clear objectives, and formulates a comprehensive plan for executing the audit effectively.
Identify Stakeholders & Vectors
The auditors ascertain the individuals, processes, and technologies that fall within the scope of the audit, while also identifying potential attack vectors.
Threat-Based Framework
In light of the risks identified through the threat assessment, the auditors develop a comprehensive framework to assess each control, ensuring thorough due diligence.
Empirical Evidence
Our audit is grounded in empirical evidence. The findings are substantiated by data, providing our clients with a comprehensive overview of any identified nonconformities.
Control Effectiveness
The auditor assesses the effectiveness of the controls implemented to verify their presence, thereby mitigating potential threats and risks.
Conclusive Findings
The auditors expertly gather and analyze evidence from various sources to reach decisive conclusions and produce a robust SOC report.
We use diverse approach to Evidence Corroboration
Triangulating evidence from multiple sources gives credible, defensible audit conclusions.
Multi-Standard Efficiency
Saves time efficiently by utilizing a single, streamlined method to evaluate a variety of different standards across multiple criteria.
Triple-Source Triangulation
Having three or more sources of evidence gives credible results for cyber security assessments.
True Facts, Corroborated
We state true facts or findings corroborated by evidence.
Honest Posture Reporting
The audit methodology indicates your probable risks and findings give you a true posture of risk — mitigated or elevated.
Frequently Asked Questions about SOC Compliance
What are the Trust Services Criteria for SOC compliance?
The five pillars of SOC compliance are security, availability, processing integrity, confidentiality, and privacy.
What is the difference between SOC 1, SOC 2 and SOC 3?
SOC 1 focuses on internal controls over financial reporting. SOC 2 assesses controls relevant to the five Trust Services Criteria. SOC 3 is a general-use, public-facing version of the SOC 2 report.
What is the difference between SOC Type I and Type II?
Type I evaluates the design of controls at a specific point in time. Type II evaluates both the design and operational effectiveness of controls over a defined period.
What does the SOC audit process involve?
Scoping, gap assessment, control framework review, evidence collection from multiple sources, design and operational effectiveness testing, and delivery of a detailed SOC report.
Ready to start your SOC compliance journey?
SOC 1, SOC 2, SOC 3 — Type I and Type II assessments grounded in empirical evidence. Covered by Cianaa across New Zealand, Australia, Asia Pacific, Europe, USA and Canada.
