ProTraining
ProTraining delivers comprehensive corporate training remotely, ensuring your employees are equipped with the knowledge and skills they need to protect your organization and adhere to industry standards.

SOC 2 Compliance Track
Upon completing of the SOC 2 Compliance training program, each participant will possess the skills and knowledge to support any business organization in establishing an Information Security program that leads to a SOC 2 certification.
This unique training is unlike any training offered to employees and managers in information security. Successful ‘graduates’ will become coveted amongst companies for their specialized knowledge of compliance, information security, and privacy.
Having employees with this specialized knowledge also helps companies keep information safe. This training assists in raising the level of information security in the companies they work.
In this course, you will learn about the SOC 2 framework, the benefits of the certification, and the importance of compliance and information security.
- 22 hours of instructor-led classes
- Online instruction
- SOC 2 Certificate: Level 1
- 2500 per participant

Leonardo Soto, PMP, ITIL, GRCP
Leonardo is an IT management professional focused on cybersecurity, compliance and digital transformation. His expertise includes IT project management, digital transformation, and preparing companies for information security audits, such as SOC 2, ISO 27001, and HIPAA.
- Understanding SOC 2
- Project Scope
- Risk assessment, Policies and Controls
- Costs and choosing the right auditor
- Preparing for a SOC 2 audit
Upon completing this course, each participant will possess the skills and knowledge to support any business organization in establishing an Information Security program leading to a SOC 2 certification.
This unique training is unlike any training offered to employees and managers in information security. Successful ‘graduates’ will become coveted amongst companies for their specialized knowledge of compliance, information security, and privacy.
Having employees with this specialized knowledge also helps companies keep information safe. This training assists in raising the level of information security in the companies they work for.
Day 1 - Introduction to SOC 2
Course Work
8:00 AM to 12:30 PM – Instructor Led
Day 1 introduces the participants to the SOC 2 framework standard and the importance of information security. The participants will also explore the impact of SOC 2 on a business operation and how its components help protect information assets.
Learning Outcomes
- Understanding what is SOC 2
- The benefits of SOC 2 for any organization
- The main components of SOC 2
Unit 01 – What is SOC 2, and why does it matter?
- The SOC 2 Standard definition
- The role of the American Institute of Certified Public Accountants (AICPA)
- The goal of SOC 2 Audits
Unit 02 – Why is SOC 2 important for your business?
- Compliance considerations
- Information security considerations
- Business considerations
Unit 03 – What Are the Components of SOC 2?
- Policies
- Controls
- Evidence
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Describe the impact a SOC 2 certification can have on your business
- List the information security policies your company currently has
Day 2 - SOC 2 Structure
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 2, the participants will understand the difference between SOC 2 Type 1 and SOC 2 Type 2 audits. We will define the four Trust Service Criteria (TSC) and how SOC 2 addresses trust for different products and services. By understanding the TSCs, the participants can scope a SOC 2 project according to the company’s needs.
Learning Outcomes
- Difference between the two types of SOC 2 audits
- What are the four Trust Service Criteria
- Scoping a SOC 2 project
Unit 04 – SOC 2 Type 1 Versus Type 2
- SOC 2 Type 1 definition
- SOC 2 Type 2 definition
Unit 05 – Trust Service Criteria (TSC)
- Availability
- Processing integrity
- Confidentiality
- Privacy
Unit 06 – Scoping your SOC 2 Project
- Define your landscape
- Define your controls
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Discuss which SOC 2 Type is more appropriate for your company
- Make a list of the types of personal information your company collects
- Which Trust Service Criteria should be included in your audit?
Day 3 - Risk Assessment, Policies, Controls, and Evidence Collection
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 3, the participants will learn to identify risks that could expose information assets. They will also learn the different threat vectors and vulnerabilities, such as vendors’ supply chains. We will discuss mitigating, accepting, transferring, or avoiding risks. Finally, we will see how robust policies and controls are essential to the information security program. We will see how evidence is collected for a SOC 2 audit.
Learning Outcomes
- Risk identification, classification, and prioritization
- Responding to risks
- Creating information security policies
- Understanding the SOC 2 controls
- How to collect evidence
Unit 07 – The SOC 2 Risk Assessment
- SOC 2 Risk Assessments must have clearly defined objectives
- Identifying and assessing risks against the organization’s objectives
- Identifying and evaluating the criticality of information assets
- Threats and vulnerabilities from vendors and other parties
- Responding to risks: Mitigate, Accept, Transfer, Avoid
Unit 08 – Creating SOC 2 Policies, Controls and Evidence Tasks
- Writing and updating your policies
- Designing and implementing controls
- Evidence collection
- SOC 2 Type 1 and Type 2 evidence collection
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Find examples of Information Security policies
- List some of the controls that are important to your company.
Day 4 - SOC 2 Costs and Auditor Selection
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 4, we will discuss the cost of a SOC 2 audit and how the cost is distributed in the project’s three phases. The participants will also learn about the auditor’s role and how to select one. We will also explore cost savings tools, such as automated evidence collection.
Learning Outcomes
- Understand SOC 2 costs involved
- How long does it take to complete a SOC 2 audit
- The role of an auditor
Unit 09 – SOC 2 Costs Explained
- Phase 1: SOC 2 Risk Assessment cost
- Phase 2: SOC 2 Audit Readiness cost
- Phase 3: The SOC 2 Audit cost
Unit 10 – How Long Does SOC 2 Take?
- Without automation
- With automation
Unit 11 – How to Select the Right Auditor
- Criteria for Choosing an Auditor
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Read and be prepared to comment on Section 1 of the sample report supplied
Day 5 - The SOC 2 Audit
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 5, the participants will learn about the Readiness Assessment as the first step in preparing for a SOC 2 audit. They will also know the difference between preparing for a SOC 1 and a SOC 2 audit. We will review a SOC 2 Report and learn how to read and interpret its five sections.
Learning Outcomes
- How to prepare for a SOC 2 audit
- Interpreting the SOC 2 Report
Unit 12 – Your SOC 2 Audit: What to Expect
- The Readiness Assessment
- Preparing for a SOC 2 Type 1 Versus a SOC 2 Type 2 Audit
Unit 13 – What Happens After I Get My SOC 2 Report?
- Understanding the SOC 2 Report
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Read and be prepared to comment on Section 1 of the sample report supplied
This course teaches you how to work towards your SOC 2 attestation, including how to prepare for an audit on your own or with the help of a consultant and how to use compliance automation software.
- 22 hours of instructor-led classes
- Online instruction
- SOC 2 Certificate: Level 2
- 2500 per participant

Leonardo Soto, PMP, ITIL, GRCP
Leonardo is an IT management professional focused on cybersecurity, compliance and digital transformation. His expertise includes IT project management, digital transformation, and preparing companies for information security audits, such as SOC 2, ISO 27001, and HIPAA.
- Working towards SOC 2 in-house
- Compliance software primer
- Finding the right auditor
- Using your SOC 2 certificate
- SOC 2 Certification Project Plan
Upon successfully completing this course, each participant will possess the skills and knowledge to support any business organization in developing a project plan for a SOC 2 certification.
This unique training is unlike any training offered to employees and managers in information security. Successful ‘graduates’ will become coveted amongst companies for their specialized knowledge of compliance, information security, and privacy.
Having employees with this specialized knowledge also helps companies keep information safe. This training assists in raising the level of information security in the companies they work for.
Day 1 - Getting Ready For a SOC 2 Audit
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 1, the participants will learn the challenges of preparing for a SOC 2 audit in-house, what resources they need, and how this activity will impact the company’s day-to-day operations. On the other hand, we will explore hiring a consultant to lead the project and how this could speed the process and reduce costs.
Learning Outcomes
- Can we do it in-house, or do we need a consultant?
Unit 01 – Can You Get Ready For Your SOC 2 Audit on Your Own?
- Important Reminders For Working Towards SOC 2 Internally
- Pros of Preparing for Your SOC 2 Audit in-House
- Cons of Preparing for Your SOC 2 Audit in-House
Unit 02 – Is Using a SOC 2 Consultant Right For You?
- Benefits of Preparing for your SOC 2 Audit Using a Consultant
- Challenges of Preparing for your SOC 2 Audit Using a Consultant
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Analyse the pros and cons of preparing for SOC 2 in-house
Day 2 - Compliance Software Primer
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 2, the participants will learn the pros and cons of automating the SOC 2 Compliance process. We will analyze the criteria for selecting SOC 2 Compliance software and services. We will lead a discussion on the need for continuous compliance and the different roles and responsibilities to achieve it.
Learning Outcomes
- Working with the Policy Module
- Collecting, uploading and associating evidence to controls
Unit 03 – What Is Compliance Software? Should You Use It?
- Benefits of SOC 2 Compliance Automation
- Downsides of Automation of SOC 2
- Criteria for Selecting SOC 2 Compliance Software
Unit 04 – Continuous Compliance
- Why You Need Continuous Compliance
- Roles and Responsibilities in a Continuous Compliance Scenario
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Define roles and responsibilities for SOC 2 Compliance in your company
Day 3 - Finding the Right Auditor
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 3, the participants will learn about auditors. We will explore the different types of auditing firms and the benefits and issues when engaging with an auditor. We will also address the recertification process.
Learning Outcomes
- Understanding of the auditing landscape
- Criteria to choose the right auditor
Unit 05 – The Auditing Firms Landscape
- Benefits and Issues Engaging The Big 4 Auditing Firms
- Benefits And Issues Engaging A Mid-Tier Auditing Firm
- Benefits and Issues Engaging A Boutique Auditing Firm
Unit 06 – Finding The Right Auditor
- Which Auditor Is Right For You?
- Criteria For Finding The Right Auditor
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Review your cyber insurance policy to find cost saving opportunities with a SOC 2 Certification
Day 4 - Using Your SOC 2 Compliance Certificate
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 4, the participants will learn how to use the SOC 2 Certificate to win more business. We will show how the information and evidence collected during the SOC 2 process can be used to respond faster to RFP questionnaires and to lower the cost of cyber insurance policies. Finally, we will talk about keeping the SOC 2 certification current and how to prepare for a SOC 2 recertification.
Learning Outcomes
- Using the SOC 2 Certificate as a marketing tool
- Responding to RFPs and cyber security questionnaires with the information gathered during the certification process
- How to approach the recertification process
Unit 07 – Using your SOC 2 compliance certificate
- The SOC 2 Certification seal
- RFPs and cyber security questionnaires
- Building trust with a SOC 2 Certification
Unit 08 – Preparing for the next cycle
- When To Recertify For SOC 2
- Steps For Recertification
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Review your website to plan for a “SOC 2 Certified” page
- Determine the best time of the year to recertify the company
Day 5 - SOC 2 Certification Project Plan
Course Work
8:00 AM to 3:30 PM – Instructor Led
On Day 5, the participants will utilize all of the knowledge acquired throughout the training to create a project plan for SOC 2 Type 2 certification.
Learning Outcomes
- SOC 2 Certification project plan
Unit 09 – SOC 2 Certification Project Plan
- The Business Case
- Defining a Scope
- Identifying Risks
- Reviewing and Re-Writing the Policies
- Creating a Budget
- Finding an Auditor
- Marketing with your SOC 2 Certification
Participants will learn to use the advanced functionalities of the Scrut Compliance Automation platform, such as policy management, evidence task automation, risk and vendor assessment, security awareness training, audit preparation and execution, and security posture disclosure. Participants will leverage the Scrut Compliance Automation platform’s to demonstrate their compliance automation expertise.
We will work with the Scrut Compliance Platform in detail to create a complete compliance automation project.
- 22 hours of instructor-led classes
- Online instruction
- SOC 2 Certificate: Level 3
- 2500 per participant

Leonardo Soto, PMP, ITIL, GRCP
Leonardo is an IT management professional focused on cybersecurity, compliance and digital transformation. His expertise includes IT project management, digital transformation, and preparing companies for information security audits, such as SOC 2, ISO 27001, and HIPAA.
- Understanding the Scrut Compliance Automation platform
- Working with Policies and Evidence Tasks
- Risk and Vendor management
- Working with Team Members and Training
- Getting ready for an audit and showcasing the security posture
Upon the successful completion of this course, each participant will possess the skills and knowledge to work with the Scrut Compliance Automation platform.
This unique training is unlike any training offered to employees and managers in the area of information security. Successful ‘graduates’ will become coveted amongst companies for their specialized knowledge of compliance, information security, and privacy.
Having employees with this specialized knowledge also helps companies keep information safe. This training assists in raising the level of information security in the companies they work.
Day 1 - Introduction to the Scrut Compliance Automation Platform
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 1, the participants will get an overview of the Scrut Compliance Automation platform. They will also understand the different cybersecurity frameworks available, such as SOC 2, ISO 27001, GDPR, HIPAA, etc. The material also shows the attendees how to work with the controls associated with each compliance framework and the Unified Controls Framework (UCF), a tool to manage controls common to all cybersecurity frameworks.
Cyber Security frameworks are guidelines for building plans to help mitigate risks and threats to data and privacy. Controls are technical or administrative (i.e., policy or procedure) countermeasures designed to protect the desired outcomes of a security or privacy program. Controls protect the confidentiality, integrity, and availability of information systems.
Learning Outcomes
- Understand the scrut.io platform, frameworks and controls.
Unit 01 – The Compliance Automation Platform (CAP) Dashboard
- Understanding the CAP Dashboard
- Demonstrating examples of how to create an audit calendar using the CAP
Unit 02 – Cyber Security Frameworks and Controls
- Cyber Security Frameworks Overview
- Understanding the cybersecurity framework dashboard
- Editing and deleting a cyber security framework requirement
- Marking Cyber Security Framework Requirements as Out of Scope
- Exporting cyber security framework requirements
- Downloading cyber security framework compliance report
- Understanding controls & the Unified Controls Framework
- Editing and deleting a control
- Linking and unlinking framework requirements to a control
- Linking and unlinking artifacts to a control
- Linking and unlinking controls to a framework requirement
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Explore the dashboard
- Export the SOC 2 framework requirements
- Edit a control
- Link a SOC 2 requirement to a control
Day 2 - Policies and Evidence Tasks
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 2, the participants will be introduced to the Policies and Evidence Tasks dashboards. These are the two most important modules for creating a centralized compliance hub.
Learning Outcomes
- Working with the Policy Module
- Collecting, uploading and associating evidence to controls
Unit 03 – Policy
- What is a Policy?
- Understanding the Policy Dashboard
- Assigning a policy to an assignee
- Understanding the policy approval workflow
- Setting a policy review cycle
- How to manage policy content (create/upload, edit, delete)
- Linking and unlinking a policy to controls
- Marking a policy as relevant or not relevant
Unit 04 – Evidence Tasks
- What are the Evidence Tasks
- Understanding the Evidence Task dashboard
- How to upload examples of an evidence task
- Assigning Evidence Tasks to an assignee
- Understanding Evidence Task approval workflow
- Setting examples of an Evidence Task review cycle
- How to remove examples of an Evidence Task
- Examples of linking and Unlinking an Evidence Task to Controls
- How to mark an Evidence Task as relevant or not relevant
- Exporting Evidence Tasks
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Explore the Policy Dashboard
- Create and upload a policy
- Explore the Evidence Task Dashboard
- Upload examples of an evidence task
- Export examples of an evidence task
Day 3 - Risk Management and Vendor Management
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 3, the participants will learn about Risk Management and Vendor Management. Understanding these concepts is critical for protecting the company’s participation in the information supply chain.
Learning Outcomes
- Understanding of Risk Management tools in scrut.io
- How to manage and mitigate vendor-associated risks
Unit 05 – Risk Management
- Understanding the Risk Management Dashboard
- What is a Risk Register
- Customizing the Risk Register
- Managing entries in the Risk Registry (create, edit, delete)
- Assessing a risk
- Linking and unlinking controls to a risk
- Understanding risk mitigation tasks
- Managing risk mitigation tasks (create/upload, edit, delete)
- Unified Mitigation Task Tab
- Linking unlinking controls to a mitigation task
- Closing or Adding a residual risk
- Understanding Risk Approval Workflow
- Exporting risk register
Unit 06 – Vendor Management
- Understanding Vendor Dashboard
- Understanding Vendor Management?
- Configuring Vendor custom fields
- Configuring Vendor custom categories
- Adding a vendor
- Understanding vendor details page
- Editing and Deleting a vendor
- Editing POC Details
- Vendor Risk Assessment Workflow
- Creating a vendor questionnaire template
- Creating a vendor questionnaire manually
- Importing vendor questionnaire template
- Sending a questionnaire to vendor
- Evaluating vendor response
- Managing vendor documents
- Adding a vendor document
- Deleting a Document
- Downloading a Document
- Vendor Discovery and Onboarding
- Creating vendor intake form
- Submitting vendor intake form from the employee portal
- Assessing vendor intake forms submitted by employees
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Explore the Risk Management Dashboard
- Examples of exporting the Risk Register
- Explore the vendor management dashboard
- Create an example of a vendor intake form
Day 4 - Team Member Management
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 4, the focus is on people management in the compliance automation platform. The participants will gain an understanding of the People Module and how employees interact with the policies and security training.
Learning Outcomes
- Working with Team Member Modules
- Creating security awareness training tasks
- Understanding the Team Members Portal
Unit 07 – The Team Member Module
- Understanding the People Module
- Understanding the People Module Dashboard
- Team Members Management
- Team Members overview
- Adding new team members to the People Module
- Viewing individual team member records
- Uploading onboarding and offboarding documents
- Sending manual training reminders to team members
- Terminating and offboarding team members
- Resetting an Offboarded team members
- Resetting Terminated a team member
- Marking a team member as ‘Person’ or ‘Non Personnel’
- Security Awareness
- Understanding Security Awareness
- Creating a security awareness campaign
- Configuring a quiz
- Editing a security awareness campaign
- Deleting a security awareness campaign
- Cloning a Campaign
- Extending a security awareness campaign
- Viewing a security campaign
- Automated Evidence Collection for Completed Security Campaigns
Unit 08 – Team Member Portal
- Team Member Portal Overview
- Team Member Portal Login Guide
- Accepting Policies in the Team Member Portal
- Completing Security Training
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Explore the Team Member Dashboard
- Explore the Security Awareness Dashboard
- Clone a Security Awareness campaign
- Explore the Team Member Portal
Day 5 - The Audit Center and the Trust Vault
Course Work
8:00 AM to 12:30 PM – Instructor Led
On Day 5, we will focus on the platform’s auditing and marketing tools. Participants will have first-hand experience with the Audit Center and the Trust Vault. The Audit Center allows auditors to be invited and manage the auditing process. The Trust Vault is the public-facing information site that advertises the organization’s security posture.
Learning Outcomes
- Using the Audit Center to manage the external audit process
- Configuring and publishing the Trust Vault
Unit 09 – The Audit Center
- Understanding Audit Center
- Creating an audit
- Understanding the audit details page
- Adding an auditor to an audit
- Editing and Deleting an audit
- Marking an audit completed
- Managing audit findings
- Creating a finding in an audit
- Adding artifacts to an audit finding
- Creating Corrective Action from Audit Finding
- Linking and unlinking controls to an audit finding
- Editing and deleting an audit finding
- Exporting Audit center Findings
- Understanding Audit Finding Closure Workflow
- Managing audit requests
- Creating a request in an audit
- Adding artifacts to an audit request
- Creating Corrective Action from Audit Requests
- Creating Corrective Action from Audit Finding
- Linking and unlinking controls to an audit request
- Editing and Deleting an audit request
- Exporting Audit center Requests
- Understanding Audit Requests Closure Workflow
Unit 10 – The Trust Vault
- Understanding the Trust Vault
- Understanding the Trust Vault dashboard
- Customizing the Trust Vault
- Adding compliance to the Trust Vault
- Adding security items to the Trust Vault
- Adding subprocessors to the Trust Vault
- Requesting access to Trust Vault
- Granting and Rejecting access to the Trust Vault
- Editing NDA for Trust Vault access
- Accessing the audit log for the Trust Vault
Activities and Exercises
2:00 PM to 4:00 PM – Independent Work
- Explore the Audit Center
- In the Trust Vault, do the following:
- Customize the Trust Vault with your company’s assets (logo, address, etc.)
- Edit the NDA
- Add at least two items in the following categories:
- Compliance
- Security
- Subprocessors
- Review the audit log to see entries for the actions you just performed.
Ready to Start?
Unlock the freedom to work from anywhere with ProServices and transform your operations with ease and confidence.
