GSE achieves SOC 2 Type I in 3 months with NeenOpal and AWS Marketplace
Learn how AWS and NeenOpal partnered to deliver GSE's SOC 2 Type I attestation across a multi-cloud environment, strengthening its position for expansion into new government markets, all in a single AWS Marketplace transaction.
Benefits
- policies developed and mapped to audit criteria.
- 20+
- of controls confirmed suitably designed
- 99%
Overview
With the goal of expanding beyond its US and Canadian roots, GSE needed a formal security attestation that procurement teams in those markets would recognize.AWS and NeenOpal started with GSE’s growth objective and worked backward to design the compliance program needed to support it.
About GSE
Geoffrey Stephens Engineered IT Inc. (GSE) is a Canadian software engineering firm and the developer of Able Assess, a platform government agencies use to run licensing and permitting programs, covering registration, knowledge testing, inspection, eligibility verification, and fraud review.
Opportunity | One small team vs. a rising compliance bar and multiple clouds to secure
Over the years, GSE has run Able Assess on a mix of cloud providers, work that replaced the monolithic systems legacy government platforms used to rely on. Two providers are especially critical to that stack today: Amazon Rekognition powers facial verification during identity checks, and Cloudflare handles CDN, DNS, and DDoS protection at the edge. That mix leaves a small, engineering-led team managing compliance across multiple cloud environments at once.
Security oversight and compliance can get complex on government initiatives. On one project alone, GSE worked with security officials from four different departments, each applying their own requirements without coordinating with one another. Formal attestation meant absorbing that same scrutiny in one repeatable process, rather than case by case.
While RFPs hadn't yet named SOC 2 attestation as a requirement, GSE anticipated that would change within a few years. Failure to adapt could mean exclusion from bidding altogether.
The company had the operational discipline in practice, built over nearly two decades of serving government customers, but not the documentation or third-party validation to prove it. Building that program across multiple cloud providers was more than the team could staff alone.
"I don't think we could have gotten there in that short period of time without NeenOpal. They had the resources and the experience to get us there and, at the end of the day, I just can't imagine us doing it any other way." Steve Lanteigne, President and CEO, Geoffrey Stephens Engineered IT Inc.
About AWS Partner NeenOpal
NeenOpal Canada Inc. is an AWS consulting partner providing security, compliance, cloud, data, and AI services, including compliance frameworks such as SOC 2, ISO 27001, and ISO 42001.
Solution | NeenOpal led the delivery, AWS made it possible
AWS and NeenOpal started with GSE's objective of winning government contracts in new markets, and designed a program to reach it. That approach is what the AWS Multi-Partner Initiative is built around: pairing complementary AWS partners around a specific customer problem instead of leaving customers to assemble a solution themselves.
AWS connected GSE with two complementary partners: NeenOpal, an experienced consulting partner in ISO and SOC 2 programs, and Sprinto, an ISV that automates compliance monitoring. NeenOpal led the engagement, with Sprinto's platform supporting the work. Both consulting and software were procured through a single AWS Marketplace private offer, landing on GSE's invoice as one consolidated line item, in local currency, with no separate procurement for either partner.
NeenOpal's work went beyond documentation and touched on configuring multi-factor authentication, tightening role-based access controls under least-privilege principles, establishing monthly vulnerability scanning with risk-ranked remediation, and setting up continuous threat-detection monitoring. They also built GSE's risk program, established a subservice organization framework governing GSE's multiple cloud providers, including AWS, under the carve-out method, and stood up a privacy program covering all eight AICPA privacy criteria. Only then did NeenOpal map GSE's practices against the AICPA Trust Services Criteria and write the twenty-plus policies GSE's team lacked bandwidth to produce alone.
Sprinto automated evidence collection across all three of GSE's cloud environments, closing the gap between what GSE was doing in practice and what it could actually prove. GSE started drafting policies in-house, then handed that work to NeenOpal, freeing the team to focus on operational maturity while NeenOpal translated day-to-day practice into audit-ready documentation.
Outcome | A clean solution isn't always purely technical
Within three months, GSE achieved SOC 2 Type I compliance across all five Trust Services Criteria. This milestone strengthens its position to compete for work in Canada, the US, and Europe where compliance attestation is becoming a gatekeeper.
Just as significant was how GSE got there. A single AWS Marketplace transaction, covering both consulting and software, built GSE's confidence in AWS as a platform, not just a vendor for one workflow. GSE now considers NeenOpal a trusted strategic advisor for its next stage of growth. The two companies have already expanded their relationship beyond the initial SOC 2 engagement to explore new opportunities in data and AI.
You learn a lot about a firm when you hand them your entire security posture. We brought NeenOpal in for SOC 2 and we've kept them on since — they're advising us on data and AI now. That wasn't the plan going in.
Steve Lanteigne
President and CEO, Geoffrey Stephens Engineered IT Inc.Did you find what you were looking for today?
Let us know so we can improve the quality of the content on our pages