What an Auditor Actually Does During a SOC 2 Type II Review
July 22, 2026 · ComplianceBase Editorial
Demystifying Type II fieldwork — samples, walkthroughs, exceptions, and why “we have a policy PDF” is not enough.
Framework updates, enforcement notes, and implementation writing. No email gate.
July 22, 2026 · ComplianceBase Editorial
Demystifying Type II fieldwork — samples, walkthroughs, exceptions, and why “we have a policy PDF” is not enough.
July 10, 2026 · ComplianceBase Editorial
Auditor invoices are only part of the story. Here is how startups accidentally turn a $25K fee quote into an $80K year.
June 26, 2026 · ComplianceBase Editorial
The 2022 edition restructured Annex A into four themes. Here is what SaaS teams should update in scope, SoA, and buyer language.
June 18, 2026 · ComplianceBase Editorial
A practical 2026 review cycle for framework versions, regulatory sources, system scope, control evidence, vendor changes, and published compliance claims.
June 12, 2026 · ComplianceBase Editorial
A practical read on the 2022 Revised Points of Focus for the 2017 Trust Services Criteria — what changed for SaaS evidence, and what did not.
June 4, 2026 · ComplianceBase Editorial
How health technology companies can coordinate HIPAA safeguards and SOC 2 controls while preserving differences in law, scope, evidence, and assurance.
May 21, 2026 · ComplianceBase Editorial
Understand ISO/IEC 27001:2022 Annex A.8.23 and build risk-based web filtering that supports users, remote work, monitoring, exceptions, and privacy.
May 7, 2026 · ComplianceBase Editorial
Translate CC6.1 into practical identity, authorization, provisioning, authentication, service-account, and access-review engineering work.
April 23, 2026 · ComplianceBase Editorial
How transparent sourcing, editorial independence, expert review, and clear boundaries make compliance guidance more trustworthy and useful.
April 9, 2026 · ComplianceBase Editorial
A practical SOC 2 guide for AI companies covering system boundaries, model providers, training data, evaluations, access, change management, and incident response.
March 19, 2026 · ComplianceBase Editorial
A durable way to interpret recent GDPR enforcement themes across transparency, lawful basis, security, data rights, and cross-border processing.
March 5, 2026 · ComplianceBase Editorial
A practical method for mapping shared security practices across four frameworks without pretending that similar requirements are interchangeable.