At a Glance
Fixed Fee IT has completed its 7th consecutive SOC 2 Type II audit with no exceptions for the fifth year running. This third-party audit verifies that our security controls, processes, and systems meet rigorous and independently verified security standards. For our clients in wealth management, accounting, legal and financial industries, it means your IT partner’s security posture is verified, documented, and defensible. Most managed IT service providers have never been audited. We do it every year, on purpose.
Why We Do This Every Year
SOC 2 audits are not easy. They are not cheap. They take a mountain of time. And nobody requires us to do them.
We do it anyway.
We do it because the clients we serve, wealth management firms, accounting practices, law firms, operate in environments where “trust us” is not an acceptable answer. Their clients demand accountability. Their regulators expect it. Their cyber insurers are requiring it.
When you partner with Fixed Fee IT, you’re not just taking our word that we take security seriously. You have proof in a third-party verified report that says so.
That’s the point.
What Is SOC 2 Type II?
SOC 2 Type II (System and Organization Controls 2) is an independent security framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates hundreds of controls, policies, and processes to verify that a company’s security practices are properly designed and actually work over time.
Every year, an independent CPA firm puts our controls, policies, and processes to the test and produces a report with their findings. Our clients can use that report as documented proof that we are delivering on our promise to keep them protected and productive. More than peace of mind, it serves as evidence to their own clients, investors, and regulators that an organization partnered with Fixed Fee IT does not compromise its obligations to security.
Learn more about SOC 2 Type II compliance
What Seven Consecutive Years Actually Means
Any company can have a good year. Seven consecutive years means something different.
It means the controls aren’t performative. It means the processes are real, documented, and followed, not just before an audit, but every day, year after year. It means that when the auditors show up, we’re not scrambling. We’re ready, because we’re always operating this way.
Most managed IT providers have never been audited at all. For those that have, a single audit represents a single data point. Seven consecutive years is a track record.
Over the course of a year, our commitment to this audit adds up to over a thousand hours across the organization. Not in a sprint before the audit, but spread across every team, every month, every process. That’s what it actually takes.
What It Means If Your Business Is in a Regulated Industry
If your firm operates in a regulated environment, wealth management, accounting or legal, your IT partner’s security posture is directly connected to your own compliance obligations.
Here’s what our SOC 2 certification means in practical terms:
- Vendor due diligence. When your clients, partners, or regulators ask how you vet your technology partners, you have a documented answer. Our SOC 2 report is available upon request.
- Cyber insurance. Insurers are scrutinizing the security practices of IT vendors that touch sensitive client data. Our annual certification gives your insurance broker and underwriter something concrete to work with.
- Regulatory alignment. Our controls are designed to align with frameworks relevant to the industries we serve, including FTC Safeguard rules, SEC Reg S-P, and IRS Safeguarding Taxpayer Data or IRS P4557 requirements for financial firms and data protection expectations for legal practices.
Client Story
One of our wealth management clients was preparing for the amended SEC Regulation S-P requirements. We helped them think through the security-focused parts of that work. Part of that process required increased oversight and review of the partners involved in protecting sensitive client information. They needed more than a general promise that their IT partner took security seriously. This client was able to use our SOC 2 Type II report to show that the controls behind their technology support had been independently audited and tested over time. It gave them a documented answer to a question every regulated firm eventually has to answer: who has access to sensitive client data, and how do you know they can be trusted?
The Team Behind It
This doesn’t happen without the people who show up every day and do the work.
SOC 2 compliance isn’t a project you complete. It’s a culture you maintain. Every member of the Fixed Fee IT team contributes to it, through the processes they follow, the controls they uphold, and the discipline they bring to every client engagement.
Seven years of clean audits is a team achievement. We’re proud of it.
Our Auditor
Fixed Fee IT’s audit was performed by KirkpatrickPrice, a licensed CPA firm providing assurance services to over a thousand clients across North America, South America, Asia, Europe, and Australia.
Ready to Work with an IT Partner You Can Verify?
If your firm needs managed IT and cybersecurity support from a provider whose security posture is independently verified, not just claimed, we’d like to talk.
