Skip to main content
Cybersecurity ops

Lead SOC 2 Manager

Lead SOC 2 Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Compliance officers responsible for establishing and managing SOC 2 compliance programmes
  • IT professionals and information security risk managers seeking deeper expertise in SOC 2 requirements
  • Members of audit and compliance teams involved in SOC 2 readiness assessments and internal audits
  • Security analysts and incident response coordinators responsible for protecting the security, availability, and privacy of information systems
  • Managers and consultants advising organisations on SOC 2 implementation
  • Executives and business leaders who need to understand SOC 2 compliance to support organisational risk management
  • Professionals working to establish information security controls that satisfy SOC 2 criteria

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no background in information security or compliance, as the course assumes working knowledge of both areas
  • Professionals seeking a purely technical cybersecurity course with no compliance or audit component
  • Those looking only for a high-level executive overview of SOC 2 without practical implementation content
  • Professionals whose organisations are not subject to SOC 2 scrutiny and who have no interest in assurance frameworks

What you'll be able to do

  • 1Explain the fundamental concepts and principles of the SOC 2 framework and its Trust Services Criteria
  • 2Interpret SOC 2 requirements from an analytical perspective to assess organisational compliance gaps
  • 3Initiate and plan the implementation of security measures aligned with SOC 2 requirements using recognised methodologies
  • 4Support an organisation in operating, maintaining, and continually improving security controls that meet SOC 2 criteria
  • 5Apply risk management principles to develop and maintain policies that support SOC 2 compliance
  • 6Plan and coordinate incident response activities consistent with SOC 2 requirements
  • 7Prepare an organisation to undergo a SOC 2 certification audit by an independent auditor

Day by day

Day 1Introduction to the SOC 2 Framework
  • SOC 2 Origins and Purpose

    This module explains why SOC 2 was developed, how it fits within the broader AICPA assurance landscape, and what a SOC 2 report conveys to stakeholders.

  • Trust Services Criteria Overview

    Participants are introduced to the five Trust Services Criteria categories: security, availability, processing integrity, confidentiality, and privacy.

  • SOC 2 Report Types and Scope

    This module distinguishes between Type I and Type II reports and explains how organisations define the scope of their SOC 2 engagement.

By end of day

  • Explain the purpose of SOC 2 and the significance of each Trust Services Criteria category
  • Differentiate between SOC 2 Type I and Type II reports and their implications for stakeholders
  • Define the scope of a SOC 2 programme within an organisational context
Day 2Risk Management and Policy Development
  • Risk Assessment in a SOC 2 Context

    Participants apply risk management principles to identify, analyse, and prioritise risks relevant to the Trust Services Criteria.

  • Developing SOC 2 Policies and Procedures

    This module covers how to design and document policies and procedures that satisfy SOC 2 requirements and can withstand audit scrutiny.

  • Gap Analysis Techniques

    Participants practise conducting a gap analysis to compare current security controls against SOC 2 requirements and identify remediation priorities.

By end of day

  • Conduct a risk assessment aligned with SOC 2 Trust Services Criteria
  • Develop policies and procedures that are evidence-ready for a SOC 2 audit
  • Perform a gap analysis and produce a prioritised remediation plan
Day 3Implementing SOC 2 Controls and Incident Response
  • Designing and Implementing Security Controls

    This module guides participants through selecting and implementing technical and administrative controls that address SOC 2 requirements.

  • Availability and Processing Integrity Controls

    Participants examine specific controls required to meet the availability and processing integrity criteria of the SOC 2 framework.

  • Incident Response Planning Under SOC 2

    This module covers how to design and operate an incident response programme that aligns with SOC 2 security and availability requirements.

By end of day

  • Select and implement controls that address the full set of applicable Trust Services Criteria
  • Design incident response processes that satisfy SOC 2 requirements and support audit evidence collection
  • Map implemented controls to specific SOC 2 criteria for documentation and reporting purposes
Day 4Auditing, Reporting, and Continual Improvement
  • Internal Audit and Readiness Assessments

    Participants learn how to plan and execute internal audits and SOC 2 readiness assessments to identify control gaps before an external audit.

  • SOC 2 Audit Evidence and Documentation

    This module addresses how to collect, organise, and present audit evidence that demonstrates control effectiveness to an independent auditor.

  • Continual Improvement of the SOC 2 Programme

    Participants explore how to use audit findings, monitoring results, and performance metrics to drive ongoing improvements in the SOC 2 compliance programme.

By end of day

  • Plan and conduct an internal SOC 2 readiness assessment
  • Organise and present audit evidence to support an efficient external audit process
  • Establish a continual improvement cycle for the SOC 2 compliance programme
Day 5Review and Exam Preparation
  • End-to-End SOC 2 Scenario Review

    Participants work through a realistic scenario covering the complete SOC 2 implementation and audit preparation lifecycle.

  • Key Domain Consolidation

    This session revisits the core competency domains from the training to reinforce understanding ahead of any external assessment.

By end of day

  • Apply the full SOC 2 compliance lifecycle to a realistic organisational scenario
  • Identify personal knowledge gaps to address before sitting any external certification exam

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of SOC 2 Framework
  • Domain 2: SOC 2 criteria
  • Domain 3: Planning of SOC 2 requirements implementation
  • Domain 4: Implementation of SOC 2 requirements
  • Domain 5: Monitoring of security measures and preparing for SOC 2 certification audit
  • Conducting a gap analysis on a SOC 2 program
  • Developing an information security policy
  • Assessing and treating information security risks
  • Implementing SOC 2 controls
  • Measuring and reporting SOC 2 performance and metrics

Certification Rules and Policies

  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

Educational approach

  • This training course combines theoretical concepts with best practices for implementing the SOC 2 framework.
  • The training course contains essay-type exercises and multiple-choice quizzes, some of which are scenario-based.
  • The participants are encouraged to interact and have meaningful discussions with each other while working on quizzes and exercises, creating a collaborative learning environment.
  • The quiz format closely mirrors that of the certification exam, ensuring participants are well-prepared for the exam.

Buyers always ask

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

What is a SOC 2 gap analysis and why is it covered in this course?+

A gap analysis compares an organisation's existing security controls and processes against SOC 2 requirements to identify areas that need improvement before an audit. It is one of the foundational steps in any SOC 2 implementation project.

The course includes gap analysis techniques because they are a practical tool that participants can apply immediately in their organisations to prioritise remediation work and build a roadmap toward audit readiness.

Who performs the actual SOC 2 certification audit, and is it covered by this training?+

A SOC 2 audit is conducted by an independent licensed CPA firm, not by PECB or Cyber Academy. The audit results in a report issued by that third-party auditor.

This training prepares participants to implement and manage the controls and evidence collection processes that an organisation needs before inviting an external auditor. The audit itself is outside the scope of the course.

Is this course relevant for organisations that are just beginning their SOC 2 journey?+

Yes. The course addresses initiation and planning of SOC 2 implementation alongside more advanced topics such as auditing and continual improvement, making it useful for participants at the early stages of a compliance programme.

Participants should nonetheless bring a working knowledge of information security practices and compliance standards, as the course does not start from first principles of information security.

How does this course address both security and the other Trust Services Criteria?+

Security is the foundational Trust Services Criterion that applies to every SOC 2 engagement, and it receives substantial coverage throughout the course. The training also addresses the availability, processing integrity, confidentiality, and privacy criteria through dedicated modules on control design and implementation.

Participants leave with the ability to map controls to each applicable criterion and to support an organisation in demonstrating compliance across the full scope of its chosen Trust Services Categories.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.