Why SOC 2 Type II matters for the future of IXM

For global brands and retailers, the physical store is becoming a connected, data-driven part of the customer journey, integrated with systems, content, operations, and business goals.
That shift is why In-store Experience Management, IXM, has become a strategic capability. IXM platforms help brands and retailers orchestrate digital in-store touchpoints at scale, connect physical and digital experiences, and create more relevant customer interactions across markets.
But with scale comes responsibility. When IXM becomes part of a customer’s digital ecosystem, trust, security, and compliance cannot be treated as add-ons. They are fundamental requirements.
We sat down with Arvid Berndtsson, Head of Information Security at Vertiseit, to talk about SOC 2 Type II, why it matters for customers using the IXM platform, and what the journey has meant for Vertiseit Group.
Why did Vertiseit Group complete a SOC 2 Type II audit?
“The main motivator was our expansion into the North American market,” says Arvid Berndtsson. “In that market, SOC 2 Type II is often expected as part of customer security and procurement processes.”
For Vertiseit Group, SOC 2 Type II was not only about meeting a formal requirement. It was about making security easier for customers and partners to evaluate. As more global brands and retailers use IXM as part of their digital in-store infrastructure, they need a clear and credible way to understand how information security is managed.
Instead of relying only on individual security questionnaires or separate documentation, customers can review an independent report covering many of the controls and processes relevant to security, availability, and trust.
Why is SOC 2 Type II relevant for IXM customers?
IXM connects the physical store with the broader digital ecosystem. It can involve content workflows, integrations, user access, operational processes, customer-facing applications, and infrastructure that need to work reliably across markets and locations.
That makes security a business-critical part of the platform experience.
SOC 2 Type II is important because it looks at how controls operate over time. It is not only a snapshot of whether policies exist. It helps demonstrate that processes, controls, and responsibilities are working consistently in practice.
“For customers, the main benefit is that we can provide an independent report instead of asking them to rely only on our own explanations,” Arvid explains. “It helps us support our security claims more efficiently and credibly.”
This matters especially for enterprise customers with mature procurement, IT, and security teams. A strong security posture can reduce friction in buying processes, support internal approvals, and make it easier for customers to adopt IXM as part of their long-term retail infrastructure.
What was the process like internally?
According to Arvid, the SOC 2 Type II journey required focus across several parts of the organisation.
“Be prepared,” he says. “It will take time, effort, and focus, not only from the security or compliance team, but also from software development, QA, product teams, consulting teams, and other parts of the organisation.”
SOC 2 Type II is often seen as a security project, but in practice, it touches many teams. It requires structured documentation, evidence collection, defined responsibilities, technical controls, and continuous follow-up.
For Vertiseit Group, with several business brands and products, the process also needed to reflect how the organisation actually works. Some products and responsibilities sit within the business brands, while other processes are handled as group functions. According to Arvid, the audit partner’s ability to understand that structure helped streamline the process.
Why did Vertiseit use a compliance platform?
Vertiseit used Vanta as its compliance platform, which Arvid describes as an important part of making the process manageable.
“I would not want to go back to managing compliance manually through SharePoint, long Excel sheets, and scattered documentation,” he says.
A platform helped the team track requirements, manage evidence, understand what needed to be done, and maintain control over the process. It also made the audit more efficient by giving Vertiseit and the auditor a single place to upload evidence, communicate about requirements, and understand what proof was needed.
For customers, this points to a broader principle: mature security is not only about passing an audit. It is about building repeatable ways of working that can be maintained over time.
What has SOC 2 Type II changed for Vertiseit Group?
Arvid says it is still early, but SOC 2 Type II has already helped open discussions in the U.S. and is increasingly being requested in Europe as well.
The biggest practical benefit is credibility. When a customer asks detailed questions about security, Vertiseit can provide an independent report rather than answering every control question from scratch.
That does not remove the need for dialogue. But it makes the dialogue more efficient and more grounded. It gives customers a clearer view of how Vertiseit approaches security and compliance and supports the trust needed as IXM becomes part of a customer’s operational and digital ecosystem.
What would you recommend to other SaaS companies considering SOC 2 Type II?
“If you are looking to enter the North American market, or if SOC 2 Type II is becoming a requirement from your customers, I would say: do it,” says Arvid. “Take it seriously and plan properly. It is worth doing, but it should not be treated as a last-minute procurement task.“
His advice is also to plan properly. SOC 2 Type II can affect delivery timelines and requires commitment from several teams. It should not be treated as a last-minute procurement task.
He also strongly recommends using a compliance platform unless the company has a very large compliance team. Structure matters, especially when the goal is not only to complete an audit once but to maintain the controls and evidence over time.
Security as an enabler of scalable IXM
For Grassfish and Vertiseit, SOC 2 Type II is part of a larger ambition: helping global brands and retailers use IXM with confidence.
As stores become more connected, adaptive, and measurable, the platforms behind those experiences must be built for scale, flexibility, and trust.
Security does not slow that down. Done right, it enables it.
By strengthening information security practices and making them easier for customers to evaluate, SOC 2 Type II supports the adoption of IXM as a strategic part of modern retail infrastructure. It helps customers move forward with confidence, knowing that the platform behind their digital in-store experiences is supported by documented controls, defined responsibilities, and independent assurance within the scope of the SOC 2 Type II report.