← Back to Case Studies

Global Network Provider — SOC 2 Type II with Clean Opinions

A global network solutions provider achieved SOC 2 Type II across all Trust Services Criteria — with clean opinions across the observation period — unlocking enterprise contracts and removing a persistent sales blocker.

Sector: Technology Services: SOC 2 Type I, SOC 2 Type II, Trust Services Criteria, Evidence Automation, Continuous Compliance Tags: SOC 2, Type II, Network Provider, Technology, Trust Services Criteria
Clean opinionsAll 5 Trust Services Criteria
3 contractsEnterprise deals unblocked
Weeks → hoursSecurity review turnaround time
Zero scramblesContinuous evidence, no audit prep panic

At a Glance

SectorTechnology / Network Infrastructure
Starting pointNo formal SOC 2 programme, inconsistent control documentation, no continuous evidence collection
TimelineType I readiness in 8 weeks; Type II clean opinion over 12-month observation period
FrameworksSOC 2 — Security, Availability, Confidentiality, Processing Integrity, Privacy
EnvironmentMulti-data-centre, multiple jurisdictions, Microsoft 365

The Challenge

Enterprise customers — particularly in financial services, healthcare, and government-adjacent industries — were requiring SOC 2 Type II before adding the provider to their approved vendor lists. Three significant contracts were stalling because the answer to “can you provide a SOC 2 report?” was “not yet.”

The complicating factor was scale and complexity. This wasn’t a startup with a simple, contained environment. The provider operated across multiple data centres, served clients in several jurisdictions, and had network infrastructure that touched customer environments directly. The Trust Services Criteria weren’t just a documentation exercise — they needed to reflect real operational controls across a complex estate.

The specific gaps at the start of the engagement:

Three six and seven-figure contracts were waiting. The cost of “not yet” was measurable and growing.


Our Approach

SOC 2 Type II requires something that Type I doesn’t: evidence of operating effectiveness over time. You can’t sprint to Type II — you have to operate controls consistently across the observation period and capture evidence as you go. The programme was designed around this reality from day one.

1. Type I foundation (weeks 1–8)

Mapped all five Trust Services Criteria to the provider’s existing control environment. Identified gaps, documented control descriptions, and built the evidence collection infrastructure. Type I readiness was achieved at week 8 — confirming that controls were designed and implemented appropriately.

2. Continuous evidence programme (months 2–12)

Built automated evidence collection workflows — monitoring logs, access review exports, change management records, incident tickets, and vendor assessment outputs. The goal was to make evidence a byproduct of normal operations, not a project that happened before an audit.

Key controls formalised and continuously evidenced:

3. Vendor and third-party risk

Rebuilt the vendor risk assessment process — prioritised critical vendors, conducted structured assessments, established an annual review cadence. Vendor security evidence was included in the Type II audit pack.

4. Type II audit support

Supported the full Type II audit — evidence presentation, auditor sampling, assessor Q&A, and finding response. The observation period produced clean opinions across all five Trust Services Criteria.


Results

SOC 2 Type II — clean opinions across all Trust Services Criteria. The three stalled enterprise contracts moved forward. Security reviews that previously took weeks now took hours.

The commercial impact was direct and measurable:

The continuous evidence programme also delivered an operational benefit: leadership had real visibility into control performance across the observation period, not just at audit time.


Key Deliverables


The Bottom Line

SOC 2 Type II isn’t a project you complete — it’s an operating state you maintain. The difference between organisations that get clean opinions and those that scramble before every audit is whether evidence collection is embedded in operations or bolted on at the last minute.

This provider built it properly from the start, achieved clean opinions on the first Type II report, and now has a compliance infrastructure that supports ongoing enterprise sales without annual disruption.

Need a similar outcome?

We help government, health, and technology organisations achieve certification faster with automated evidence and expert delivery.

Book a free 30-min call
📞 Microsoft Teams