SOC 2 compliance is the process of proving, through an independent audit, that your organisation manages customer data securely against the AICPA Trust Services Criteria. It is one of the most recognised assurance frameworks in North America and increasingly a baseline expectation for SaaS vendors, cloud providers, and data processors worldwide. This guide explains what SOC 2 is, who needs it, how the attestation process works, and how to reach a clean report efficiently.
A crucial point up front: SOC 2 is not a certification and it is not an ISO standard. It is an attestation engagement. You do not receive a certificate; you receive a report signed by a licensed CPA (Certified Public Accountant) firm that expresses an independent opinion on your controls. That distinction shapes everything about how the framework works.
What SOC 2 compliance is and why it matters
SOC 2 stands for “System and Organization Controls 2.” It is a reporting framework developed by the American Institute of Certified Public Accountants (AICPA). A SOC 2 examination evaluates the design (and, in a Type 2 report, the operating effectiveness) of a service organisation’s controls relevant to security and, optionally, other trust principles.
The output is a detailed report intended for a restricted audience: your customers, prospects, auditors, and regulators. Unlike a public certificate, a SOC 2 report contains the auditor’s opinion, a description of your system, the controls tested, and often the specific test results and any exceptions found.
SOC 2 compliance matters because trust in the digital supply chain is now transactional. Enterprise buyers frequently require a current SOC 2 report before signing a contract or sharing sensitive data. A clean report shortens sales cycles, reduces the burden of answering endless security questionnaires, and signals operational maturity to investors and partners.
Who needs SOC 2 compliance
SOC 2 is aimed at service organisations that store, process, or transmit customer data on behalf of other businesses. If your customers trust you with their data, you are a candidate.
- SaaS and cloud software companies whose product handles client information.
- Data centres, hosting, and managed IT service providers.
- Fintech, healthtech, and HR-tech platforms handling regulated or sensitive records.
- Analytics, marketing, and business-process outsourcing vendors.
- Any B2B vendor whose enterprise customers demand third-party assurance.
The trigger is usually commercial rather than legal. SOC 2 is not mandated by statute, but losing deals because you cannot produce a report is a powerful incentive. Many organisations pursue it the first time a large prospect makes it a contractual condition.
The five Trust Services Criteria
SOC 2 is built on five Trust Services Criteria (TSC). You do not have to include all five. Every report must cover Security; the other four are optional and chosen based on the commitments you make to customers.
- Security (the “Common Criteria”) — mandatory in every SOC 2 report. It covers protection of systems and data against unauthorised access, including access controls, network security, change management, and incident response.
- Availability — whether the system is available for operation and use as committed, covering monitoring, capacity planning, backup, and disaster recovery.
- Processing Integrity — whether system processing is complete, valid, accurate, timely, and authorised.
- Confidentiality — protection of information designated as confidential, such as intellectual property or contract terms.
- Privacy — how personal information is collected, used, retained, disclosed, and disposed of in line with your privacy notice.
The Security criterion is organised around the “Common Criteria” (often referenced as CC1 through CC9 in the current version — verify the latest AICPA points of focus, as these are periodically updated). The scope you select directly affects cost, effort, and how relevant the report is to your customers.
Type 1 vs Type 2: report options
SOC 2 comes in two report types, and understanding the difference is essential. A Type 1 report assesses whether your controls are suitably designed at a single point in time. A Type 2 report goes further and tests whether those controls operated effectively over a period, typically 3 to 12 months.
| Dimension | SOC 2 Type 1 | SOC 2 Type 2 |
|---|---|---|
| What it assesses | Control design at a point in time | Design and operating effectiveness over a period |
| Observation window | A single date | Typically 3–12 months |
| Evidence required | Policies and control descriptions | Ongoing evidence proving controls ran consistently |
| Buyer confidence | Moderate — shows intent and design | High — proves controls work in practice |
| Typical use | First report, or a fast interim signal | The report most enterprises ultimately require |
Many organisations start with a Type 1 to demonstrate progress quickly, then follow with a Type 2 covering the subsequent observation period. Others move straight to Type 2. Because a Type 2 is what most enterprise buyers eventually ask for, factor the observation window into your timeline from the start.
The SOC 2 compliance process step by step
Reaching a clean SOC 2 report follows a fairly consistent path. The examination itself is performed by a licensed CPA firm, but most of the work happens inside your organisation before the auditor arrives.
1. Define scope
Decide which Trust Services Criteria apply and which systems, products, and locations are in scope. Base this on the promises you make to customers. Over-scoping wastes effort; under-scoping produces a report your buyers will not accept.
2. Choose Type 1 or Type 2
Select your report type and, for a Type 2, the length of the observation period. This decision drives your entire schedule.
3. Perform a readiness assessment (gap analysis)
Compare your current controls against the criteria to find gaps. This can be internal or run by a consultant or the audit firm’s advisory arm. Note that the same firm generally cannot both consult on remediation and issue an independent opinion, so keep those roles separate.
4. Remediate gaps
Implement or fix controls: access management, encryption, logging and monitoring, vendor management, change control, and incident response. Write the policies that describe how these controls operate.
5. Operate controls and collect evidence
For a Type 2, let the controls run across the full observation window while you gather evidence — access reviews, ticket records, monitoring alerts, training logs. Consistency here is what earns a clean opinion.
6. Undergo the audit
The CPA firm examines your control design and, for Type 2, tests operating effectiveness by sampling evidence across the period. They document findings and any exceptions.
7. Receive and share the report
You receive the final SOC 2 report with the auditor’s opinion. Because it is a restricted-use document, share it under NDA with customers and prospects. Reports are effectively point-in-time, so plan for an annual refresh to keep SOC 2 compliance current.
Documentation involved in SOC 2 compliance
SOC 2 is evidence-driven. Auditors expect documented policies plus proof that those policies are lived, not shelved. Typical documentation includes:
- Information security policy and acceptable use policy.
- Access control, password, and identity management procedures.
- Change management and software development lifecycle policies.
- Incident response and business continuity / disaster recovery plans.
- Risk assessment methodology and a maintained risk register.
- Vendor / third-party risk management policy.
- Data classification, retention, and secure disposal procedures.
- A system description of the in-scope environment.
- Evidence artefacts: access reviews, training records, monitoring logs, and remediation tickets.
A well-organised control-and-evidence library is the single biggest lever for a smooth audit. Starting from a mature template set saves considerable time versus writing everything from scratch.
Timeline and cost drivers
Timelines vary with scope, report type, and starting maturity. As a rough guide (verify against quotes for your situation), a Type 1 might take a few months of preparation plus the examination. A Type 2 adds the observation window on top — commonly 3 to 6 months for a first report, meaning the whole effort can run 6 to 12 months end to end.
Cost drivers include the number of Trust Services Criteria in scope, the size and complexity of your environment, the audit firm’s fees, and whether you use compliance automation tooling. Approximate cost ranges circulate widely online, but they vary so much by region and scope that you should treat any single figure with caution and gather your own quotes.
The largest hidden cost is usually internal engineering and staff time spent remediating gaps and gathering evidence — budget for people, not just the auditor’s invoice.
Common challenges and how to avoid them
Most SOC 2 programmes stumble in predictable places. Knowing them in advance lets you plan around them.
- Scope creep or the wrong scope. Including criteria your customers do not care about inflates effort. Confirm scope against real buyer requirements early.
- Policies without practice. Auditors test whether controls actually operate. A polished policy with no evidence it was followed produces exceptions. Automate evidence collection where you can.
- Leaving evidence to the end. For Type 2, you cannot retroactively create a clean observation period. Start collecting from day one.
- Treating it as a one-off. SOC 2 compliance is an annual, continuous cycle, not a project you finish and forget.
- Mixing advisory and audit. The firm that helps you build controls generally should not be the one issuing the independent opinion.
SOC 2 compliance versus ISO 27001
The most common comparison is SOC 2 against ISO/IEC 27001. Both address information security, but they differ in structure, geography, and outcome.
| Aspect | SOC 2 | ISO/IEC 27001 |
|---|---|---|
| Type | Attestation report (opinion by a CPA firm) | Certification against a standard |
| Issued by | Licensed CPA / audit firm | Accredited certification body |
| Outcome | A restricted-use report | A publicly shareable certificate |
| Framework basis | AICPA Trust Services Criteria | An Information Security Management System (ISMS) |
| Geographic strength | Strong in North America | Recognised internationally |
| Renewal cadence | Typically annual | Multi-year cycle with periodic surveillance audits |
Neither is inherently superior. Many organisations pursue both because their control sets overlap heavily. If your buyers are mostly US-based, SOC 2 often comes first; if you sell globally, ISO 27001 may carry more weight. A shared control foundation lets you satisfy both with far less duplicated effort.
Frequently asked questions about SOC 2 compliance
Is SOC 2 a certification?
No. SOC 2 results in an attestation report signed by a licensed CPA firm, not a certificate. It is common to hear people say “SOC 2 certified,” but the accurate term is SOC 2 compliant or “having a SOC 2 report.”
How long is a SOC 2 report valid?
A report reflects a point in time or a defined period, so it does not carry a formal expiry like a certificate. In practice, buyers expect a report covering a recent period, so most organisations undergo an examination annually to keep it current.
Should I start with Type 1 or Type 2?
If you need to show progress quickly, a Type 1 provides an early signal. However, most enterprise customers ultimately want a Type 2, which proves controls operated over time. Some organisations skip straight to Type 2 to avoid two engagements.
Do I need all five Trust Services Criteria?
No. Only Security (the Common Criteria) is mandatory. You add Availability, Processing Integrity, Confidentiality, or Privacy based on the commitments you make to customers and the nature of your service.
Who performs a SOC 2 audit?
Only a licensed CPA firm can issue a SOC 2 report, because it is an AICPA attestation engagement. Advisory firms and automation platforms can help you prepare, but the independent opinion must come from a qualified CPA firm.
How much does SOC 2 compliance cost?
Costs vary widely by scope, environment size, report type, and firm. Beyond audit fees, budget for internal staff time and any tooling. Because published ranges differ so much, gather quotes tailored to your specific scope rather than relying on a single figure.

Related guides
- SOC 2 Type 1 vs Type 2: which report do you need?
- SOC 2 Trust Services Criteria explained
- The complete SOC 2 compliance checklist
- SOC 2 vs ISO 27001: a detailed comparison
- SOC 2 cost and timeline: what to budget
For the authoritative source on the Trust Services Criteria and SOC reporting, consult the AICPA (AICPA & CIMA), which develops and maintains the framework.
Ready to accelerate your programme? Our editable SOC 2 (AICPA Trust Services Criteria) toolkit gives you pre-written policies, a control library, and evidence templates mapped to the Trust Services Criteria, so you can close gaps faster and walk into your audit prepared. Explore the SOC 2 Toolkit and shorten your path to a clean report.

