What is SOC 2?
SOC 2 is an independent audit report, defined by the AICPA, that shows how a service organization protects customer data against the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
Definition
SOC 2 (System and Organization Controls 2) is an attestation report produced by a licensed CPA firm under AICPA standards. It evaluates the controls a service organization uses to protect customer data against one or more of the five Trust Services Criteria.
Background
SOC 2 was created by the American Institute of Certified Public Accountants (AICPA). It is not a certification you pass or fail; it is an auditor’s opinion on whether your controls are suitably designed (Type I) and operating effectively over a period, typically 3 to 12 months (Type II). The Security criterion, also called the Common Criteria, is always in scope; Availability, Processing Integrity, Confidentiality, and Privacy are added based on the promises you make to customers.
Why it matters
For most B2B software companies, a SOC 2 report is the artifact enterprise buyers ask for before they will trust you with their data. Having one shortens security reviews, unblocks deals, and signals a real security program rather than good intentions.
Step by step
- Choose your report type (Type I to start, or go straight to Type II) and which Trust Services Criteria apply beyond Security.
- Define your system scope: the product, infrastructure, and data in the report.
- Implement the controls: access management, change management, monitoring, vendor management, and incident response.
- Collect evidence continuously (policies, tickets, logs, reviews) rather than scrambling before the audit.
- Run a readiness assessment to find gaps, then remediate them.
- Engage a licensed CPA firm for the audit; for Type II, sustain the controls across the observation window.
Examples
- A 20-person SaaS startup pursues a SOC 2 Type II covering Security and Availability because its customers run on the product during business hours.
- A payroll platform adds the Confidentiality and Privacy criteria because it handles sensitive personal data on behalf of clients.
Common mistakes
- Treating SOC 2 as a one-time project instead of an ongoing control program, so the next Type II period starts from zero.
- Over-scoping the criteria: adding Privacy or Processing Integrity you don’t need multiplies the work.
- Collecting evidence manually at the last minute instead of capturing it as work happens.
FAQ
Is SOC 2 a certification?
No. SOC 2 is an attestation report: a CPA firm gives an opinion on your controls. There is no pass/fail certificate, though the report can note exceptions.
What is the difference between SOC 2 Type I and Type II?
Type I assesses whether controls are suitably designed at a single point in time. Type II assesses whether they also operated effectively over a period, usually 3 to 12 months, and is what most buyers prefer.
How long does SOC 2 take?
Readiness typically takes a few weeks to a few months depending on your starting point. A Type II report then requires an observation window (commonly 3 to 12 months) before the auditor can opine.
Free tools & downloads
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free