BlueKey IT helps companies prepare for a SOC 2 audit. We assess your controls against the AICPA Trust Services Criteria, close technical gaps, build the policies and evidence, and keep controls running through your audit period.
Real reviews from real customers. See why businesses choose BlueKey IT.
Read All Reviews →Posted on Google![]()
Nilam KhuranaSeptember 12, 2026Trustindex verifies that the original source of the review is Google.
Bluekey IT has been helping our businesses for years. From setting up offices, setting up security measures and continued monitoring to make sure we are safe, they have been there. I would highly recommend them.Posted on Google![]()
Katlyn KaiserJuly 31, 2026Trustindex verifies that the original source of the review is Google.
I have had a great experience working with BlueKey IT. Their team is knowledgeable, responsive, and always willing to go the extra mile to ensure issues are resolved quickly.Posted on Google![]()
Corey NashJuly 29, 2026Trustindex verifies that the original source of the review is Google.
Bluekey has been keeping my business systems running smoothly for nearly a decade. If my systems are down, I cannot make money, when I call Bluekey with a problem they are always quick to answer the phone and give me back up and going in short order. I am so thankful to have them on my side.Posted on Google![]()
Anthony WeinbergJuly 27, 2026Trustindex verifies that the original source of the review is Google.
Amazing team of tech professionals, always there when you need them!Posted on Google![]()
Amy BaerJuly 27, 2026Trustindex verifies that the original source of the review is Google.
I own a large company with over 100 employees. We have used BlueKey for many years area and very happy with the service they provide. Their Management and staff are all amazing.Posted on Google![]()
Undrea SmithJuly 27, 2026Trustindex verifies that the original source of the review is Google.
We've worked with Blue Key for well over a decade, and they've been much more than just an IT company. As our firm has grown, they've been a true technology partner, helping us upgrade our systems, improve security, and make sure our infrastructure keeps pace with our business. One of the things we value most is their responsiveness. Our team is spread across the country, so having 24/7 support that anyone on our team can access is incredibly important. No matter when an issue comes up, Blue Key is there to help quickly and professionally. If you're looking for an IT company that is proactive, knowledgeable, and genuinely invested in your success, I highly recommend Blue Key. They've played an important role in supporting our growth, and we're grateful for the partnership.Posted on Google![]()
David RobinsonJuly 27, 2026Trustindex verifies that the original source of the review is Google.
BlueKey It Services are very knowledgeable and caring. They provide white glove service and top of the line support for all their clients needs. They are all trained to the highest level in their respective industry and I would recommend them to anyone that needs IT services.Posted on Google![]()
Ed WiegnerApril 8, 2026Trustindex verifies that the original source of the review is Google.
Had an AMAZING iT support experience with Alex at Blu Key IT today. In over 25 years this IT support professional wen above and beyond. Patient focused kind focused and understanding. Jason's following up just appreciate that kind of service and knowledge. Thank YouPosted on Google![]()
C W MaccApril 2, 2026Trustindex verifies that the original source of the review is Google.
Harrison at BlueKeyIT is quick to answer, courteous, knowledgeable, and professional. I continue to be 100% satisfied with the genuine Customer Care provided by the entire Team at BlueKeyIT. Highly recommended!
A SOC 2 audit tests whether your controls exist and whether they work. BlueKey IT prepares the technical environment, builds the policies and evidence trail, and keeps controls running through your audit period, so the auditor you choose finds a company that is ready.
Readiness work · Technical controls · Policies and evidence · 200+ customers and 6,000+ endpoints managed
SOC 2 is an attestation report written by an independent CPA firm about the controls a service organization uses to protect customer data. The report is based on the AICPA Trust Services Criteria. It is not a certification and it is not pass or fail. The auditor describes your system, tests your controls, and gives an opinion, and any exceptions are included in the report.
The auditor evaluates whether your controls are suitably designed as of a specific date. It is a faster first report and shows intent.
The auditor tests whether controls operated effectively over a period of time. Many customers ask for this report.
Most companies repeat the audit each year so customers always have a current report.
| Report | Covers | Typical use |
|---|---|---|
| SOC 1 | Controls relevant to a customer’s internal control over financial reporting | Service providers whose work affects customers’ financial statements |
| SOC 2 | Security, availability, processing integrity, confidentiality, or privacy controls, with control-level detail | Shared with customers and prospects, usually under a non-disclosure agreement |
| SOC 3 | The same subject areas as SOC 2 with less detail | A general-use report that can be shared publicly |
Who issues the report: A SOC 2 report is issued by an independent, licensed CPA firm, not by an IT provider or a compliance software platform. BlueKey IT is not a CPA firm and does not perform SOC 2 audits. We get your technical environment, policies, and evidence ready and work alongside the auditor you choose.
Security is included in every SOC 2 report. You choose whether to add the others based on what your customers expect. Each additional category adds criteria and audit work.
| Category | What it covers | How BlueKey IT helps |
|---|---|---|
| Security (required) | Protection of systems and data against unauthorized access and other threats. Covered by the common criteria, CC1 to CC9 | MFA, access controls, endpoint protection, 24/7 monitoring, patching, and security awareness training |
| Availability (A1) | Systems are available for operation and use as committed | Monitored infrastructure, backups, and disaster recovery planning and testing |
| Confidentiality (C1) | Information designated as confidential is protected and disposed of as committed | Encryption, access restrictions, and secure data handling and disposal |
| Processing integrity (PI1) | System processing is complete, valid, accurate, timely, and authorized | Change management, monitoring, and supporting documentation for the IT environment |
| Privacy (P1 to P8) | Personal information is collected, used, retained, disclosed, and disposed of as committed | Access controls, retention and disposal practices, and policy documentation |
The security category is built on nine series of common criteria. Several are about governance and management decisions, which only your leadership can own. Others are technical, and that is where we do most of our work.
| Criteria series | What auditors look at | Where BlueKey IT helps |
|---|---|---|
| CC1 Control environment | Leadership commitment, oversight, roles, and accountability | Policy drafting and documentation support. Decisions stay with your leadership |
| CC2 Communication and information | How security information is communicated internally and externally | Documentation of security responsibilities and communication channels |
| CC3 Risk assessment | How risks are identified, analyzed, and managed | Technical input to your risk assessment and a tracked remediation plan |
| CC4 Monitoring activities | Ongoing and separate evaluations of whether controls work | Monitoring reports, scheduled reviews, and evidence collection |
| CC5 Control activities | Policies and procedures that put risk responses into action | Written procedures and the technical controls that enforce them |
| CC6 Logical and physical access | Access provisioning and removal, authentication, encryption, and physical security | MFA, role-based access, access reviews, offboarding records, and device encryption |
| CC7 System operations | Detection of anomalies, monitoring, and incident response | 24/7 monitoring, endpoint detection and response, logging, and incident response documentation |
| CC8 Change management | Authorization, testing, and approval of changes to systems | Patch and change records, and support documenting change procedures |
| CC9 Risk mitigation | Business disruption risk and vendor and partner risk | Backup and recovery planning, and vendor review support |
For a Type II report, auditors test samples from throughout the period. The easiest way to prepare is to collect the evidence as part of normal operations. These are typical examples.
| Control area | Typical evidence |
|---|---|
| Access provisioning and removal | New hire and termination tickets, access approvals, and timestamps showing when access was granted or removed |
| Authentication | MFA enrollment and enforcement reports, and password and session settings |
| Access reviews | Dated reviews of user, administrator, and vendor access, with approvals and follow-up |
| Endpoint and malware protection | Device inventory, protection coverage reports, and alert handling records |
| Vulnerability and patch management | Scan results, patch compliance reports, and remediation tickets |
| Change management | Change tickets with approval, testing, and deployment records |
| Monitoring and incident response | Alert history, incident tickets, post-incident reviews, and tabletop exercise notes |
| Backup and recovery | Backup job reports and dated restore test results |
| Training and policies | Policy acknowledgments, training completion records, and phishing simulation results |
| Vendor management | Vendor inventory, contracts or security terms, and periodic review records |
Decide which systems and services are in scope and which Trust Services categories to include, based on what customers ask for.
Compare current controls to the criteria, then close technical and documentation gaps.
Choose a licensed CPA firm with SOC 2 experience and agree on report type, scope, and timing.
Confirm controls are designed and evidence is flowing. Some companies take a Type I report first.
Controls operate and evidence is collected throughout the period agreed with your auditor.
The auditor tests samples, reports any exceptions, and issues the report. Most companies then repeat the cycle each year.








We choose the scope and criteria with you, review your current controls, and document the gaps.
We implement the technical controls and write the policies and procedures that support them.
We organize evidence, hand off to your auditor, and keep controls running through the audit period.
A technical description of in-scope systems, data flows, and infrastructure for the system description your auditor needs.
Findings mapped to the criteria with owners and status.
Evidence of MFA, encryption, logging, monitoring, and patching configuration.
Security policies and procedures matched to how your company operates.
A schedule of recurring tasks, such as access reviews, restore tests, and training, so evidence exists when it is sampled.
A list of vendors in scope and review records.
A written plan and records of tabletop reviews.
Help answering technical evidence requests during the audit.
Support requests follow our standard help desk response times: 1 business hour for critical issues, 2 hours for high, 4 hours for medium, and 8 hours for low priority requests.
Accounts are removed, but there is no ticket or timestamp that proves it happened on time.
Some laptops or phones that reach company data are not enrolled in management or monitored.
Backups run, but no one has a dated restore test.
No one has reviewed who has administrator or vendor access on a schedule.
Infrastructure and configuration changes happen without a ticket, approval, or rollback note.
Policies exist but do not describe how the company actually works, which is what the auditor tests.
Companies whose customers ask for a SOC 2 report or security questionnaire, including software and technology companies, managed service providers, and service organizations that handle customer data. Already working with a compliance platform or consultant? We work alongside them. Have an in-house IT team? See co-managed IT. Need ongoing security leadership? See our vCISO packages.
Readiness projects are quoted individually. Ongoing controls and support can be added to a managed IT or co-managed IT plan. Audit fees are paid separately to your CPA firm.
No. SOC 2 is an attestation report written by an independent CPA firm. It describes your system and controls and gives the auditor’s opinion on them. There is no SOC 2 certificate, so no one can truthfully say a company is certified.
A Type I report covers the design of your controls at a single point in time. A Type II report covers the design and the operating effectiveness of your controls over a period of time, which means the auditor tests that controls worked consistently. Many customers ask for Type II.
The length is agreed between you and your auditor and is influenced by what your customers expect. We are not aware of a single minimum period published by the AICPA, so ask your auditor and your customers what they require before you plan.
Security is included in every SOC 2 report. Availability, confidentiality, processing integrity, and privacy are optional, and most companies add only the ones their customers ask about. Adding categories adds criteria, controls, and audit work.
A SOC 1 report covers controls relevant to a customer’s internal control over financial reporting. A SOC 2 report covers controls related to security, availability, processing integrity, confidentiality, or privacy and is typically shared under a non-disclosure agreement. A SOC 3 report covers the same subject areas with less detail and can be shared publicly.
Only a licensed CPA firm. Compliance automation platforms can organize evidence and track tasks, but they cannot issue the report. BlueKey IT is not a CPA firm and does not perform SOC 2 audits. The AICPA cautions against vendors that promise fast and easy reports without a licensed, peer-reviewed auditor.
A SOC 2 report includes the auditor’s report and opinion, management’s assertion about the system and controls, a description of the system, and, for a Type II report, the tests of controls performed and their results. Exceptions are reported, so a report can be useful even when it is not perfect.
We can describe what auditors typically ask for and support your evidence requests. Choosing the auditor is your decision. Ask each firm about its SOC 2 experience, its peer review, and how it handles companies at your size.
The auditor reports it as an exception in the control testing results, and management may add a response. Exceptions do not automatically make a report unusable, but repeated or significant failures can affect the auditor’s opinion. This is why we build monitoring and reminders around the controls that are easiest to miss.
Many controls overlap, including access control, encryption, monitoring, backups, and training, so work done for one framework often supports the others. They are separate programs with different outputs and requirements. See our pages on ISO 27001 readiness and HIPAA IT compliance.
Yes. Many companies add SOC 2 readiness to a managed or co-managed IT plan so monitoring, patching, backups, access reviews, and documentation are handled in one place.
Tell us what your customers are asking for. We will explain what SOC 2 readiness means for your environment and put together a clear plan and quote.
Related compliance frameworks: CMMC compliance, HIPAA IT compliance, FTC Safeguards Rule compliance, PCI DSS compliance, and ISO 27001 readiness. See also cybersecurity insurance readiness, cybersecurity and compliance, endpoint security, backup and disaster recovery, and Microsoft 365 and Google Workspace.
Last updated: October 2026. Based on the AICPA 2017 Trust Services Criteria with revised points of focus (2022).