BY FULTON MAY SOLUTIONS
Your business runs on technology. Your data is everywhere: in the cloud, on devices, on servers, stored, processed, transmitted. The systems that differentiate you are built on this technology.
Your security posture determines whether you can move forward or whether you are spending energy just protecting what you already have.
This is why System and Organization Controls (SOC) reporting has become something regulators, customers, and competitors expect from IT providers, and why the SOC 2® Type II report in particular has become the standard serious buyers look for. This page explains what the report actually verifies, why it matters more today than it did five years ago, and what it should change about how you evaluate an IT partner.
What SOC 2 Type II Actually Means
A SOC 2 Type II examination is an independent assessment that verifies your IT provider’s security controls work, over a full 12-month period, in real operating conditions.
The examination is performed by an independent CPA firm. They have no stake in the outcome.
A Type I report is a point-in-time assessment: “At this moment, these controls exist and are suitably designed.”
A Type II report is a durability test: “These controls existed and operated effectively, consistently, over the past 12 months.”
If you are evaluating IT providers, the Type II report is what matters. Anyone can design a control. Far fewer can prove it worked, every day, for a year.
Why SOC 2 Type II Matters
Threats are faster and more targeted.
Attackers are not looking for any vulnerability. They are looking for vulnerabilities in your specific systems that affect your specific business. Defending against that requires security controls that are constantly tested, verified, and updated, not controls that were documented once and never revisited.
Every industry now requires proof of security.
Healthcare, finance, legal, manufacturing: regulators and customers will not accept promises. They want third-party evidence that security controls actually work. A SOC 2 Type II report is that evidence.
Data is both your liability and your asset.
You cannot grow without protecting your data. You cannot comply without managing your data. You cannot make decisions without trusting your data. When your IT provider has completed a SOC 2 Type II examination, an independent firm has verified that the controls protecting that data work.
From Keeping Systems Running to Helping Your Business Grow
Ten years ago, IT providers were measured by uptime and response time. “Did my system stay up? Did you fix it fast?”
Today, those are minimum expectations. The real question is: “Is my business growing?”
Your technology either works for your business (automating processes, enabling faster decisions, protecting competitive advantage) or it consumes resources just to maintain the basics.
That requires a different kind of IT partnership, one where security is not an add-on. It is foundational, built into how your IT environment is designed, managed, and verified.
A provider that has completed a SOC 2 Type II examination has proven they understand this.
What the SOC 2 Type II Report Means at Fulton May Solutions
Fulton May Solutions has completed a SOC 2 Type II examination and received a SOC 2 Type II report on the controls relevant to the security, availability, and confidentiality of the systems we use to deliver services.
This means:
- Every security control we operate has been independently examined.
- Those controls were verified to operate effectively over a full 12-month period.
- We practice the same security discipline in our own business that we recommend to clients.
- We are accountable not just to our clients, but to an independent CPA firm that examined us.
- Our security approach is verified, not theoretical.
What This Means for Different Businesses
Healthcare Organizations
In healthcare, patient data protection is non-negotiable. HIPAA compliance is foundational, but HIPAA does not specify how you protect data.
When your IT provider has completed a SOC 2 Type II examination, the how has been independently verified. Your patient data is managed by a provider whose security controls have been examined and reported on by a third party.
For healthcare: regulators and patients get evidence that patient data is protected by controls that worked for 12 consecutive months.
Financial Services Organizations
Financial institutions are under constant regulatory scrutiny. Regulators do not just want to know you are compliant today; they want to know you will be compliant tomorrow.
A SOC 2 Type II report from your IT provider addresses this directly. It shows the provider maintained consistent, effective security controls over time, under changing conditions.
For financial services: regulators see proof of security controls operating effectively across a full year, not a snapshot.
Legal Services Firms
In legal services, confidentiality is not just a best practice. It is a professional obligation, and attorney-client privilege is fundamental to the legal system.
When your IT provider has completed a SOC 2 Type II examination, your client information is managed by a provider whose confidentiality controls have been independently examined and verified.
For legal services: courts, bar associations, and clients see evidence that privileged communications are protected by controls that hold up over time.
Manufacturing Organizations
Modern manufacturing depends on connected systems. Production technology, inventory systems, supply chain visibility: all of it runs on IT. When IT fails, production stops.
When your IT provider has completed a SOC 2 Type II examination, your production systems are managed by a provider whose availability and operational security controls have been independently verified.
For manufacturing: an independent firm verified, over 12 months, that the controls keeping your production systems available actually work.
What Makes SOC 2 Type II Different
There are many security frameworks and assessments out there: ISO 27001, HIPAA compliance programs, PCI DSS, the SOC 2 Type I report.
What makes the SOC 2 Type II report different?
Duration. Most assessments are point-in-time. A SOC 2 Type II examination covers 12 months. The auditor tested whether controls operated effectively across the entire period.
Real conditions. Controls are examined in the provider’s actual operating environment, not a test scenario. If something failed in the real world during the period, the auditor saw it.
Independence. The examination is performed by a CPA firm with no stake in the outcome. Their job is to test whether the controls work.
Scope. SOC 2 examinations cover controls relevant to security, availability, processing integrity, confidentiality, and privacy, the exact dimensions regulated industries need protected.
This is why the SOC 2 Type II report has become the standard buyers expect from IT providers in regulated industries.
The Cost of Working with Unverified Providers
Here is what happens when you work with an IT provider whose controls have not been independently examined:
You are trusting their word that security controls work. You are assuming their security practices match what they say they are. You are betting that when they talk about compliance, they actually meet those standards.
That is a risk.
A data breach affects your business, your customers, your reputation, and your regulatory standing. If your IT provider’s controls were never verified, you are the one explaining to regulators and customers why you trusted an unexamined provider.
A SOC 2 Type II report removes that guesswork. An independent firm examined the controls and reported on whether they worked.
How Fulton May Solutions Approaches Security
Our SOC 2 Type II report means our approach to security is verified. Here is what that looks like in practice:
We build security into how we work, not on top of it.
Security is not bolted onto our service after the fact. Every system we implement, every process we design, every recommendation we make: security is built in from the start.
We measure success by whether your business is growing.
Systems staying up is the baseline. Data accuracy is the baseline. The goal is helping your business move forward.
We hold ourselves to the same standards we recommend to clients.
We run our own business with the same security discipline we bring to yours, and we submitted that discipline to independent examination.
We invest in security continuously.
A SOC 2 Type II examination covers 12 months of operating evidence. Maintaining it means updating controls, testing systems, and improving processes constantly, not once a year.
What This Means for Your Business
If you are evaluating IT providers, a current SOC 2 Type II report should be on your requirements list. Regulators, customers, and competitors expect it. More importantly, it is proof that an IT provider takes security seriously enough to let an outsider test it.
An IT provider with a SOC 2 Type II report has demonstrated they can:
- Protect your data and systems consistently over time.
- Operate effectively in real conditions, not ideal ones.
- Meet control standards across security, availability, and confidentiality.
- Hold themselves accountable to third-party examination.
- Make security foundational to how they operate.
Questions to Ask Any IT Provider
Whether you are evaluating Fulton May Solutions or anyone else, these questions separate providers with verified controls from providers with good marketing:
- Have you completed a SOC 2 Type II examination? If the answer is “we are certified,” that phrasing alone tells you something. SOC examinations produce reports, not certificates.
- What period did the report cover? Anything less than a sustained operating window is a Type I report, a snapshot, not a track record.
- Which trust services categories were in scope? Security is the required core. Availability, processing integrity, confidentiality, and privacy are optional. The scope tells you what was actually examined.
- Who performed the examination? It should be an independent, licensed CPA firm, not an internal review or a self-assessment tool.
- Will you share the report under NDA? A provider with a real report will share it with a serious prospect. Hesitation here is a signal.
The Path Forward
If you run a healthcare organization, financial services firm, legal practice, or manufacturing operation, you need an IT provider you can trust, not just today, but next year and the year after.
The SOC 2 Type II report behind Fulton May Solutions means that trust is verified.
If you are evaluating IT providers and a SOC 2 Type II report is already a requirement, or if you are realizing it should be, let’s talk about what that looks like for your business.
Industry-Specific Resources
Your industry has specific compliance and security needs. We have built resources for each:
- SOC 2 Type II for Healthcare Organizations
- SOC 2 Type II for Financial Services
- SOC 2 Type II for Legal Services
- SOC 2 Type II for Manufacturing
About Fulton May Solutions
Fulton May Solutions is an IT partner for healthcare, financial services, legal, and manufacturing organizations. We have completed a SOC 2 Type II examination, which means the security controls behind our services have been independently examined and reported on.
Founded in 2003. More than 20 years in business, 800+ projects delivered, and a 98% customer satisfaction score verified through ConnectWise.






