SOC 2 Explained

SOC 2 is a reporting framework used to evaluate how well an organization protects customer data and operates its systems securely over time. It is governed by the American Institute of Certified Public Accountants (AICPA) under its System and Organization Controls suite.

SOC 2 matters because it has become the default trust requirement for SaaS, technology providers, and service companies.

SOC 2 is often the gatekeeper if your organization:

  • Sells to other businesses: B2B procurement runs on it.
  • Handles customer data: the report exists to answer for exactly that.
  • Operates a SaaS or cloud-based service: the sector where it is assumed.
  • Is asked for a SOC 2 report during sales or procurement: the ask that starts most SOC 2 projects.

What It Is

SOC 2 is not a cybersecurity framework and not a certification. It is an independent audit report - an examination only a licensed CPA firm can perform, under AICPA attestation standards. That is why "SOC 2 certified" is always the wrong phrase: there is no certificate, there is an auditor's opinion.

The examination evaluates whether your controls are:

  • Designed appropriately (SOC 2 Type I): a point-in-time snapshot of control design.
  • Operating effectively over time (SOC 2 Type II): the same controls, tested across a review period.

The report is based on the Trust Services Criteria (TSC):

  • Security: the baseline - its criteria are AICPA's "common criteria," included in virtually every SOC 2 report.
  • Availability: uptime and resilience commitments.
  • Confidentiality: protection of sensitive business information.
  • Processing Integrity: systems doing what they promise, accurately.
  • Privacy: handling of personal information.

Think of it this way: SOC 2 is proof that your security and operational controls actually work - not just that they exist.

Who It Applies To

SOC 2 applies to organizations that:

  • Provide SaaS or hosted services: your systems are your customers' risk.
  • Process or store customer data: the trust being examined.
  • Support business-critical systems: where your outage is their outage.
  • Operate in competitive, trust-driven markets: the report is a sales asset as much as an audit artifact.

It is commonly requested by enterprise customers, procurement and security teams, partners and resellers, and investors and insurers.

Even if SOC 2 is not legally required, it is often commercially required.

What Information Is Regulated

SOC 2 applies to systems and processes that support your service commitments.

This includes:

  • Production environments: the systems delivering the service you promised.
  • User identities and access: every account that can touch them.
  • Endpoints and servers: the operational estate.
  • Cloud platforms and applications: wherever the service actually runs.
  • Email and collaboration tools: operational systems attackers reach first.
  • Logging, monitoring, and alerting: the evidence-producing layer.
  • Backup and recovery systems: availability commitments made real.
  • Policies, procedures, and governance: the management wrapper auditors test against practice.

If it affects customer trust, it is in scope.

Relation to Other Frameworks

SOC 2 overlaps heavily with other frameworks.

Common alignments include:

  • ISO/IEC 27001: the management-system counterpart; many organizations pursue both from one control set.
  • NIST SP 800-53: control depth beneath the criteria.
  • NIST CSF: risk communication alongside the report.
  • HIPAA and HITECH: healthcare safeguards that share most of the same controls.
  • PCI DSS: payment environments with overlapping requirements.
  • COBIT: governance above the control layer.

The difference: SOC 2 is evidence-based and time-bound. Auditors test what you actually did - not what you planned.

IT Requirements

Ignore trust service jargon. Focus on what must consistently work.

Identity & Access Management

  • Unique user IDs: shared accounts end the conversation.
  • MFA where appropriate: expected on anything that matters.
  • Least-privilege access: rights match roles, nothing extra.
  • Timely access reviews: departures and role changes caught on schedule.

System & Endpoint Security

  • Secure configurations: hardened baselines, maintained.
  • Patch and vulnerability management: known issues fixed on a defensible cadence.
  • Malware protection: deployed, updated, and monitored.

Data Protection

  • Encryption in transit and at rest: the table-stakes control auditors verify first.
  • Secure data handling: classification and procedures followed in practice.
  • Controlled access to sensitive data: who can see it, tracked and justified.

Logging & Monitoring

  • Centralized logging: one place where the evidence accumulates.
  • Alerting on suspicious activity: detection wired to a human response.
  • Evidence of review: logs someone provably looked at.

Incident Response

  • Documented response plan: written before it's needed.
  • Clear roles: who declares, who investigates, who communicates.
  • Testing and lessons learned: exercised, then improved.

Change Management

  • Controlled changes to production: no undocumented pushes.
  • Approvals and testing: review before release, every time.
  • Rollback capability: a way back when a change goes wrong.

Governance & Documentation

  • Policies that reflect reality: auditors compare paper to practice.
  • Defined ownership: every control answers to someone.
  • Evidence of operation: proof produced by daily work.

SOC 2 is about consistency over time.

Why It Matters

The real risk is failing a trust conversation when it matters most.

Organizations struggle with SOC 2 when:

  • Controls exist but aren't followed consistently: Type II exposes exactly this.
  • Evidence isn't collected during normal operations: the pre-audit scramble begins.
  • Responsibilities are unclear: controls without owners drift.
  • Security is treated as a one-time project: the review period never stops running.

Common impacts include lost or delayed deals, extended security reviews, increased sales friction, higher audit costs, and reputation damage.

How It Fits Into Cyber Risk Management

SOC 2 isn't about passing an audit. It's about operating securely, doing it the same way every day, and proving it when asked.

That operating discipline is what our Cyber Risk Management service builds, and the evidence habit is what our GRC service systematizes - so the audit documents a program instead of interrupting one.

Start with controls. Prove with consistency.

How We Help With SOC 2 Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps your controls and evidence habits against the Trust Services Criteria - so you walk into the CPA firm's examination knowing what they'll find.

How to Prepare

  1. 01Define scope and commitments

    You don't start with auditors. You start with operations. Know what systems support your service and what promises you make to customers - the report is an examination of exactly those commitments.

  2. 02Validate core security controls

    Focus on identity, endpoints, email, data protection, logging, and incident response. These map to most SOC 2 criteria, and they're the controls attackers test before any auditor does.

  3. 03Document what you actually do

    Auditors test reality, not intent. A modest, followed policy beats an impressive, ignored one in every examination.

  4. 04Collect evidence continuously

    Logs: retained and reviewable. Screenshots: configurations captured when set. Tickets: work recorded as it happens. Approvals: authorization trails intact. Evidence should be a byproduct of work - not a scramble.

  5. 05Test over time

    SOC 2 Type II rewards consistency, not heroics. The review period measures months of ordinary operation - make ordinary operation the thing that passes.

Frequently Asked Questions

Is SOC 2 a certification?

No. SOC 2 is an attestation examination performed under AICPA standards, and only a licensed CPA firm can issue the report. There is no certificate - there is an auditor's opinion. Vendors claiming to be "SOC 2 certified" are using the wrong words.

What's the difference between SOC 2 Type I and Type II?

Type I evaluates whether controls are designed appropriately at a point in time. Type II tests whether they operated effectively across a review period, typically several months. Most enterprise customers ask for Type II.

Who asks for SOC 2 reports?

Enterprise customers, procurement and security teams, partners, resellers, investors, and insurers. It is rarely a legal requirement - it is a commercial one, and in B2B SaaS it is close to universal.

Which Trust Services Criteria do we need?

Security is the baseline - its criteria are AICPA's common criteria, included in virtually every report. Add Availability, Confidentiality, Processing Integrity, or Privacy based on what you actually commit to customers. More categories isn't better; matching your commitments is.

What's the difference between SOC 1 and SOC 2?

SOC 1 covers controls relevant to customers' financial reporting - payroll processors, billing platforms. SOC 2 covers security and operational controls over customer data. Different reports for different questions; some organizations need both.

How long does SOC 2 readiness take?

Our gap assessment runs 2 to 4 weeks and shows where you stand. Remediation depends on your evidence habits, and a Type II report then requires an operating review period - typically several months - before the CPA firm examines it.

What does SOC 2 cost?

Readiness cost depends on your gaps; the examination itself is priced by the CPA firm you engage. We publish no pricing; you get a firm quote for the readiness work after your assessment, and the conversation costs nothing.

Where do we start?

Start with an honest gap picture against the Trust Services Criteria. Our Cyber Risk & Compliance Gap Assessment delivers that, plus the corrective action plan that turns findings into an auditable operation.

Official source

Official source: AICPA & CIMA

Secondary source: AICPA & CIMA - SOC Suite of Services

Source verified 2026-07-24

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25