SOC 2 Type II Compliant: An Enterprise Security Milestone
- Susan Malla

- Jun 25
- 3 min read
Updated: Jun 25
Reflecting on new learnings and discipline in the SOC 2 Type II Compliance process.

Novelty Technology is now SOC 2 Type II Compliant, and for me, this milestone represents more than the completion of an audit. It reflects the security discipline, process maturity, and operational standards we have built into the way we work.
I have seen this journey closely, not only as a compliance process, but as a meaningful effort to strengthen how we manage infrastructure, access, documentation, and internal accountability. SOC 2 Type II compliance gave us a clear standard to work toward, but the value of the milestone comes from the discipline required to meet that standard.
Strengthening the Foundation
Our SOC 2 compliance journey was supported by the foundation we had already built through ISO / IEC 27001 : 2022. That experience gave us a strong understanding of security controls, documentation, process ownership, and continuous improvement.
Because of that foundation, SOC 2 Type II Compliance became an opportunity to refine and strengthen how we operate. We reviewed our systems more closely, improved infrastructure controls, strengthened identity and access management, formalized security policies and procedures, and brought more consistency to how security practices are followed across teams.
A lot of this work happens behind the scenes. It is not always visible in the final product or in day-to-day client conversations, but it plays a major role in how reliable and secure our delivery environment becomes. From device-level discipline to access control, documentation, internal reviews, and team alignment, each layer contributes to a stronger operating standard.
The Work Behind the Milestone
One of the most important parts of this journey was seeing security become more structured across the organization.
SOC 2 Type II compliance is not achieved through a single policy, tool, or audit checklist. It requires consistent technical execution, careful documentation, regular review, and alignment between people, process, and technology. It also requires teams to understand that security is not separate from delivery. It is part of delivery.
That shift matters. When security practices become part of everyday operations, they create stronger internal habits, clearer controls, and a more mature environment for the work we do.
What SOC 2 Type II Compliant Means for Our Clients
For our clients, SOC 2 Type II compliance provides added confidence in how Novelty operates as a technology partner.
It validates that our internal systems and processes are structured, reviewed, and built to support secure, reliable, and accountable delivery. It also shows that our approach to security is intentional, and proactive.
When companies work with Novelty, they are working with a partner that understands the expectations of serious business environments, where trust, data security, accountability, and operational reliability matter.
That is what makes this milestone meaningful. It represents the work behind the certification, but it also reflects the standard Novelty is committed to carrying forward.
Building Forward
SOC 2 Type II compliance is a milestone we are proud of, but it is not the finish line.
Security and compliance require continuous attention. Systems evolve, client needs grow, and standards must keep improving with them. For Novelty, SOC 2 Type II compliance gives us a stronger foundation to keep scaling, strengthening our processes, and serving clients with confidence.
This achievement is a reminder that trust is built through consistent work. It is built through discipline, accountability, and the everyday decisions that shape how we operate.
This milestone reflects what our work here at Novelty continues to stand for: disciplined work, trusted delivery, and a stronger standard carried forward with confidence.
About the Author

Susan Malla
CISO / Sr. DevOps Engineer | Novelty Technology
Connect with Susan on LinkedIn.
