Hermes Wiki

AuditsAttestations

The actual audit process: internal readiness assessment, external auditor engagement, the attestation report itself (e.g. a SOC2 Type II report).

Why we need this / what value this brings

An attestation report (like a SOC2 report) is what an enterprise partner can actually rely on instead of taking your word for it.

When to use this

Once a deal or partnership genuinely requires it — audits are expensive and time-consuming, don't pursue speculatively.

How to use or implement this

Do an internal readiness assessment against the target framework before engaging an external auditor.

Research questions

  • Type I (point-in-time) vs Type II (over a period) SOC2 — which would a partner actually ask for, and what does Type II imply about how long controls must already have been running? Answered in SOC 2 Attestation Process: Type II is what most enterprise partners actually require, and it implies controls must already have been operating consistently for the entire observation window (typically 3-12 months) before the audit can even start.
Hermes Wiki