ValorTech Logo
Solutions
Services
Partners
Resources
Company
Get Started
Get Started
Client Portal
(414) 410-9440
By Business Need
Identify Gaps in My Cybersecurity Plan
Identify Gaps in My IT Plan
Fulfill Compliance Assessments & Requirements
Replace Current IT Provider
Manage Business Continuity
Manage Complex Cybersecurity Technologies
Enhance & Scale My Internal IT Environment
By Industry
/api/icon/file/icon_healthcare.svg
Healthcare
/api/icon/file/icon_legal.svg
Legal
/api/icon/file/icon_Insurance.svg
Insurance
/api/icon/file/icon_finance.svg
Finance
/api/icon/file/icon_manufacturing.svg
Manufacturing
/api/icon/file/icon_education.svg
Education/NPO
/api/icon/file/icon_government.svg
Government
Solutions Hero
Save 10% With Cyber Warranty

ValorTech’s Cyber Warranty helps clients qualify for up to a 10% discount on cybersecurity insurance.

Learn More

Have an urgent need?

>>

Consult with an Expert
Discover ValorTech
We’re not your average MSSP. Born from a security-first mindset and built by people who care deeply about doing the right thing, ValorTech blends technical excellence with real-world purpose. From veteran roots to community impact, we lead with integrity—and back it up with bold, reliable tech that just works.
Learn more
/api/icon/file/icon_leadership.svg

Our Leadership

Meet our Visionaries

/api/icon/file/icon_culture_values.svg

Culture & Values

What Drives Us

/api/icon/file/icon_news_media.svg

News & Media

Latest Updates

/api/icon/file/icon_social_impact.svg

Social Impact

Rooted in Service

Contact Us
Have a challenge? Let’s talk—we’re the kind of partner who actually shows up and solves it.
Consult with an Expert
Current Client Support
Careers
Do work that matters—join a team that backs each other, builds boldly, and gives a damn. At ValorTech, we invest in our people the same way we invest in our tech—with purpose, trust, and a long-game mindset.
Learn more
Consult with an Expert
Services Header
Cybersecurity

Cybersecurity

Battle-tested and trusted to keep your business secure when it matters most.

Managed IT Services

Managed IT Services

Proactive, security-first IT support built to scale with your business.

IT Consulting

IT Consulting

Strategic guidance from engineers who actually understand your world—and speak your language.

Cloud Solutions

Cloud Solutions

Custom cloud environments optimized for agility, compliance, and growth.

Apple First Environments

Apple First Environments

Certified Jamf support for Apple-first environments — because great tech deserves great service.

Microsoft 365

Microsoft 365

Secure, streamlined collaboration powered by expert Microsoft 365 deployment and management.

Resources
/api/icon/file/icon_blog.svg

Blog

Proactive, security-first IT support built to scale with your business.

/api/icon/file/icon_downloadassets.svg

Downloadable Assets

Practical tools, checklists, and guides built to make your next move smarter and faster.

/api/icon/file/icon_trustcenter.svg

Trust Center

Where transparency meets accountability—see how we keep your data secure, always.

Featured Articles
Article

Why Troop Salute Hits Home for Me

Article

5 End-of-Year IT Quick Wins: The C-Suite Q4 Checklist

Have an urgent need?

>>

Consult with an Expert

SOC 2 Compliance & What You Need to Know

SOC
Compliance
avatar
Jessica Wolfe

Director of Operations

August 23, 2024

Table of contents:

Why Get Compliant?
What is SOC 2?
What is the Difference Between SOC 2 Type I and SOC 2 Type II?
What Was the Attestation Process?
Who Did We Partner With?

Why Get Compliant?

SOC 2 was not a mandatory security framework for ValorTech—we were not under a legal or regulatory requirement to be compliant. Achieving a SOC 2 attestation is a way for our organization to showcase our dedication to cybersecurity and privacy. For years, ValorTech has operated under formal security controls and processes, but it’s incredibly helpful to get an outside opinion on those practices.

In the competitive field of managed security services, SOC 2 compliance can differentiate an organization from its competitors; it can instill client confidence, build stakeholder trust and help an organization remain ahead of regulations. The successful realization of our SOC 2 Type II report verifies the measures we have in place to protect client’s data.

Retaining an annual SOC 2 Type II audit will confirm our commitment to ongoing assessment and improvement of our security posture as our organization continues to grow.

What is SOC 2?

SOC 2 is a cybersecurity compliance framework and audit report developed for service and technology providers that handle client data.

 A SOC 2 audit scrutinizes an organization's policies, procedures and information protection systems across five Trust Services Criteria categories:

Security, Availability, Processing Integrity, Confidentiality and Privacy. Designed by the American Institute of Certified Public Accountants (AICPA), SOC 2 offers a verified method for evaluating and certifying an organization’s security infrastructure.

The proof is a SOC 2 report—a living document providing interested parties and clients information about an organization’s commitment to security.

What is the Difference Between SOC 2 Type I and SOC 2 Type II?

SOC 2 Type II is not just a one-time attestation, but a continual compliance journey. It assesses the effectiveness of security processes by observing operations over a period of up to 12 months, offering a more comprehensive view of an organization’s security practices. In contrast, with a SOC 2 Type I audit, an organization’s cybersecurity controls are assessed at a single point in time, usually shortly after they’ve been implemented.

What Was the Attestation Process?

In early 2023, we began evaluating our organization's current security practices, policies and procedures against the SOC 2 framework with the goal of becoming compliant by mid-2024.

Secureframe, an all-in-one compliance framework platform, helped us automate the collection of our controls evidence, centralize documentation and identify areas of non-compliance. The evidence collection process included but was not limited to the following: creating policies, training personnel on security and privacy requirements, scanning and securing cloud services, documenting network configurations, documenting and verifying logical access, identifying disaster recovery and incident response plans, and assessing and managing vendor risks.

Secureframe’s team of experts conducted a readiness assessment to determine if we had met the necessary criteria and controls to undergo a full audit. An impartial auditor was then engaged to assess the evidence. Once it was determined that ValorTech’s service commitments and system requirements were achieved in accordance with the trust services criteria, we received our SOC 2 Type II report.

Who Did We Partner With?

Our audit was completed by Johanson Group, LLP, a licensed CPA firm and trusted partner in comprehensive audit and security compliance services. Johanson Group, LLP helped us navigate the complexities of certification seamlessly. Sprocket Security, Inc. assisted us in meeting the penetration testing requirements. Sprocket Security, Inc. employs a blend of attack surface management and humans to detect change and perform testing. Continuous penetration testing is performed, though only an annual penetration test is required for SOC 2 compliance. ValorTech has a rigorous change management process established for tracking and mitigating any findings.

Secureframe acts as a central repository to track and hold evidence for our entire compliance program, providing us a holistic view into our security infrastructure. Native integrations with our tech stack and Secureframe’s automated control testing capabilities collect evidence to continuously monitor compliance to the SOC 2 framework. This helps us remain audit-ready and ensures our data is well protected.

Want to Learn More?

If you’re interested in becoming SOC 2 compliant, email [email protected] to learn more about our compliance consulting services.

Stay Ahead with Our Expert Insights
Get the latest IT security strategies, business tips, and tech updates — straight to your inbox.

Related Articles

  • When AI Agents Become Cyberattackers: What the OpenAI - Hugging Face Incident Means for BusinessesAI agents are changing cybersecurity. See what the OpenAI–Hugging Face incident means for businesses and how leaders can reduce AI-related risk.
  • 10 Cybersecurity Questions Every Business Leader Should Ask in 2026Can your business answer these 10 cybersecurity questions? Learn what leaders should know about access, backups, phishing, vendors, response plans and more.
  • What the 2026 Verizon DBIR Means for Small and Mid-Sized BusinessesThe 2026 Verizon DBIR reveals rising vulnerability exploitation, ransomware and mobile attacks. Learn five actions businesses should take now.

Powered By

ValorTech Logo
(414) 410-9440

N85W16186 Appleton Ave
Menomonee Falls, WI 53051

Follow Our Social Media

Solutions

HealthcareLegalInsuranceFinanceManufacturingEducation/NPOGovernment

Services

CybersecurityManaged IT ServicesIT ConsultingCloud SolutionsApple First EnvironmentsMicrosoft 365

Service Areas

IT Support in WisconsinCloud Solutions in Wisconsin

Resources

BlogDownloadable AssetsTrust Center

Partners

Partners

Company

About ValorTech
Our Leadership
Culture & Values
News & Media
Social Impact
Careers

Partners

Partners

Contact Us

Consult with an ExpertCurrent Client Support

Contact Us

Consult with an ExpertCurrent Client Support

ValorTech Insights

Get the latest IT security strategies, business tips, and tech updates—straight to your inbox.

© 2026 All Rights Reserved

Privacy PolicyTerms of Service