Home › FAQ

SOC 2 frequently asked questions

Answers about SOC 2 in Ukraine: what it is, how long it takes, what it costs, who issues the report, how it differs from ISO 27001.

How long does a SOC 2 project take?
Type 1 usually takes 3–6 months from kick-off to report depending on process maturity. Type 2 adds an observation period of 3–12 months (most often 6) during which controls must operate continuously.
How much does SOC 2 cost in Ukraine?
Two components: readiness (BALTUM) and the audit (CPA firm). The audit fee is fixed from five inputs: headcount, nature of the service, infrastructure, data types, report type and TSC categories. As a guide, a Type 1 audit for a small company ranges from a few thousand to ~20k USD; Type 2 is higher. Fill in the form for an exact figure.
Who issues the SOC 2 report?
Only a licensed CPA firm (USA). The BALTUM group has its own US-registered CPA firm with licensed CPA auditors — it performs the examination and signs the report. Readiness is delivered by a separate consulting team to preserve auditor independence.
Can we go straight to Type 2 and skip Type 1?
Yes. If controls have been operating for several months you can go straight to Type 2. Many companies get Type 1 first to close a deal and Type 2 six months later.
Can we order only ISO 27001, GDPR or NIS2 without SOC 2?
Yes. Every service is available separately: ISO 27001 certification by the accredited body, a GDPR package, Cyber Essentials or NIS2 compliance. Packages simply save time and budget through shared controls.
Do we need SOC 2 if we have ISO 27001?
It depends on your customers. US buyers usually ask for SOC 2, European ones for ISO 27001. The standards overlap by roughly 70–80 %, so the second one is much cheaper than the first.
Which clouds do you work with?
AWS, Google Cloud, Azure, Hetzner, DigitalOcean, plus hybrid and on-prem environments. Inherited cloud-provider controls are reflected in the responsibility matrix.
How does SOC 2 differ from SOC 1 and SOC 3?
SOC 1 covers controls relevant to a customer's financial reporting (e.g. payment processors). SOC 2 is about data security and privacy. SOC 3 is a short public version of SOC 2 without test details.
What are the TSC?
Trust Services Criteria — five AICPA categories: security (mandatory), availability, processing integrity, confidentiality, privacy. The company chooses which to include in scope.
Is a SOC 2 report from BALTUM accepted in the US?
Yes. The report is issued by the BALTUM group's US-registered CPA firm through licensed CPA auditors under AICPA standards (SSAE 18 / AT-C 205). That is the only requirement for recognition.
Do we need to travel to the US or host the auditor on site?
No. The audit is remote: video calls, read-only system access, evidence via a secure portal.
What language are the report and documents in?
The SOC 2 report is in English. Policies and procedures can be in Ukrainian or English; an English version is required for the audit.
Do you work with companies registered in Diia.City or abroad?
Yes. Legal form and country of registration do not affect SOC 2. The contract is with Baltum Büroo OÜ (Estonia) — convenient for payment from any jurisdiction.
What is a bridge letter?
A management letter covering the gap between the end of a Type 2 report period and today (usually up to 3 months), confirming no material changes to controls.
SOC 2

Get a fixed-fee SOC 2 quote

Five fields — exactly what our CPA auditors need to quote a fixed audit fee. We reply within one business day.

By submitting you agree to our privacy policy.