HomeIndustriesPCI and SOC 2

PCI DSS and SOC 2

IT that holds up when the auditor opens it.

Your customers want the SOC 2 report. Your card processor wants PCI. An outside auditor is going to test the laptops, the access lists and the patch reports. We’ve managed both programs through outside audits.

In your vocabulary

What the auditor opens.

Access.

Who can reach what, reviewed on a schedule, with the review on file.

Devices.

Every laptop and phone managed, encrypted and accounted for.

Vulnerabilities.

Scans on a schedule. Findings fixed. The fix recorded.

Patching.

Servers and software patched on a cadence you can show.

Cloud and data center.

The links between office, data center and cloud documented and locked down.

Evidence.

Collected as the work happens. Not reconstructed the week before the audit.

Your compliance software lists what’s failing. Somebody still has to fix it.

What we’re not

We do the work the auditor tests.

  • Not your auditor.
  • Not a PCI assessor.
  • Not a compliance platform.

An independent firm issues the SOC 2 report. An assessor or your acquiring bank checks PCI. We run the systems they test and hand them the evidence.

Proof

From inside the audit.

  • We’ve managed PCI and SOC 2 compliance through outside audits.
  • We’ve run vulnerability scanning and remediation, and moved a company’s devices to modern management.
  • We’ve migrated a data center and connected it to the cloud.

Questions

Asked before audit season.

We already use a compliance platform. Do we still need you?

It tells you what’s failing. We fix it, and keep it fixed between audits.

Do you write the SOC 2 report?

No. An independent audit firm does. We get your systems ready and keep the evidence coming.

Are you a PCI assessor?

No. We do the IT work an assessor or your acquiring bank checks.

Start here

Two invoices. Two business days.

Send the last two bills from whoever handles your IT. We’ll tell you what you’re paying for, and whether it’s fair. Free.