Skip to main content
NOVACompliance

Frameworks

Available now

SOC 2

Service organisation reporting against the Trust Services Criteria, used widely in enterprise procurement.

Overview

SOC 2 examines whether a service organisation's controls are suitably designed and, for a Type II report, operating effectively over a period of time.

The examination is performed by an independent public accounting firm against the Trust Services Criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added according to the commitments an organisation makes to its customers.

Because the report describes a period rather than a moment, the evidence record matters as much as the control design.

Who this is for

  • SaaS and technology providers selling to enterprise customers
  • Service organisations that host or process customer data
  • Organisations that repeatedly answer the same security questionnaires

Governance areas

Control environment

Governance structures, accountability and the way management communicates expectations.

Risk assessment

Identifying, analysing and responding to risks that threaten the service commitments.

Monitoring

Ongoing and separate evaluations that detect control deficiencies before an examination does.

Logical and physical access

Who can reach systems and data, how that access is granted, reviewed and removed.

Change and operations

How changes are authorised, tested and released, and how incidents are handled.

How NOVA supports this framework

  • Activate the Trust Services Criteria you commit to and record scope decisions in one place
  • Assign an accountable owner and an operating expectation to every control
  • Collect period-of-time evidence with dates, sources and reviewer validation
  • Track exceptions and remediation before an examination begins
  • Give the examining firm scoped access through the Auditor Portal

Controls and evidence focus

  • Access review records with the reviewer and date retained
  • Change approvals linked to the change management control
  • Incident records with timeline, impact assessment and closure
  • Policy approvals showing who approved which version, and when

Cross-framework reuse

Access control, change management and incident response evidence is reusable against ISO/IEC 27001

Patching, backup and application control evidence overlaps with Essential Eight

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Structure

Trust Services Criteria

Security is always in scope. The remaining four categories are added only where an organisation makes commitments that call for them, and that scope decision is recorded in NOVA before evidence collection begins.

Security

Common Criteria

Protection of information and systems against unauthorised access, disclosure and damage. Required in every SOC 2 examination.

Availability

Availability

The system is available for operation and use as committed. Covers capacity, monitoring and recovery arrangements.

Confidentiality

Confidentiality

Information designated as confidential is protected through its lifecycle, including retention and disposal.

Processing integrity

Processing integrity

Processing is complete, valid, accurate, timely and authorised in relation to the service commitments.

Privacy

Privacy

Personal information is collected, used, retained, disclosed and disposed of in line with stated notice and commitments.

Evidence

Typical evidence held in NOVA

A Type II report describes a period, so each artefact carries the dates it covers, its source and the reviewer who validated it.

ArtefactTypical sourceExpected cadence
User access reviewIdentity provider export or connectorQuarterly
Change approval recordSource control or ticketingPer change
Incident recordIncident tooling or manual uploadPer incident
Vulnerability scan outputScanning toolMonthly
Policy approvalNOVA policy registerAnnual
Vendor reviewNOVA vendor registerAnnual

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

How it runs

Working through SOC 2 in NOVA

  1. Step 1

    Scope

    Decide which criteria categories your commitments require, and record why each was included or excluded.

  2. Step 2

    Design

    Assign an owner and an operating expectation to every control, and close obvious design gaps first.

  3. Step 3

    Observation period

    Collect evidence continuously across the period the report will cover, with dates retained.

  4. Step 4

    Readiness review

    Review exceptions and remediation before the examining firm begins fieldwork.

  5. Step 5

    Examination

    Grant the firm scoped access through the Auditor Portal rather than assembling a request pack by hand.

Questions

SOC 2 questions we are asked

Does NOVA issue a SOC 2 report?
No. A SOC 2 report is issued by an independent public accounting firm. NOVA maintains the control and evidence record that the examination draws on, and gives the firm scoped access to it.
What is the difference between Type I and Type II?
Type I addresses the suitability of control design at a point in time. Type II also addresses operating effectiveness over a period, which is why continuous, dated evidence matters.
Can evidence be reused for other frameworks?
Where a single artefact genuinely satisfies more than one control it can be mapped to both. NOVA shows the mapping so reuse is visible and reviewable rather than assumed.

Pricing

Plans that cover SOC 2

Plans are subscription entitlements on one workspace, so you can start with a single framework and widen scope later.

Launch

AUD $99 /month

A first certification or attestation programme run properly from the start.

  • One activated framework
  • Control ownership and review cadence
  • Evidence mapping and reviewer validation
  • Policy versioning and approval
Compare plans

Growth

Most chosen

AUD $249 /month

Multiple frameworks on one shared control set, with reuse across requirements.

  • Multiple activated frameworks
  • Cross-framework control and evidence reuse
  • Risk register with treatment and acceptance
  • GitHub evidence connector
Compare plans

Professional

AUD $499 /month

Assurance-grade operation with external review workflows included.

  • Everything in Growth
  • Auditor Portal with scoped engagement access
  • Trust Centre publication
  • Asset register and classification
Compare plans

Enterprise

On request

Quoted per organisation against scope, users and assurance requirements.

  • Everything in Business
  • Scope defined per organisation
  • Commercial terms agreed with Eredox
  • Structured onboarding programme
Compare plans

Indicative amounts shown for planning purposes. All published prices require Eredox approval before they are contractually binding.

Getting started

How to start with SOC 2

Four steps from an empty workspace to a reviewable readiness position.

  1. Step 1

    Activate the framework

    Create the workspace and activate SOC 2 so its requirements load into your control set.

  2. Step 2

    Assign control ownership

    Give each control a named owner and a review cadence, so accountability is recorded rather than assumed.

  3. Step 3

    Map and validate evidence

    Attach evidence to the requirements it supports and have a reviewer confirm it is current and sufficient.

  4. Step 4

    Review readiness

    Track gaps and readiness reporting, then decide with your assessor when the programme is ready for external review.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.

Talk to us

Ask about SOC 2

Tell us your scope, timeline and any assessment date you are working to. We will reply with what NOVA covers and what remains with your independent assessor.

NOVA assists with readiness and evidence management. Certification, attestation and regulatory conclusions remain with authorised independent, regulatory or customer-appointed parties.

Forms are not connected yet. Please email compliance@eredox.com.

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.