Guides
SOC 2 evidence for US virtual assistant agencies facing client reviews
Virtual assistant agency operations: AICPA trust services criteria, access controls, vendor questionnaires and evidence US clients expect in SOC 2 reviews.
What to take away
- Virtual assistant agency operations face buyer security reviews that ask for a SOC 2 report or a credible readiness story, not a finished audit.
- The AICPA trust services criteria clients raise first are security, availability, confidentiality and privacy; processing integrity matters mainly for transaction work.
- Four policies, written in a week, cover most requests: access control and MFA, incident response, vendor management and data retention.
- Least privilege plus MFA on every assistant account is the single control that resolves the most questionnaire items.
- A client-facing evidence pack of policies, screenshots, subprocessor lists and a control matrix shortens review cycles from weeks to days.
- NIST Cybersecurity Framework and CISA Cyber Essentials give a free baseline that maps cleanly to SOC 2 readiness for small agencies.
What enterprise buyers actually ask for in a security review
A US enterprise buyer rarely opens with "send your SOC 2 report." Procurement usually sends a security questionnaire first, then asks for evidence behind the answers. For a virtual assistant agency, that evidence covers how assistants reach client systems, where client data is stored and who can see it.
Most reviews land in one of three buckets. A short vendor security questionnaire of 40 to 80 questions. A full third-party risk assessment run by the client's security team. Or a contract rider that adds security, confidentiality and breach-notification terms to your retainer agreement, which is why the clauses you sign early matter as much as the controls you run later.
The contract should cover security obligations, data handling and breach notice, because those terms set the evidence you will be asked to produce.
The buyer's real question is simple: can an outsider reach our systems through your assistants? Answer it with named controls, not assurances. Enterprise clients in California, Texas, New York, Illinois and Washington often apply stricter vendor rules than their smaller peers, so assume the toughest questionnaire you have seen is the baseline.
Timing matters too. Reviews surface during onboarding, at annual renewal, and whenever the client adds a regulated workload. Build the evidence pack once and refresh it quarterly. That turns a recurring scramble into a routine task your operations lead can run.
The AICPA trust services criteria that come up first
The AICPA trust services criteria are the control categories behind a SOC 2 report. Five exist: security, availability, processing integrity, confidentiality and privacy. Enterprise clients weight them differently depending on what your assistants touch.
Security is always in scope. It covers logical access, change management, risk assessment and incident response. Availability covers uptime and recovery commitments. Confidentiality covers how client data is protected and destroyed. Privacy covers personal information handling. Processing integrity applies when assistants process transactions, such as invoice entry or order handling.
| Trust services criterion | What the client asks | Evidence a small agency can produce |
|---|---|---|
| Security | Who can access our systems, and how is access controlled? | Access control and MFA policy, user access reviews, onboarding and offboarding records |
| Availability | What happens when your tools or staff go down? | Business continuity and incident response plans, uptime notes from core tools |
| Confidentiality | Where does our data live, and who can see it? | Data classification and retention policy, subprocessor list, device standards |
| Privacy | How is personal data handled and deleted? | Privacy notice, data subject request procedure, retention schedule |
| Processing integrity | Are transaction tasks complete and accurate? | Task checklists, QA sampling, error logs |
A SOC 2 report is an audit opinion on those criteria. A small agency does not need the report to win the first enterprise retainer, but it does need an answer for each criterion. Say plainly which criteria are in scope, which are not, and what you do instead.
If the client asks for the report itself, explain the path: readiness, gap remediation, then a Type I point-in-time opinion followed by a Type II period opinion. Most buyers accept a readiness statement plus evidence for year one, then expect the Type II at renewal. Put that timeline in writing so procurement can plan around it.
Policies a small agency can write in a week
You do not need a compliance department. You need four short policies, each two to four pages, approved by the owner and dated. Write them in plain American English. Auditors and client reviewers read for coverage, not prose.
- Access control and MFA policy: who approves accounts, what MFA method is required, how access is reviewed quarterly, and how it is removed on the last day of work.
- Incident response policy: what counts as an incident, who is notified, how clients are told, and the breach-notification window you committed to in the retainer.
- Vendor and subprocessor policy: how a new tool is reviewed, what data it may hold, and where the approved vendor list lives.
- Data classification and retention policy: what is confidential, where it may be stored, and when it is deleted after a client leaves.
Add a one-page acceptable use addendum for assistants covering personal devices, password managers, screen sharing and AI tools. State that client data never goes into a public AI tool. That single line answers a question now appearing in most 2026 questionnaires.
Keep the policies where staff actually work. A policy stored in a folder nobody opens fails the walkthrough test reviewers use: they ask an assistant to show the rule, not the owner. Link each policy from your onboarding checklist so a new assistant reads it on day one, a step that belongs in the documented account setup you already run for each client.
Access controls, MFA and least privilege for assistant accounts
Access is where most small agency reviews fail. Reviewers ask for a user list, then compare it to the client's own logs. Gaps show up fast: shared logins, stale accounts, admin rights nobody needs.
The core rules are simple. Every assistant gets a named account, never a shared one. MFA is required on email, the client's systems and your password manager. Access is granted per client, per system, at the lowest role that lets the work get done. Admin rights sit with one or two people.
Run a quarterly access review. Export the user list from each client system, confirm each person still works on that account, and remove anyone who does not. Keep the signed review as evidence. Offboarding is the same list in reverse, completed within one business day of the last shift.
Password managers and a single sign-on layer reduce the number of credentials an assistant holds. Where the client's system supports it, use their SSO and role assignment rather than issuing a separate login. Document the choice in your evidence pack so a reviewer sees the control, not just the outcome.
Device standards belong here too. Require disk encryption, automatic screen lock and current patches on any machine that touches client data. If assistants use personal devices, say so and show the standard they must meet. Reviewers accept personal devices with controls; they reject silence.
Vendor questionnaires and subprocessor evidence
Your assistants run on other companies' software. Every tool that touches client data is a subprocessor, and buyers want the list. Keep one page with the vendor name, purpose, data categories, hosting country and security page link.
Expect two questionnaire directions. Inbound questionnaires come from clients assessing you. Outbound questionnaires go to your vendors so you can answer client questions without guessing. Send the outbound version once a year and store the replies.
The vendor security questionnaire you build should ask each tool: Do you support MFA and SSO? Where is data stored? Do you hold a SOC 2 report or ISO 27001 certificate? What is your breach-notification commitment? What is your subprocessor policy? Those five answers cover most client follow-ups.
US payment and contractor-payroll rails such as Stripe and Gusto are common subprocessors for agencies paying assistants and collecting retainers. List them, describe the data they hold, and link their security pages. If a client objects to a vendor, you need a substitute ready, so note one alternative per critical tool.
Keep the vendor list current. A stale list is worse than a short one, because a reviewer who finds an unlisted tool questions everything else. Review it when you add software, which is also when your agency software choices should pass the same test.
Mapping NIST and CISA basics to SOC 2 readiness
You do not need to choose between frameworks. NIST and CISA material gives you a free, credible baseline, and the AICPA criteria give you the reporting structure clients recognize.
The NIST Cybersecurity Framework organizes controls into identify, protect, detect, respond and recover functions. Use it as your gap checklist. The Cybersecurity Framework | NIST is the baseline most US reviewers recognize, and mapping your policies to its functions shows coverage without a paid consultant.
CISA Cyber Essentials is written for small organizations and covers the practical steps buyers probe: patching, MFA, backups, phishing training and incident plans. The Cyber Essentials | CISA steps are a sensible first pass for an agency facing its first enterprise review.
Privacy deserves its own pass. Assistants often handle client customer names, emails and order details, so privacy controls belong in scope even when the client does not ask. The Privacy Framework | NIST helps you separate privacy risk from security risk and document handling rules for personal data.
NIST publishes broader guidance that frames what buyers expect from vendors. The Cybersecurity and privacy | NIST resources are useful when a client's security team cites a specific control family and you need a neutral reference. When you cite a control in your evidence pack, point to the underlying publication rather than a blog summary; the Publications | NIST catalog is the citable source reviewers accept.
Map once, then reuse. Build a spreadsheet with three columns: AICPA criterion, NIST function, and your control with an evidence link. That single artifact answers most of a security questionnaire preparation effort and shows a reviewer you understand both languages.
Preparing a client-facing evidence pack
An evidence pack is a folder you can send in one link. It should let a reviewer verify your answers without a call. Keep it current, version it, and store it behind access control so only named staff can edit it.
- Company overview: legal name, state of registration, owners, locations, headcount
- Security narrative: two pages describing systems, data flows and assistant access
- Policies: access control and MFA, incident response, vendor management, data retention
- Control matrix: AICPA criterion, NIST function, control description, evidence link
- Subprocessor list: vendor, purpose, data categories, hosting country, security page
- Access review records: latest quarterly review and offboarding samples
- Incident summary: any incidents in the last 12 months, or a statement that there were none
- Insurance certificate: cyber liability coverage limits and carrier
- Contacts: security contact, escalation path and response commitments
The narrative is the part reviewers read first. Describe how a client request becomes work, which systems hold client data, and how an assistant's access ends. Two pages is enough. Keep screenshots small and labeled with the date they were captured.
Run a tabletop once a year. Pick a scenario, such as a lost laptop or a phishing click, and walk through your incident response steps with the team. Record the date, attendees and findings. Reviewers treat a completed tabletop as strong evidence that the policy is real.
Finally, align the pack with your client rhythm. Refresh evidence at each quarterly access review, and attach the current summary to your monthly report, which already follows a one page, five blocks format clients read. When renewal season arrives, the renewal and reporting playbook keeps the security summary and the commercial conversation on the same schedule.
Common questions
Do we need a SOC 2 report to win enterprise retainers? Not for the first contract. Most US buyers accept a readiness statement, policies and evidence, then expect a Type II report by the first or second renewal. Put that timeline in writing during procurement.
How long does SOC 2 readiness take for a small agency? With four policies, MFA everywhere and a control matrix, most small agencies can produce a credible pack in four to eight weeks. The audit itself depends on the observation period the client wants.
Which trust services criteria should we include? Security always. Add confidentiality and availability if clients ask about data handling and uptime. Add privacy when assistants handle personal data, and processing integrity only for transaction work.
What if an assistant uses a personal device? Allow it with written standards: disk encryption, screen lock, patching and no local client files. Document the standard and show it in the evidence pack.
How often should we refresh the evidence pack? Quarterly, alongside the access review. Refresh the subprocessor list whenever you add or drop a tool, and update the incident summary after any event.
Can we reuse client questionnaires instead of writing our own? Use them as input, but write your own outbound version for vendors. Reusing a client's form leaves gaps about your specific tools and data flows.

