What Is SOC 2?

SOC 2 is a US-centric attestation report, governed by the AICPA (American Institute of CPAs) and audited by licensed CPA firms, evaluating a company's controls against the Trust Services Criteria. Unlike a certification, it's an auditor's written opinion — and it's become the default trust signal US SaaS and cloud companies show enterprise customers.

The Trust Services Criteria

SOC 2 is built around five possible criteria: security (mandatory for every report), availability, processing integrity, confidentiality, and privacy. An organization scopes its audit to whichever criteria are actually relevant — a company with strict uptime commitments might include availability; one handling highly sensitive personal data might add privacy.

Type I vs. Type II

A Type I report checks whether controls are designed correctly at one point in time — a snapshot. A Type II report checks whether those same controls actually operated effectively over an observation window, commonly 3–12 months. Type II is significantly more meaningful to a customer evaluating a vendor, since it's evidence of sustained behavior, not a design review.

How it's different from a certification

SOC 2 doesn't produce a certificate; it produces a detailed report with the auditor's opinion, meant to be read (usually under NDA) by the customers and prospects who request it. This is a real structural difference from ISO 27001, which produces a pass/fail certification that's often displayed publicly. See how SOC 2 compares to ISO 27001 for the full picture.

The GRC work behind it

Preparing for a SOC 2 audit is standard GRC work: writing and maintaining policies mapped to the relevant Trust Services Criteria, collecting audit evidence continuously through the observation window, and tracking gaps in a risk register well before the auditor shows up.

Common Questions

Do all SOC 2 reports cover all five Trust Services Criteria?

No. The security criterion is mandatory for every SOC 2 report; the other four (availability, processing integrity, confidentiality, privacy) are optional and scoped based on what's actually relevant to the organization's service.

How long does a SOC 2 Type II audit period usually last?

Commonly 3 to 12 months. The report covers that entire window, showing whether controls operated effectively throughout — not just on the day of the audit.

Is a SOC 2 report public?

No, typically not. SOC 2 reports are usually shared under NDA with customers and prospects who request them, not published openly — unlike an ISO 27001 certificate, which is often shown as a public badge.

Want hands-on practice with these controls?

Try the GRC Track in CX Challenges, or get a personalized roadmap through 1:1 GRC mentorship.

Keep Reading

What Is GRC?

Governance, Risk, and Compliance, explained from the ground up.