Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

SOC 2 compliance explained - the five Trust Services Criteria, Type 1 vs Type 2 and the audit

SOC 2 Explained: The Complete Compliance Guide

SOC 2 compliance has become a standard requirement for technology and SaaS companies that want to sell to security-conscious customers, especially in North America. A SOC 2 report is one of the clearest ways to prove you protect customer data. This guide is your complete introduction to what SOC 2 is, how it works, and how to achieve it.

SOC 2 compliance explained - the five Trust Services Criteria, Type 1 vs Type 2 and the audit

Below we cover what SOC 2 is, why it matters, the five Trust Services Criteria, the difference between Type 1 and Type 2, how the audit works, and a practical path to compliance.

What is SOC 2?

SOC 2 (System and Organization Controls 2) is a reporting framework developed by the American Institute of CPAs (AICPA). It defines how service organizations should manage customer data based on a set of trust principles, and it results in an independent auditor’s report on the design — and, for Type 2, the operating effectiveness — of your controls. Unlike ISO 27001, SOC 2 produces an attestation report rather than a certificate, and it is especially familiar to buyers in the United States.

Why SOC 2 matters

For SaaS and technology vendors, SOC 2 has become a gatekeeper to enterprise sales. Prospective customers increasingly require a SOC 2 report before they will trust you with their data, and having one shortens security reviews and shortens sales cycles. It also drives genuine improvement, forcing you to formalise the security, availability, and confidentiality controls that protect both you and your customers. In competitive markets, a clean SOC 2 report is a powerful differentiator.

The five Trust Services Criteria

SOC 2 is built on five Trust Services Criteria, and you choose which apply to your report:

  • Security — protection of systems against unauthorised access. This is the common criteria and is always included.
  • Availability — systems are available for operation and use as agreed.
  • Processing integrity — processing is complete, valid, accurate, and timely.
  • Confidentiality — information designated as confidential is protected.
  • Privacy — personal information is handled in line with commitments and criteria.

Most organizations start with Security and add the criteria most relevant to their service and customer commitments.

SOC 2 Type 1 vs Type 2

There are two report types. A Type 1 report assesses whether your controls are suitably designed at a single point in time. A Type 2 report goes further, testing whether those controls operated effectively over a period — typically three to twelve months. Type 2 carries far more weight with customers because it proves your controls work in practice over time, so many organizations pursue Type 1 first and then Type 2.

How a SOC 2 audit works

A licensed CPA firm performs the SOC 2 examination. You define your scope and criteria, design and implement controls, and (for Type 2) operate them over the review period while gathering evidence. The auditor then tests your controls, reviews evidence, and issues the report with their opinion. The heaviest lifting is defining controls and maintaining evidence — which is exactly where a mapped toolkit saves significant time.

SOC 2 vs ISO 27001

SOC 2 and ISO 27001 both demonstrate strong information security but suit different markets — SOC 2 is a US attestation report, while ISO 27001 is an international certification. The underlying controls overlap heavily, so organizations often pursue both, and a strong ISO 27001 ISMS covers much of what SOC 2 requires. If you are deciding which to prioritise, our ISO 27001 vs SOC 2 guide breaks down the choice.

How to achieve SOC 2 compliance

A practical path starts with selecting your Trust Services Criteria and scope, then performing a readiness assessment to find gaps. From there you implement the required controls, write the supporting policies, and — for Type 2 — operate them while collecting evidence, before engaging a CPA firm for the examination. Starting from a mapped toolkit turns the documentation-heavy preparation into a structured, achievable programme.

Get SOC 2 ready the fast way.

Our SOC 2 Toolkit delivers the policies, control documentation, and evidence templates mapped to the Trust Services Criteria — so you prepare for your Type 1 or Type 2 examination efficiently, in Word and Excel.

Explore the SOC 2 Toolkit →

Frequently asked questions

What is SOC 2 in simple terms?

SOC 2 is an AICPA reporting framework that shows, through an independent auditor’s report, that a service organization manages customer data securely against a set of trust principles.

What are the five Trust Services Criteria?

Security, availability, processing integrity, confidentiality, and privacy. Security is always included; you add the others based on your service and commitments.

What is the difference between SOC 2 Type 1 and Type 2?

Type 1 assesses control design at a point in time; Type 2 tests operating effectiveness over a period, usually three to twelve months, and carries more weight with customers.

Is SOC 2 a certification?

No. SOC 2 results in an attestation report from a CPA firm rather than a certificate. ISO 27001 is the equivalent certifiable standard.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.