Knowledge items

Nsecure Raises the Bar with SOC 2 Type II

The Gold Standard in IT Security

 

Alexander Snel
CISSP CIPP/E - Information security & Privacy
12 February 2022

Update July 2023: After earning the SOC 2 Type II certification in February 2022, Nsecure has successfully passed another audit. Over six months, our information security measures have been extensively reviewed by an independent external auditor. This certification provides independent assurance that everything is managed to the highest standards. The full report is available upon request. 

Nsecure has recently obtained the SOC 2 Type II Assurance Certification, a rarity in the access and security industry. This ensures that the data processed by Nsecure as an IT security service provider is safer than ever. Alex Smaling, Manager of Business Identity & Cloud Services at Nsecure, states, “This is currently the gold standard in IT security and, in our view, the new minimum. It is our duty to our clients to always stay ahead.” 

‘The art of control’ is Nsecure’s credo. It reflects our commitment to not only delivering standard services but also constantly pushing boundaries, much like a passionate artist. Whether it’s office environments, industrial complexes, hospitals, or outdoor locations, Nsecure’s integrated platforms ensure efficient access while maintaining compliance with laws and regulations. This makes it clear who is allowed where, what tasks they are permitted to perform, and whether all risks have been mitigated. In short, our clients are fully ‘in control’—and now more securely than ever. 

As of February 4, 2022, Nsecure holds the SOC 2 Type II assurance report for all its IT services. But what does this mean and what does it imply for our clients?

Based on Five ‘Trust Service Principles’

Hugo Gerritse, Information Security & Privacy Consultant at Nsecure, explains: “SOC 2 was developed to provide greater insight into IT service quality, ensure its reliability, and periodically assess the effectiveness of processes and measures. SOC 2 is an official auditor’s certification focused on the security of IT services and data processing.”

SOC 2 evaluates the management of client data based on five trust service principles: security, availability, processing integrity, confidentiality, and privacy. Gerritse adds, “SOC 2 Type II ensures that data is handled securely and with respect for privacy. It reassures clients that all necessary steps have been taken to safeguard and protect their data. This certification goes beyond ISO 27001.” 

“The ISO 27001 certification is no longer sufficient for Nsecure when it comes to IT security.”

The key difference between SOC 2 Type II and ISO 27001 is that ISO certification provides a snapshot, assessing data processing at a specific point in time. SOC 2 Type II evaluates the performance of security controls over an extended period and is periodically reviewed by an independent, specially trained auditor. 

The Highest Level of Assurance 

Alex Smaling noted a growing demand among large organizations for greater assurance regarding IT services and data processing. “Nsecure serves the top 500 companies in the Netherlands, many of which process enormous volumes of data. When we saw the need for high IT security standards and a SOC 2 Type II certification, we took action. Less than a year later, we can now offer this highest level of assurance to our clients, making us one of the first in our industry in the Netherlands.” 

“We are one of the first in the Netherlands to achieve this.”

The audits for SOC 2 Type II are thorough. Gerritse explains, “All processes related to data processing must be traceable and effective. This creates an audit trail, which provides reliable evidence of how systems operate. For example, if my calendar notes a meeting with a key partner, I must be able to provide proof, such as minutes, action lists, and follow-up records. SOC 2 Type II requires rigorous documentation and precision across all disciplines, providing a reliable overview of control over all IT processes.” 

Independent Assurance for the Future

Smaling emphasizes that this certification is likely to become as indispensable as ISO certifications in the near future. “Large organizations increasingly need to prove that every link in their data processing chain is secure. Our SOC 2 Type II certification provides immediate assurance to these organizations, saving them time and effort. It guarantees that we meet the highest standards.” 

The art of control

Securing the certification doesn’t mean the work is done. Smaling concludes, “We focus on this every day. Periodic audits ensure we stay sharp, and that’s part of our DNA. ‘The art of control’ is not just a slogan—it reflects our commitment. We are intrinsically motivated to continuously elevate the level of control across all processes. This ensures our services are always future-proof, and our clients remain demonstrably ‘in control’ at all times.” 

Related

Topics

Alexander Snel CISSP CIPP/E - Information security & Privacy
More information

Question

Want to know more about our certifications? Please contact us.