Does an agency need SOC 2? What client reviews ask for
When you work inside client accounts, your access to them is the system a report describes.
Does an agency need SOC 2? Only when a client’s security review asks for one. A SOC 2 is an examination a company commissions from a CPA firm,1 and no law requires an agency to hold one. When a client does ask, the report covers less of their world than you might fear: your own systems, and your access to theirs.
That access is the whole engagement. Who can sign in to which client account, how they got there, and how fast they lose it.
This applies to software development shops and marketing agencies alike. One works in client repositories and cloud accounts. The other works in client ad, analytics and marketplace accounts. The mechanism is identical.
When a client review asks for SOC 2
The request arrives inside a vendor review. A client’s security or procurement team sends a questionnaire, and one of the questions asks for a SOC 2 report. From then on, the report can be a condition of a renewal or a new contract.
The questionnaire may be the client’s own or a standard one. The Cloud Security Alliance publishes the Consensus Assessments Initiative Questionnaire (CAIQ) v4, a set of yes or no questions a cloud customer may put to a provider.2 An agency running client work in the cloud fits that frame closely enough to receive it.
If the review has a date, what to do when a customer asks for a SOC 2 report works backwards from it.
What the system is when you work in client accounts
A system description has to state what the system is and where its boundary sits.3 For an agency, the honest boundary runs between your environment and theirs.
- Inside your boundary
- Your identity provider and laptops. Your password manager, drive and chat, wherever client data or credentials land. Your project tooling. And the access your people hold to client accounts.
- Outside it
- The client’s AWS account, ad accounts, store and repositories. The client owns and operates them, so their controls are the client’s, not yours.
Draw it that way and the report tests what you actually run. Draw it around the client systems and you are asserting controls you do not operate. An auditor will ask you to evidence them, and you cannot.
Contractors and offshore staff
If you staff work with contractors, freelancers or a team in another country, the rule is simple. For the report, anyone who touches a client account is one of your people. They need the same onboarding record, background check where your policy requires one, device rules and offboarding as an employee.
Hiring through an employer of record raises its own scoping question. Contractors and employers of record covers whether the provider is a subservice organization and what evidence you still owe.
Client account access is the central control
Logical access is one of the common criteria every SOC 2 tests.4 For an agency it carries most of the report. Five rules make it testable.
- Keep an inventory. Every client account your people can reach, with the named users on each. If you cannot list them, you cannot review them.
- Use named access, never shared logins. Platforms support this. Google Ads, for one, grants each user one of five access levels from Email-only to Admin.5 A client adds your developer to a repository as an outside collaborator on GitHub.6
- Grant the lowest level that does the job. Read-only for reporting work. Admin only where the engagement needs it.
- Review it quarterly. Walk the inventory, confirm each user still needs each account, and record what you removed. The access review template has the columns.
- Remove it the same day. When someone leaves an engagement or the company, their access to every client account goes with them. The offboarding checklist lists the steps.
One structure deserves its own attention. A manager account linked to several client ad accounts concentrates access: on Google Ads, admins on a linked manager account can manage the client’s campaigns.5 Keep that admin list short, protect it with strong multi-factor authentication, and review it first.
The controls the client keeps
Some controls only the client can run. They decide who from your team gets into their account. They can remove your people at any time. They set their own multi-factor rules. Those belong in your description as complementary user entity controls, written so a client can tell what it has agreed to do.
How to word CUECs shows the difference between a sentence that transfers a duty and one that decorates.
One report, not one per client
A SOC 2 describes your system and the controls you run across every engagement. One report serves every client who asks. A client with a requirement the report does not cover, a data location rule or a named contact for incidents, handles it in the contract or the questionnaire, not in a second examination.
Scope stays narrow on purpose. Security is the one category every SOC 2 includes, and Polara G.R.C. scopes Security only.
Answer the questionnaire first
A report takes time. A review may not wait for it. Answer the questionnaire completely and honestly now, say what is in progress, and give the date your examination is planned. How to answer a security questionnaire has wording for the no SOC 2 yet case.
Through Polara Labs it is audit-ready starting at about a week of focused work. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. A Type 1 report is optional: $2,000 added later, or $4,000 in total with onboarding, with the engagement fee for the independent partner auditor inside it. Polara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
Does a marketing agency need SOC 2?
Does a software development agency need SOC 2?
Is the client's AWS account in the agency's SOC 2 scope?
Do we need a separate SOC 2 report for each client?
What can an agency send before it has a SOC 2 report?
Sources
- SOC 2 Report
- STAR Level 1: Security Questionnaire (CAIQ v4)
- 2018 SOC 2® Description Criteria (With Revised Implementation Guidance, 2022)
- TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy
- About access levels in your Google Ads account
- Adding outside collaborators to repositories in your organization
Get audit-ready without a compliance team.
The readiness assessment is free, with no payment and no card. Onboarding is $2,000 one time, then SOC 2 Type 2 is $600 a month on a 12-month term, and your first SOC 2 Type 2 audit is included in the term. You can be audit-ready starting at about a week.
Take the free assessmentPolara Labs is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.