Open menu

What is SOC 2? Trust Services Criteria, Types, and Audits

Written by Hadis Mohtasham Marketing Manager
What is SOC 2? Trust Services Criteria, Types, and Audits

SOC 2 is an attestation framework from the AICPA, the American Institute of Certified Public Accountants. It defines how a service organization should protect the customer data it stores and processes. An independent CPA firm examines those controls and issues a formal report on whether they work.

Notice the word report. SOC 2 does not produce a certificate you frame on a wall. It produces a detailed document, often 60 to 120 pages, describing your systems, your controls, and what an auditor actually observed.

I have sat on both sides of that document. Over the years I fed evidence into audits at data companies, and I tore apart vendor reports as a buyer. So in this guide, I will walk through the five Trust Services Criteria, Type I versus Type II, real costs, and how to read a report before you sign a contract.

What Does SOC 2 Actually Mean?

SOC 2 stands for System and Organization Controls 2, a framework the AICPA maintains for reporting on how service organizations handle customer data. Only a licensed CPA firm can perform the examination and sign the resulting report.

The technical term for this is an attestation. Your company makes an assertion, roughly “here is our system and here are our controls.” Then the auditor tests that assertion and states, in a formal opinion, whether it holds up.

In practice, SOC 2 plays three roles at once:

  • A security baseline. The Trust Services Criteria force you to define access rules, monitoring, vendor management, and incident response.
  • An audit deliverable. The report gives your customers an independent account of whether those controls operate.
  • A sales unblocking tool. Enterprise procurement teams ask for it by name, usually before legal review even starts.

That third role explains most of the demand. Almost nobody wakes up wanting an audit. Deals force the issue.

📌 Example: In 2023 I watched a mid-market deal generate a 212-question security questionnaire. Our team spent nine days answering it. The next buyer accepted our SOC 2 Type II report in place of the whole exercise. One document replaced two weeks of back and forth.

Where Did SOC 2 Come From?

SOC 2 grew out of an older accounting standard called SAS 70, which dates back to the early 1990s. That standard audited outsourced financial controls, things like payroll processors affecting a client’s books. It was never designed for security.

Then cloud computing changed the question buyers were asking. Companies stopped worrying only about vendors touching their ledgers. They started worrying about vendors holding their customer data. So in 2011 the AICPA retired SAS 70 and split its reporting into the System and Organization Controls family: SOC 1 for financial reporting, SOC 2 for data handling, and SOC 3 as a public summary.

The framework kept evolving after that. In 2017 the AICPA restructured the Trust Services Criteria to align with the COSO internal control model, which is the version auditors still use today. Why does this history matter to you? Because it explains the framework’s personality. SOC 2 thinks like an accountant, not like a penetration tester. It cares whether your controls are defined, followed, and evidenced, not whether your firewall brand is fashionable.

What Are the Five Trust Services Criteria?

The five Trust Services Criteria are security, availability, processing integrity, confidentiality, and privacy. Security is mandatory in every SOC 2 report. The other four are optional, and you scope them in based on what your service promises and what your customers ask about.

CriterionCore question it answersRequired?
SecurityAre systems protected against unauthorized access and disclosure?Yes, always in scope
AvailabilityIs the service up and usable as committed in your SLA?Optional
Processing integrityDoes the system process data completely, accurately, and on time?Optional
ConfidentialityIs confidential business information restricted to the right people?Optional
PrivacyIs personal information collected, used, and disposed of as promised?Optional

Security is called the common criteria because every other category builds on it. It covers logical and physical access, change management, monitoring, and risk assessment. In evidence terms, this is where auditors check that data access is granted by role, reviewed quarterly, and revoked the day someone leaves.

Confidentiality and privacy sound similar but split cleanly. The confidentiality criterion protects business information like contracts and price lists, using controls such as encryption and data masking in non-production environments. Privacy covers personal information specifically. Auditors here look for consent handling, retention limits, and techniques like pseudonymization, and the category loosely mirrors what GDPR and CCPA regulate by law.

Processing integrity is the least understood of the five. It asks whether your system does what it claims with the data, completely and accurately. The concept overlaps with data integrity but is broader, because it covers the whole processing pipeline, not just storage. Palo Alto Networks’ SOC 2 overview is a solid vendor-neutral read on how the criteria fit together.

💡 Pro Tip: Scope criteria from your customers' questionnaires, not from ambition. Most first reports cover security alone, or security plus availability and confidentiality. Adding privacy before you have mature consent and retention processes is the most common way I see first audits slip by a quarter.

SOC 2 Type I vs Type II: Which One Do Buyers Want?

Buyers almost always want Type II. A Type I report checks that your controls are properly designed at a single point in time. Type II goes further and checks that those controls actually operated over an observation window, which Secureframe’s guide notes generally runs 3 to 12 months.

DimensionType IType II
What it testsControl design at one dateDesign plus operating effectiveness over a period
Observation windowNone, a snapshot3 to 12 months of evidence
Time to obtainWeeks after readinessMonths, window plus fieldwork
Weight with buyersA starting signalThe standard procurement ask
Typical roleFirst-year stepping stoneRenewals and enterprise deals

The difference sounds academic until a deal depends on it. Anyone can behave for a photograph. Behaving for six months, with an auditor sampling evidence from every week of it, is a different claim entirely. That is why security teams discount Type I reports so heavily.

Here is what that looks like commercially. In 2023 a deal I supported stalled for five weeks because we could only produce a Type I. The buyer’s security team would not budge, and we salvaged the contract only by committing to a Type II with a three-month window written into the agreement. Since then I treat Type I as a milestone you mention, never a destination you market.

What About SOC 1 and SOC 3?

SOC 1 covers controls relevant to a customer’s financial reporting, while SOC 3 is a public marketing summary of a SOC 2 examination. They bracket SOC 2 rather than compete with it.

Use SOC 1 when your service can change a client’s financial statements. Payroll providers, billing platforms, and claims processors live here. Linford & Co’s comparison, written by practicing auditors, is the cleanest breakdown I have found of where each report applies.

SOC 3 exists because SOC 2 reports are restricted documents, normally shared under NDA. A SOC 3 strips out the system description and test details, leaving a short attestation a vendor can post publicly. It is fine as a trust-page badge. No serious security review accepts it as a substitute for the full SOC 2 report.

What Does a SOC 2 Audit Actually Involve?

A SOC 2 audit runs through four phases: scoping, readiness, evidence collection, and auditor fieldwork. The audit firm only shows up at the end. Most of the work happens inside your company long before anyone tests anything.

Scoping decides which systems, products, and criteria the report covers. This step quietly determines the report’s value. A report that scopes out your main production system is technically real and commercially useless.

Readiness is the gap assessment. You compare current practice against the criteria, then fix what is missing: access reviews, onboarding checklists, vendor assessments, incident runbooks. Compliance automation platforms compress this phase by pulling evidence from your stack through an API instead of screenshots.

Evidence collection then runs for the whole observation window. Every control needs artifacts: tickets, logs, review sign-offs, training records. Fieldwork comes last, when the auditors sample that evidence and interview your team. Vanta’s guide puts the assessment itself at four to six weeks once the window closes.

Fieldwork itself is quieter than people expect. Auditors do not hack anything. They sample: show me the access review from March, the offboarding ticket for this former employee, the postmortem from that outage. Interviews fill the gaps, and inconsistent answers between teams are what trigger deeper evidence pulls.

The finished report has a consistent anatomy, and knowing it saves you time later:

  • Auditor’s opinion. Unqualified means clean; qualified means at least one control failed materially.
  • Management assertion. Your formal claim about the system and controls.
  • System description. What the service is, its infrastructure, its people, and its boundaries.
  • Tests and results. Every control tested, how it was tested, and any exceptions found.
  • Other information. Optional management responses, remediation notes, and future commitments.
🔍 Field Note: Our 2024 Type II cycle generated 184 separate evidence requests. The painful ones were never technical. They were process artifacts: proof that a quarterly access review happened in the quarter it was due, with the reviewer named. Automation collected logs beautifully; it could not fake a habit we had skipped.

SOC 2 vs ISO 27001: What Is the Difference?

SOC 2 is an attestation report issued by a CPA firm, while ISO 27001 is a certification against an international standard for information security management systems. They answer the same customer worry through different machinery, and the choice usually follows your buyers’ geography.

DimensionSOC 2ISO 27001
NatureAttestation report on your controlsCertification against a fixed standard
Issued byLicensed CPA firm under AICPA rulesAccredited certification body
Buyer geographyDominant expectation with US buyersRecognized default across Europe and Asia
OutputDetailed restricted report with test resultsCertificate plus statement of applicability
FlexibilityControls tailored to your own systemPrescribed management system requirements
CycleNew report for each observation periodThree-year certificate with surveillance audits

The practical rule I give founders is simple. Selling mostly to US companies, start with SOC 2. If Europe or global enterprise is your market, expect ISO 27001 on questionnaires. Scaling into both regions eventually means holding both, because the control work overlaps far more than the paperwork does.

One more difference matters to buyers. An ISO certificate tells you a system passed. A SOC 2 report shows you the test results, exceptions included. As a reviewer, I learn far more from ten pages of test tables than from any certificate.

Who Actually Needs SOC 2?

Any company that stores or processes customer data and sells to mid-market or enterprise buyers will eventually need SOC 2. SaaS platforms, data vendors, managed service providers, and fintech infrastructure sit at the front of that line.

No law mandates it. SOC 2 is a market requirement, not a legal one, and that distinction confuses people constantly. Regulations like GDPR carry fines; SOC 2 carries lost deals. Procurement teams simply refuse to onboard data-handling vendors without a report, so the requirement enforces itself through revenue.

The pattern by vertical is fairly stable, too. SaaS platforms hit the requirement first, because their product holds customer data by definition. Data and enrichment vendors follow close behind, since processing records at scale is their whole business. Agencies and consultancies feel it last, usually when a client’s procurement policy sweeps in every vendor with system access.

Timing matters more than ambition here. A five-person startup selling to other startups can usually wait. The trigger point is your first mid-market prospect with a security review, which in my experience arrives around the time deals cross five figures in annual value. Starting readiness one quarter before you expect that prospect is cheap. Waiting until the questionnaire lands is how quarters get lost.

How Much Does SOC 2 Cost, and How Long Does It Take?

Plan for tens of thousands of dollars all-in, and six to twelve months for a first Type II. Anyone quoting one number is hiding the others, so here are the realistic bands I have seen across small and mid-size vendors.

The audit fee itself typically runs from around 5,000 to 20,000 dollars for a Type I and roughly 12,000 to 40,000 dollars for a Type II, scaling with scope, criteria, and firm prestige. Around that fee sit the quieter costs: compliance automation tooling, an annual penetration test, sometimes a consultant, plus new security tools the gap assessment exposes. Internal hours are the cost everyone forgets, and they are rarely small.

On timeline, the math stacks predictably. Readiness work takes one to three months for a company with reasonable practices. The observation window adds 3 to 12 months, with 3 to 6 common for a first report. Fieldwork and report writing add another four to six weeks at the end.

You can shrink those numbers with three moves. First, narrow the scope to the systems your customers actually care about instead of your whole stack. Second, automate evidence collection early, because manual screenshot hunts burn the most internal hours. Third, choose a shorter first window, say three months, then extend toward twelve once the report exists and renewals begin.

📌 Checkpoint: Before signing with an audit firm, ask which criteria, which products, and which window the quote assumes. In 2022 I watched a team accept a bargain quote, then discover mid-cycle it covered security only, while their biggest prospect required availability and confidentiality too. The re-scope cost more than the original difference between firms.

How Do You Read a Vendor’s SOC 2 Report as a Buyer?

Read the opinion first, then the scope, then the exceptions, then the CUECs. Most people skim the opinion letter and stop, which is exactly how bad vendors pass reviews. A disciplined read takes under an hour and follows six checks.

  • Opinion. Unqualified is clean. Qualified means a control failed materially, so find out which one and what changed since.
  • Type and period. Confirm it is a Type II, check the window’s end date, and ask for a bridge letter if months have passed since.
  • Scope. Verify the product you are buying is inside the system description, with the criteria you care about included.
  • Exceptions. Read every one, plus the management response. A few minor exceptions with honest remediation beat a suspiciously spotless report.
  • CUECs. Complementary user entity controls are your homework as the customer, like enforcing SSO. Miss them and the vendor’s assurances stop applying to you.
  • Subservice organizations. Check whether cloud providers are carved out, and confirm the vendor monitors those dependencies somehow.

Exceptions deserve the most judgment. In 2024 I reviewed a data vendor whose report showed three failed access-review controls, no management response, and a window that had ended ten months earlier. We walked away, and the deciding factor was not the failures. It was the silence about them.

🧠 Worth Remembering: A SOC 2 badge on a website is a claim, not evidence. The report is the evidence, and vendors share it under NDA every day. Any vendor who resists sharing one, or offers a SOC 3 summary instead, has answered your due-diligence question already.

Why Does SOC 2 Matter in the B2B Data Industry?

SOC 2 matters doubly for B2B data vendors because their entire product is other people’s information. A provider of B2B data enrichment processes millions of contact and company records, and its customers pipe that data straight into their own CRMs. That concentration raises the stakes, because a breach leaks everyone’s prospect base at once, not one company’s secrets.

Buyers in this industry have learned to ask layered questions. Security reviews now sit alongside data governance questions about sourcing, consent, and retention. A SOC 2 report answers the security half convincingly. It says nothing about whether the records were collected lawfully, which is a separate diligence track under privacy law.

Keep the two axes separate when you evaluate providers. One axis is protection, evidenced by SOC 2. The other is data quality and lawful sourcing, which no audit opinion covers. Enrichment platforms like CUFinder publish their security and compliance posture for exactly this review process, and the same rule applies to them as to everyone: read the actual report, because no attestation substitutes for your own diligence on data accuracy and sourcing.

Contract terms follow the report too. Data processing agreements in this industry now reference SOC 2 explicitly, and renewal questionnaires ask whether the newest report changed scope or opinion. In other words, the audit stopped being a sales artifact and became part of the ongoing vendor relationship.

What Are the Most Common SOC 2 Mistakes?

The most common SOC 2 mistakes are treating the report as one-and-done, performing compliance theater, and marketing a Type I as full compliance. Each one eventually costs more than doing it right, and I have watched all three happen up close.

One-and-done thinking is the classic. A SOC 2 report describes a past period, and buyers treat reports older than twelve months as expired. Controls rot quietly the moment attention moves on: access reviews slip, offboarding tickets pile up, the risk register gathers dust. The second-year audit then rediscovers everything the first one fixed.

Compliance theater is more dangerous because it looks like success. In 2022 I watched a startup write 40 policies in two weeks to hit an audit deadline. Nobody read them afterward, quarterly reviews existed only as calendar entries, and the year-two report came back with a string of exceptions their largest customer read line by line. Passing an audit while skipping the habits is renting a reputation, with interest.

The Type I shortcut rounds out the list. Plenty of vendors complete a Type I and market themselves as “SOC 2 compliant,” hoping nobody asks which type. Security teams always ask. The moment a reviewer catches the inflation, every other claim in your questionnaire gets re-checked, and deals slow down precisely when the badge was supposed to speed them up.

Scoping errors deserve an honorable mention as well. Some teams scope so narrowly that the report excludes the product customers actually buy, which reviewers notice in minutes. Others scope in every internal system, then pay for audit hours that prove nothing commercially. Scope to the promise you make customers, nothing more and nothing less.

Frequently Asked Questions

What is the difference between a SOC 1 and a SOC 2?

SOC 1 covers controls that affect a customer’s financial reporting, like a payroll processor’s calculations. By contrast, SOC 2 covers how a service organization protects customer data against the Trust Services Criteria. Pick SOC 1 when your service touches clients’ financial statements, and SOC 2 when you store or process their data.

Is SOC 2 the same as ISO 27001?

No. SOC 2 is an attestation report issued by a CPA firm, mostly expected by US buyers. ISO 27001 is a certification against an international standard, more common in Europe and Asia. The underlying security work overlaps heavily, so many vendors eventually hold both.

How do you get a SOC 2 certification?

Strictly speaking, you cannot, because SOC 2 is an attestation rather than a certification. You scope the criteria, close gaps in a readiness phase, collect evidence over an observation window, and then a licensed CPA firm examines everything and issues the report. Most first-timers complete the journey in six to twelve months.

Is SOC 2 legally required?

No law requires SOC 2. It is a market standard enforced by procurement and security teams, who routinely refuse to onboard data-handling vendors without a report. Legal requirements like GDPR or CCPA operate separately, and holding a SOC 2 report does not by itself satisfy them.

What is a SOC 2 Type II report?

A SOC 2 Type II report is an auditor’s examination of whether your controls operated effectively over a period, generally 3 to 12 months. It contains the auditor’s opinion, your system description, and every test result, including exceptions. Buyers treat it as the standard proof of security posture.

How long is a SOC 2 report valid?

Formally, a SOC 2 report never expires, because it describes a specific past period. In practice, buyers treat reports as stale twelve months after the window ends. That is why most vendors run continuous annual cycles, and why bridge letters exist to cover the gap between reports.

How much does a SOC 2 audit cost?

Audit fees alone commonly run from about 5,000 to 20,000 dollars for a Type I and 12,000 to 40,000 dollars for a Type II, depending on scope and firm. Total program cost lands higher once tooling, penetration testing, and internal hours join the bill. Budget all-in, not for the fee alone.

Can a small startup pass a SOC 2 audit?

Yes. SOC 2 scales to company size because you define the system and the controls being tested. A ten-person team with disciplined access management and clean offboarding can earn an unqualified opinion. Small teams usually lean on compliance automation to handle evidence collection without a dedicated hire.

So that is SOC 2 in full: an auditor’s verdict on whether your company treats customer data the way it claims to. Get the habits right and the report becomes a byproduct. Chase the badge alone and you will buy it again, at a worse price, every single year.

How would you rate this article?
Bad
Okay
Good
Amazing
Comments (0)
Comments (0)
98% accuracy, GDPR & CCPA ready

Prefer to Explore on Your Own?

Skip the call and start free — 15 credits, no credit card required. Upgrade or talk to us whenever you’re ready.

Free plan available · 50 credits/month · no credit card required