What Is SOC 2 Compliance? Criteria, Types and Audits
SOC 2 is the report enterprise buyers ask for before they will hand you their data. It is an accountant's opinion on your controls, not a certificate, and understanding that difference is what tells you how much one is worth.

The question usually arrives attached to the largest deal of the year, in a procurement email of about eleven words: can you send us your SOC 2 report? Everything about the next twelve months follows from how you answer, and most founders answer badly because they think they are being asked for a certificate. They are not. They are being asked for an accountant's opinion about a period of time that has not happened yet.
What Is SOC 2?
SOC stands for System and Organization Controls, and SOC 2 is the second of three report types in a suite published by the American Institute of Certified Public Accountants. The AICPA's own name for the engagement is an examination of controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy, and every word in that title is doing work.
A service organization is any company that holds, processes or transmits data on behalf of its customers. Software companies, hosting providers, payroll processors, managed IT firms, data centers and analytics vendors are all service organizations. Examination means an independent accountant tested something and formed a conclusion. Controls means the practices you actually run, not the policies you wrote.
What you receive at the end is a document, usually somewhere between forty and a hundred pages, containing management's assertion about its own system, the auditor's opinion, a description of the system, and a table of every criterion, the controls mapped to it, the tests performed and the results. It is written for your customers and their auditors, and it carries a restricted use notice saying so.
The single most misunderstood thing about it: there is no certificate, no registry, no expiry sticker and no pass mark. Nobody certifies you. A CPA firm gives an opinion, and an opinion can be unqualified, qualified, adverse or disclaimed. "SOC 2 compliant" is industry shorthand for holding a report with a clean opinion, and it has no formal meaning beyond that.
What Are the Five Trust Services Criteria?
SOC 2 does not hand you a control list. It hands you criteria, and you design controls that meet them, which is why two companies can hold clean reports and run almost nothing in common.
| Category | What it covers | Include it when |
|---|---|---|
| Security (common criteria) | Protection against unauthorized access, disclosure and damage | Always. It is mandatory and it is most of the work |
| Availability | The system is available for operation and use as committed | You sell an uptime commitment or your customers depend on continuity |
| Processing integrity | Processing is complete, valid, accurate, timely and authorized | You transform data or move money and the output has to be right |
| Confidentiality | Information designated confidential is protected as committed | Contracts oblige you to protect customer information beyond personal data |
| Privacy | Personal information is collected, used, retained and disposed of as committed | You are the controller of personal information and can genuinely support it |
Scope narrowly on the first report. Security alone is a complete, credible SOC 2 and it is what most procurement teams mean. Availability is cheap to add if you already run uptime monitoring. Privacy is expensive and drags in data subject rights, retention schedules and notice obligations most companies are not ready to be examined on. Categories can be added next year; removing one after a customer has seen it is an awkward conversation.
Two of the security criteria account for most of the engineering work. CC6 is access control, which in practice means multi-factor authentication everywhere, least privilege, joiner and leaver processes that actually run, and encryption in transit and at rest. CC7 is system operations, which means monitoring, alerting, and evidence that somebody looked.
SOC 2 Type 1 vs Type 2
This is the distinction that decides your timeline, and it is not a difference in rigor of the controls. It is a difference in what the auditor is willing to say.
A Type 1 is a legitimate report and a reasonable first step, particularly when a deal is waiting. Be honest with yourself about what it buys, which is time rather than trust. A sophisticated buyer reads a Type 1 as a promise that a Type 2 is coming, and will ask when.
The observation period is the part founders underestimate. If a customer needs a Type 2 in March and you start work in January, the earliest credible report covers a period ending in April at best, with fieldwork and drafting after that. The clock does not start when you buy the tooling. It starts when the controls are genuinely running, because the auditor will sample evidence from the whole window and a control that began three weeks late produces exceptions for the weeks it was absent.
What Is the Difference Between a SOC 1 and a SOC 2?
Different subject matter, different audience, same suite. The AICPA's overview of SOC engagements for service organizations names all three, and the subtitles are the clearest explanation available.
- SOC 1 is "SOC for Service Organizations: ICFR". Its subject is internal control over financial reporting. A payroll processor or a claims administrator gets one because its customers' financial auditors need to rely on the controls. If nothing you do affects a customer's financial statements, you do not need a SOC 1, however much a salesperson wants one.
- SOC 2 is "SOC for Service Organizations: Trust Services Criteria". Its subject is security and the other four categories. It is a restricted use report, meaning it goes to customers, prospects under NDA and their auditors, not on your website.
- SOC 3 is "SOC for Service Organizations: Trust Services Criteria for General Use Report". Same examination as a SOC 2, stripped of the detailed test results, and publishable. Companies that want a public marketing artifact get a SOC 3 alongside the SOC 2, from the same engagement.
The most common real confusion is not SOC 1 against SOC 2 but SOC 2 against a security questionnaire. A report is an independent opinion covering a period. A questionnaire is you answering questions about yourself. Buyers accept the second only until they have leverage to demand the first.
Who Needs a SOC 2 Report?
Anyone selling a service that touches customer data to a buyer large enough to have a vendor risk process. In practice that means business software companies at the point they start selling to enterprises, plus hosting, managed IT, payroll, benefits administration, analytics and anything in healthcare or financial services adjacent markets.
The reason the question is being asked more often is measurable. The 2026 Verizon Data Breach Investigations Report found third-party supply chain breaches up 60 percent, with breaches involving a third party now accounting for 48 percent of all breaches. Nearly half of incidents now arrive through somebody's vendor, which is why vendor risk teams that used to send a spreadsheet now ask for an examined report instead.
Is SOC 2 Legally Required?
No. No US statute requires a SOC 2 report, no regulator issues one, and no fine follows from not having one. It is a commercial instrument enforced by contracts and procurement policies, which in practice makes it feel mandatory to anyone selling to enterprises.
Distinguish it from the obligations that genuinely bind. HIPAA's Security Rule is federal law for covered entities and their business associates. State breach notification statutes are law. PCI DSS is not law but is contractually enforced by the card brands, with real financial consequences. SOC 2 sits with none of these: it is a report your customers ask for, and its force comes entirely from your master services agreements.
That has one useful consequence. Because nobody prescribes your controls, you get to design a program that fits how your company actually operates, then show the auditor that it meets the criteria. Companies that treat SOC 2 as a checklist handed down from outside end up running controls nobody believes in, which produces exceptions in year two when the enthusiasm fades.
How to Get a SOC 2 Report
The path is well worn and the durations are fairly predictable. What varies is how much of the readiness work you had already done before anyone asked.
- Scope it: which system, which trust services categories, which subservice organizations you rely on and whether they are carved out
- Readiness assessment against the criteria, then close the gaps. Policies written, controls actually switched on and running
- Optional Type 1 examination, giving an opinion on design at a point in time. Useful when a deal is waiting
- The observation period. Three months is the practical minimum and twelve is the steady state. Evidence accumulates whether you collect it or not
- Fieldwork. The CPA firm samples evidence across the whole period and tests whether each control operated
- The Type 2 report is issued, naming the period covered and any exceptions the auditor found
- Renewal. The next period should start where the last one ended, because a gap is visible to every buyer
How Hard Is It to Get SOC 2?
Harder than the compliance platforms suggest and easier than the horror stories. The difficulty is not intellectual; it is that a Type 2 examines a period, so it converts security from a project into an operating rhythm.
The hard parts are consistent across companies. Access reviews every quarter, performed and recorded, on every in-scope system. Offboarding that removes access the same day, including the contractor nobody remembered. Change management that survives a hotfix on a Friday night. Vendor reviews for the subservice organizations you depend on. Security awareness training that everyone completes, which is where social engineering resistance comes from and where completion rates quietly rot.
Automation platforms help with evidence collection, control monitoring and policy templates, and they have taken real cost out of the process. What they cannot do is operate a control for you. A dashboard showing that a quarterly access review is overdue is not a performed access review.
On cost, be skeptical of any confident single number, including the ranges compliance vendors publish, because none is drawn from a published dataset. What drives the figure is scope: the categories, systems and locations examined, the size of your engineering organization, and whether you buy a readiness partner and a compliance platform on top of the auditor. The audit fee is usually the smaller half. Staff time is the larger half and never appears on an invoice.
Is SOC 2 the Same as ISO 27001?
No, and they answer to different buyers. SOC 2 is a US attestation: a CPA firm gives an opinion on your controls against the trust services criteria, and the deliverable is a report. ISO 27001 is an international certification: an accredited body certifies that you operate an information security management system meeting the standard, and the deliverable is a certificate valid for three years with surveillance audits in between.
The choice is usually decided by geography and by who is asking. US buyers ask for SOC 2 by name. European and Asian buyers, and public sector procurement in much of the world, ask for ISO 27001. Companies selling into both eventually hold both, and the sensible order is whichever one a signed contract is waiting on.
How to Read a SOC 2 Report
A vendor sends you 90 pages. Most people skim the opinion, see the word "unqualified" and file it. The value is in four things, and they take about twenty minutes to find.
The period and the date. A Type 2 covers a stated window, so a period that ended nine months ago tells you about last year. Ask for a bridge letter, management's written statement that nothing material changed since the period ended. It is not audited and it is not a substitute for a current report.
The scope. Section 3, the system description, states which products, environments and locations were examined. A report covering one product line tells you nothing about the one you are buying.
The subservice organizations. Most reports carve out major providers, meaning the vendor's own cloud host was excluded and its controls were not tested here. That is normal, and it means your assurance chain continues elsewhere. Read the complementary user entity controls too: those are the things the report assumes you will do, and the customer who requested it routinely ignores them.
The exceptions. Section 4 lists every control, the tests performed and the results, with exceptions stated plainly alongside management's response. Two well explained exceptions and a candid response is often a better signal than a spotless report, because it shows the auditor tested something. This is also where centralized logging evidence lives, since CC7 testing leans on it.
Key takeaways
- SOC 2 is an AICPA attestation. A CPA firm examines a service organization's controls and issues an opinion. There is no certificate and no pass mark.
- The criteria are the 2017 Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Only security is mandatory, and it is most of the work.
- A Type 1 covers design at a point in time. A Type 2 covers design and operating effectiveness across a period, commonly three to twelve months, and it is what enterprise buyers mean.
- Nothing in US law requires SOC 2. Contracts do, which is why it feels mandatory when you sell to enterprises.
- The observation period is the one part of the timeline you cannot compress, so the date the controls genuinely start running sets the date the report can exist.
- When reading someone else's report, look at the period, the scope, the carved out subservice organizations and the exceptions in section 4.
- Reports vary in rigor. The AICPA's own peer review guidance flags engagements that produce identical testing across different clients.
Common questions
What does SOC 2 stand for?
System and Organization Controls 2, the second report type in the AICPA's SOC suite, covering controls at a service organization measured against the Trust Services Criteria. SOC 1 covers internal control over financial reporting, and SOC 3 is a publishable summary of the same examination.
Is SOC 2 the same as ISO 27001?
No. SOC 2 is a US attestation producing an auditor's report and opinion. ISO 27001 is an international certification of an information security management system, producing a certificate valid for three years. The controls overlap heavily, so evidence can be reused, but neither converts into the other.
What is the difference between a SOC 1 and a SOC 2?
Subject matter. SOC 1 examines internal control over financial reporting, because your customers' financial auditors need to rely on your controls. SOC 2 examines security, availability, processing integrity, confidentiality and privacy. If nothing you do affects a customer's financial statements, SOC 1 is not the report you need.
Is SOC 2 legally required?
No US statute requires it and no regulator issues it. It is enforced through contracts and vendor risk policies, which makes it commercially unavoidable for most companies selling to enterprises. That is different from HIPAA, which is law, and PCI DSS, which the card brands enforce contractually.
How hard is it to get SOC 2?
The concepts are simple; the discipline is not. A Type 2 examines a period, so quarterly access reviews, same-day offboarding, change approvals and training completion have to happen every time for months, with evidence. Most first-time trouble is missing records rather than missing controls.
How long does a SOC 2 audit take?
Plan on nine to fifteen months from a standing start: one to three months of readiness work, an observation period of three months at minimum and twelve as the norm, then six to ten weeks of fieldwork and drafting. A Type 1 can be produced in weeks once readiness is complete.
How much does a SOC 2 report cost?
No authoritative dataset publishes this, so treat confident single figures with suspicion. Scope moves it most: the number of categories, systems and locations, your headcount, and whether you buy a readiness partner and a compliance platform on top of the audit. Staff time is usually the larger half.
Is SOC 2 a certification?
No. It is an attestation engagement, and the deliverable is a report containing an independent accountant's opinion. Nobody is certified, nothing is registered, and the AICPA authorizes no SOC 2 logo. Saying "SOC 2 certified" marks a vendor as unfamiliar with what it bought.
Who can perform a SOC 2 audit?
Only a licensed CPA firm, working under the AICPA's attestation standards and independence rules. That independence requirement is why the firm helping you build controls generally cannot be the firm that examines them, and why readiness and the audit are usually two engagements.
Is SOC 2 the same thing as a security operations center?
No, and the shared acronym causes real confusion. A security operations center is a team that monitors and responds to threats around the clock. SOC 2 is an AICPA reporting standard about controls at a service organization. Having one says nothing about the other, though a monitoring function does help satisfy the system operations criteria.
How long is a SOC 2 report valid?
A Type 2 covers a stated period and does not expire so much as go stale, and most buyers treat anything older than twelve months as insufficient. A bridge letter, management's unaudited statement that nothing material changed since the period ended, covers a short gap. Beyond that, buyers ask for the current report.
On this page

Daniel Reyes
Daniel Reyes is a CISSP who spent twelve years in security operations, most recently leading a detection and response team for a mid-sized healthcare group in Texas. He reviews every resource and breach report on Cyber Security Firms for technical accuracy before it publishes.
Most of the people he has trained arrived having been told too much: a dozen acronyms, six vendors, and no clear idea which risk was theirs. His approach is to explain what an attack actually does before naming the tool that stops it, on the basis that most breaches start with something a reader could have recognised.