Software & SaaS

SOC 2 to close the deal. ISO 27001 for European buyers. One platform.

STORM GRC is a SOC 2 compliance platform built for SaaS companies that need to unblock enterprise procurement — without buying a separate tool for ISO 27001, GDPR, or whatever European framework lands on their security questionnaire next. Pre-built control library and automated evidence from your stack.

SOC 2 Type 1 & 2 ISO 27001 GDPR Auto evidence
Trust & Security Updated · 14 May 2026 ACTIVE SOC 2 TYPE 2 ISO 27001 CERTIFIED GDPR COMPLIANT — TRUST SERVICES CRITERIA Security Availability Confidentiality Processing integrity Privacy ✓ COVERED ✓ COVERED ✓ COVERED ✓ COVERED ✓ COVERED
SOC 2 · Evidence Collection Live
Defender · endpoint posture · auto-collected 94%
AWS & Azure · config evidence · auto-collected 100%
Access reviews · Q2 cycle · 3 reviewers pending Action
Recognitions Independent awards for the STORM platform and its industry-specific implementations
Cyber Security Awards 2025 Gold
GoldMaritime cyber framework
Cyber Security Awards 2025 Silver – Integrated cyber services
SilverIntegrated cyber services
Cyber Security Awards 2025 Silver – GRC automation
SilverGRC automation
Compliance Awards 2025 Bronze – Best compliance platform
BronzeBest compliance platform
Cyber Security Awards 2026 Silver – Best Project
Silver 2026Best Project – New Product (Risk Analysis)
Cyber Security Awards 2026 Silver – Best Use of Risk Technology
Silver 2026Best Use of Risk Technology & Platform
Cyber Security Awards 2026 Silver – Best Cybersecurity Risk Management
Silver 2026Best Cybersecurity Risk Management
Cyber Security Awards 2025 Gold
GoldMaritime cyber framework
Cyber Security Awards 2025 Silver – Integrated cyber services
SilverIntegrated cyber services
Cyber Security Awards 2025 Silver – GRC automation
SilverGRC automation
Compliance Awards 2025 Bronze – Best compliance platform
BronzeBest compliance platform
Cyber Security Awards 2026 Silver – Best Project
Silver 2026Best Project – New Product (Risk Analysis)
Cyber Security Awards 2026 Silver – Best Use of Risk Technology
Silver 2026Best Use of Risk Technology & Platform
Cyber Security Awards 2026 Silver – Best Cybersecurity Risk Management
Silver 2026Best Cybersecurity Risk Management
Why SaaS teams adopt STORM

SOC 2 is the foundation for continuous compliance.

Almost every SaaS team adopts a GRC platform under the same pressure: a procurement team asks for SOC 2 in writing. What changes month-on-month is what comes next — ISO 27001 from European prospects, GDPR from EU customers, AI Act, NIS 2 reaching into your supply chain.

PHASE 01

SOC 2 unblocks the deal

Enterprise procurement asks for SOC 2 in writing. Without a report — or at least a credible “in progress” attestation — six-figure deals stall in security review for months.

Type 1 readiness
PHASE 02

Type 2 means continuous

Type 2 covers a 6 to 12-month observation period. Evidence has to be collected continuously, not retrofitted. Spreadsheets and quarterly screenshots stop working in week six.

Continuous evidence
PHASE 03

European buyers raise the bar

EU prospects ask for ISO 27001 and GDPR alongside SOC 2. US-only GRC tools don’t cover them well. You end up with one tool for SOC 2 and a parallel programme for everything else.

ISO 27001 · GDPR
PHASE 04

The next wave is regulation

If your customers are caught by NIS 2 or DORA, that scope flows down to you through their security questionnaire. AI Act and incoming data-protection updates do the same. SOC 2 alone won’t carry you.

NIS 2 · DORA · AI Act
SOC 2 path

Type 1 to ship the deal. Type 2 to keep shipping it.

Most SaaS companies start with SOC 2 Type 1 to unblock the enterprise sale, then move to Type 2 in the same calendar year. STORM is built for both — with the auto-evidence collection that makes Type 2 viable for a small security team.

SOC 2 Type 1

SOC 2 Type 1 confirms that the required controls are in place and suitably designed at a specific point in time. It is usually the fastest route to giving enterprise buyers formal assurance while the longer Type 2 observation period begins.

  • System description finalised and approved
  • Controls mapped to Trust Services Criteria
  • Point-in-time evidence pack ready for the auditor
  • Enables sales conversations with most enterprise buyers

SOC 2 Type 2

SOC 2 Type 2 confirms that controls operate effectively over time. It requires continuous evidence collection, regular reviews and documented handling of exceptions throughout the observation period.

  • Continuous evidence pulled from your MDM, EDR and cloud
  • Access reviews, change tickets, vulnerability scans tracked
  • Quarterly internal audit cadence built into the platform
  • Exceptions tracked with root cause and remediation
  • Next-year auditor walkthrough takes days, not weeks
Coverage

Trust Services Criteria. Plus the frameworks that come next.

STORM’s SaaS configuration ships with the five Trust Services Criteria and a control library cross-mapped to ISO 27001 Annex A, GDPR Article 32 and NIST CSF. One control answers multiple questionnaires — answer once, reuse everywhere.

TSC · CC
Security (Common Criteria)
The required core of every SOC 2 report — control environment, communication, risk assessment, monitoring, logical access, system operations, change management, risk mitigation. Mapped 1:1 to ISO 27001 Annex A.
Required
TSC · A
Availability
SLAs, capacity planning, backup, disaster recovery, business continuity. Recommended for SaaS infrastructure providers and most enterprise-targeting SaaS.
Covered
TSC · C
Confidentiality
Information classification, encryption, retention, secure disposal. Recommended if you handle customer business data subject to confidentiality obligations.
Covered
TSC · PI
Processing Integrity
Completeness, accuracy, validity, authorisation and timeliness of processing. Recommended for SaaS that performs critical transactions for customers (billing, payments, regulated workflows).
Covered
TSC · P
Privacy
Personal information lifecycle — collection, use, retention, disclosure, disposal. Often combined with GDPR coverage; STORM’s data-mapping module handles both.
Covered
ISO
ISO 27001 & Annex A 2022
Full Annex A 93-control set with Statement of Applicability, internal audit, management review and corrective-action evidence — the same control library that powers your SOC 2 Common Criteria.
Covered
EU
GDPR & data mapping
Article 30 ROPA, DPIA workflow, sub-processor register, breach-notification workflow — built into the same workspace, ready for EU customer questionnaires.
Covered
+
NIS 2, DORA, NIST CSF
When your enterprise customers come back with the next regulation, the same control library extends to cover it — without rebuying a GRC platform.
Ready
Continuous evidence rhythm

Type 2 only works if evidence collects itself.

The reason SaaS teams give up on Type 2 mid-period is the same reason they give up on every spreadsheet GRC programme: collecting hundreds of pieces of evidence by hand is unsustainable. STORM runs the rhythm for you.

Daily
Automated

From your stack, into the audit pack

Endpoint posture (Defender / CrowdStrike / Intune / Jamf), cloud config (AWS, Azure, GCP), identity (Entra), vulnerability scans — pulled automatically, mapped to controls, attached to the audit period.

Weekly
Reviewed

Exceptions surfaced, not buried

Anything outside policy — failed control, missed review, unexpected change — is flagged in a weekly digest with an owner and a deadline. No surprises in the auditor’s walkthrough.

Quarterly
Audited

Internal audit baked in

A lightweight quarterly internal audit runs over the rolling period, producing a management report your board can sign off and your external auditor can take into their workpapers.

The SaaS workspace

What your Head of Security actually opens on Monday.

STORM ships with a pre-built SaaS control library, the Trust Services Criteria, ISO 27001 Annex A, GDPR Article 32 — all on the same data model. You don’t run four parallel programmes.

STORM GRC — SOC 2 compliance platform for SaaS companies

Pre-audit gap analysis

Each Trust Services Criterion scored against your current state, with drill-down to specific controls, evidence required, and remediation tasks assigned to owners.

A public-facing trust page showing your SOC 2, ISO 27001 and GDPR status, with gated access to the actual reports. Replaces sending NDA-locked PDFs over email.

Auto-evidence dashboard

Live view of every piece of automated evidence — coverage by control, by integration, by Trust Services Criterion. The dashboard your CTO checks before the auditor walkthrough.

Implementation

Type 1 ready in 8 weeks. Type 2 collecting from day one.

A typical SaaS team (20–250 staff, AWS or Azure stack, a mature engineering culture) hits SOC 2 Type 1 audit-ready in 6–10 weeks. The same setup feeds the Type 2 observation period that follows, without re-keying anything.

30
days

Kickoff & scope

  • System description & Trust Services Criteria scoped
  • Cloud, MDM and identity integrations connected
  • Pre-built control library mapped to your stack
  • Auditor selected (we can recommend EU and US firms)
60
days

Type 1 ready

  • Gap analysis completed, remediation tracked
  • Policies approved, evidence pack ready
  • Auditor fieldwork begins — Type 1 attestation in flight
90
days

Type 2 collecting

  • Type 1 report delivered to customers
  • Continuous evidence rhythm running automatically
  • Quarterly internal audit cadence in place
  • ISO 27001 / GDPR roadmap on the same platform
SaaS implementation snapshot
Cyber Security Awards 2025 Silver – Integrated cyber services Cyber Security Awards 2025 Silver – Integrated cyber services Cyber Security Awards 2025 Silver – Integrated cyber services

From first customer request to ongoing evidence collection

Enterprise buyers often ask for SOC 2 before a deal can move forward. STORM gives SaaS teams one place to manage readiness, control ownership, evidence collection, and the transition from Type 1 to Type 2.

SOC 2 readiness and evidence workflow SaaS security and compliance operations
Operation snapshot
Type 1Readiness workflow
Type 2Evidence collection
3Frameworks on one platform
1Workspace for audit readiness
SaaS FAQ

Questions CTOs and Heads of Security actually ask.

If your question isn’t here, the answer is a 30-minute call — usually faster than email.

Type 1 or Type 2 — which do we need first?
Almost always Type 1 first. Type 1 is point-in-time, takes 6–10 weeks for most SaaS teams, and unblocks the immediate enterprise deal. Type 2 then covers a 6 to 12-month observation period that starts the day Type 1 is complete. Selling on a Type 1 report is normal — most enterprise security reviewers accept it for new vendors, then expect Type 2 at the next annual review.
Which Trust Services Criteria should we choose?
Security (Common Criteria) is required. Most SaaS teams add Availability and Confidentiality because enterprise buyers ask about uptime and data-handling. Processing Integrity matters if you handle transactional or regulated workflows (payments, healthcare, financial). Privacy matters if you collect substantial personal data — often combined with GDPR coverage on the same platform.
Do we need ISO 27001 if we have SOC 2?
European prospects often ask for ISO 27001 specifically. SOC 2 is widely recognised in the US and increasingly in Europe. Many controls and evidence requirements overlap, so STORM lets you run both on the same evidence — without maintaining separate GRC workflows.
How does STORM compare to Vanta, Drata or Secureframe?
For pure SOC 2 in a US-only customer base, those tools are excellent and we’d say so. STORM’s case is stronger when (a) you have EU customers asking for ISO 27001 and GDPR, (b) your customers fall under NIS 2 or DORA and the scope flows down to you, (c) you want an on-premise deployment, or (d) you value an EU-based team. The auto-evidence model is comparable; the framework coverage is broader.
Which auditor should we use?
We work with a number of independent CPA firms across the US and Europe and can recommend a few based on your size, geography and budget. STORM exports evidence in a format auditors expect, so you’re not locked into one auditor — you can switch if the relationship doesn’t work.
What about GDPR for our EU customers?
STORM covers Article 30 ROPA, DPIA workflow, sub-processor register and breach-notification workflow in the same workspace as your SOC 2 controls. When an EU customer’s security questionnaire asks about Article 32 technical measures or your sub-processor chain, you answer from the same data model that backs your SOC 2 report.
How is STORM priced for a SaaS company?
STORM is licensed per organisation, scaled by user count and the frameworks you need. There are no per-document, per-control or per-report fees. We provide a fixed quote after a 30-minute scoping call so the year-one cost is clear before you commit.
Certifications

ICT PROTECT holds internationally recognised certifications across quality, security and assurance.

ISO 9001 · ISO 27001 · ISO 22301 · ISO 27701 ISAE 3000 Type I Cyber Essentials Certified and Cyber Essentials Plus
Get started

Unblock the enterprise deal. Then the next four.

A 30-minute call with someone who has shipped SaaS GRC programmes — not a generic vendor demo. You leave with a written 8-week path to SOC 2 Type 1 audit-readiness, whether you buy or not.

Book a 30-min demo

EU-based team. No sales pressure.