Frameworks

What is SOC 2?

SOC 2 is an independent audit report, defined by the AICPA, that shows how a service organization protects customer data against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

Definition

SOC 2 (System and Organization Controls 2) is an attestation report produced by a licensed CPA firm under AICPA standards. It evaluates the controls a service organization uses to protect customer data against one or more of the five Trust Services Criteria.

Background

SOC 2 was created by the American Institute of Certified Public Accountants (AICPA). It is not a certification you pass or fail; it is an auditor’s opinion on whether your controls are suitably designed (Type I) and operating effectively over a period, typically 3 to 12 months (Type II). The Security criterion, also called the Common Criteria, is always in scope; Availability, Processing Integrity, Confidentiality, and Privacy are added based on the promises you make to customers.

Why it matters

For most B2B software companies, a SOC 2 report is the artifact enterprise buyers ask for before they will trust you with their data. Having one shortens security reviews, unblocks deals, and signals a real security program rather than good intentions.

Step by step

  1. Choose your report type (Type I to start, or go straight to Type II) and which Trust Services Criteria apply beyond Security.
  2. Define your system scope: the product, infrastructure, and data in the report.
  3. Implement the controls: access management, change management, monitoring, vendor management, and incident response.
  4. Collect evidence continuously (policies, tickets, logs, reviews) rather than scrambling before the audit.
  5. Run a readiness assessment to find gaps, then remediate them.
  6. Engage a licensed CPA firm for the audit; for Type II, sustain the controls across the observation window.

Examples

  • A 20-person SaaS startup pursues a SOC 2 Type II covering Security and Availability because its customers run on the product during business hours.
  • A payroll platform adds the Confidentiality and Privacy criteria because it handles sensitive personal data on behalf of clients.

Common mistakes

  • Treating SOC 2 as a one-time project instead of an ongoing control program, so the next Type II period starts from zero.
  • Over-scoping the criteria: adding Privacy or Processing Integrity you don’t need multiplies the work.
  • Collecting evidence manually at the last minute instead of capturing it as work happens.

FAQ

Is SOC 2 a certification?

No. SOC 2 is an attestation report: a CPA firm gives an opinion on your controls. There is no pass/fail certificate, though the report can note exceptions.

What is the difference between SOC 2 Type I and Type II?

Type I assesses whether controls are suitably designed at a single point in time. Type II assesses whether they also operated effectively over a period, usually 3 to 12 months, and is what most buyers prefer.

How long does SOC 2 take?

Readiness typically takes a few weeks to a few months depending on your starting point. A Type II report then requires an observation window (commonly 3 to 12 months) before the auditor can opine.

Related

SOC 2 in Keel → How to prepare for SOC 2 → SOC 2 evidence kit → What is a risk register? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free