Flat per firewall
£199/month per firewall, plus the VM you run it on. No per-GB data-processing charge — the bill stops scaling with traffic.
The SOC 2 Common Criteria land on the firewall in three places: logical access, system monitoring and change management. Enforza enforces scoped egress, streams your audit logs to your own SIEM, and checks every rule change against a bundled SOC 2 (Type II) pack, advising or blocking a rule that would break a control before it reaches a firewall.
Enforza helps you satisfy and evidence the SOC 2 Common Criteria that touch the firewall. It is a network security control, not a SOC 2 certification or an auditor. Your attestation is issued by a licensed CPA firm across the whole Trust Services report.
SOC 2 attests against the AICPA Trust Services Criteria. The Common Criteria — the Security category, always in scope — hold the logical-access, monitoring and change points a firewall directly supports. Here is what they ask, and the Enforza control that lines up with each.
Logical access controls must protect information assets from unauthorised access. Enforza policies default-deny on every section, with explicit allows you scope by network, port and hostname — a documented, enforced network access boundary rather than an implicit open path.
Access from sources outside the system boundary must be restricted. A guardrail catches an inbound allow from 0.0.0.0/0 with no hostname or restricted source — advise it, or block the publish in enforce mode, so the perimeter stays scoped.
The transmission and movement of information must be restricted to authorised destinations. Broad egress to 0.0.0.0/0 is scoped with an L7 (FQDN / SNI) matcher rather than a bare-port passthrough, so every wide egress rule names where data is allowed to go.
System components must be monitored to detect anomalies. Enforza streams egress audit logs to your own SIEM — never through Enforza's cloud — so you hold the who / what / where-it-went record that an auditor asks for as CC7 monitoring evidence.
Changes to infrastructure must be authorised, tested and approved. Run Enforza as policy-as-code through a pipeline, or in the console — either way every rule change is checked against the attached SOC 2 pack, and the result is recorded as an audit event you can show an auditor.
Criteria references are to the AICPA Trust Services Criteria Common Criteria (CC series). The optional Availability, Confidentiality, Processing Integrity and Privacy categories, and the many Common Criteria outside a firewall's scope, are marked accordingly in the control catalogue.
The SOC 2 (Type II) pack is one of 25 bundled framework packs covering 210 firewall-applicable controls. Attach it to the policy that governs your network and every change is checked.
SOC 2 (Type II) ships as one of 25 bundled framework packs. Attach it to the policy that governs your network — whole pack, or cherry-pick the Common Criteria points that map to firewall rules.
Run the pack in advise mode to surface violations without blocking, bring your rules into line, then switch to enforce so a rule that breaks a control is rejected before any firewall sees it.
Every check, advise warning and enforce block is recorded, and egress logs stream to your SIEM. When your auditor asks how network access is controlled and monitored, you show what was evaluated, what failed, and where traffic actually went.
A SOC 2-scoped network usually means a managed firewall plus a NAT gateway — a per-hour endpoint fee (often duplicated per Availability Zone) and a per-GB data-processing charge that scales with every byte inspected (on Azure and Google Cloud, a separately-metered NAT layer stacks on top). Enforza is one flat-priced appliance.
£199/month per firewall, plus the VM you run it on. No per-GB data-processing charge — the bill stops scaling with traffic.
Against a cloud-native firewall stacked with a NAT gateway at modest egress, the flat line is usually 60–80% cheaper — and the gap widens as traffic grows.
The SOC 2 pack and advise-or-enforce guardrails are part of the platform. There is no separate compliance SKU and no per-control charge.
Enforza is a network security control and evidence tool that helps you satisfy the SOC 2 Common Criteria that touch the firewall — primarily logical access (CC6), system monitoring (CC7) and change management (CC8). It is not itself a SOC 2 certification and Enforza is not your auditor. SOC 2 is an attestation report issued by a licensed CPA firm against the AICPA Trust Services Criteria, covering far more than the network — governance, people, availability, confidentiality and more. Enforza covers the network-control slice and gives you the evidence for it.
SOC 2 is an attestation report against the AICPA Trust Services Criteria (TSC). The Common Criteria (the CC series, which is the Security category and always in scope) sit alongside four optional categories — Availability, Confidentiality, Processing Integrity and Privacy. A firewall supports the Common Criteria points on logical and network access: CC6.1 (logical access architecture), CC6.6 (protect against threats from outside the boundary), CC6.7 (restrict the movement of information), CC7.2 (monitor components for anomalies) and CC8.1 (authorise and control change). Enforza's default-deny policies, scoped FQDN/SNI egress, SIEM-bound audit logs and advise-or-enforce guardrails line up with each of those.
You attach the bundled SOC 2 pack to the policy governing your network. Scoped egress and default-deny inbound implement the CC6 logical-access points; egress audit logs streamed to your own SIEM give you the CC7 monitoring evidence; and every policy change — from a GitHub pipeline or the console — is checked against the pack and recorded, which is the CC8 change-management record. Violations are advised or, in enforce mode, blocked before the rule reaches a firewall.
Yes. Egress audit logs stream to your own SIEM (never via Enforza's cloud), giving you the record of what left the network, and every compliance check is recorded — the controls evaluated, what passed, what was advised, and any enforce block that rejected a change before it reached a firewall. That is defensible evidence for the network-access and monitoring Common Criteria. Enforza evidences the firewall-control points; your CPA firm still performs the attestation across the full report.
No. The SOC 2 pack and the advise-or-enforce guardrails are part of the platform, not a paid add-on. Enforza is a flat per-firewall licence — £199/month per firewall, however many you run — plus the VM you run it on, with no per-GB data-processing charge. Against a cloud-native firewall stacked with a NAT gateway, the flat line is typically 60–80% cheaper at modest egress, and the gap widens as traffic grows.
A bundled SOC 2 (Type II) pack, advise-or-enforce on every rule change, audit logs to your own SIEM, and a flat per-firewall price with no per-GB tax. Start free, no card.