Category: SOC 2
SOC 2 is an attestation report on a service organisation’s controls, produced by a licensed CPA firm under AICPA standards. It is not a certification and there is no SOC 2 certificate — what you receive is a report describing your controls and the auditor’s findings about them.
You choose which of the five Trust Services Criteria are in scope. Security, often called the common criteria, is always required. Availability, processing integrity, confidentiality and privacy are optional and should only be added when a customer genuinely asks for them, because each one widens the evidence you must maintain.
The distinction that matters most commercially is Type 1 versus Type 2. A Type 1 report assesses whether your controls are suitably designed at a single point in time. A Type 2 report assesses whether they also operated effectively across an observation period, typically three to twelve months. Enterprise buyers almost always want Type 2; Type 1 is best understood as a way to unblock a deal while the Type 2 window runs.
SOC 2 readiness is largely a documentation and evidence-collection exercise. The policies auditors expect are predictable, and the failure modes are consistent: scope drawn too wide, controls that are described but not consistently operated, and evidence gathered retrospectively at the end of the period rather than continuously throughout it.
The guides below cover what a SOC 2 audit involves, how to prepare, the Trust Services Criteria in detail, the documentation you need, what it costs and how long it takes, and how SOC 2 compares with ISO 27001.