What SOC 2 actually is
SOC 2 is not a certification — it is an attestation. A licensed CPA firm examines your controls against the AICPA's Trust Services Criteria and issues a report describing what they found. That distinction matters: there is no pass/fail badge, there is a report your customers read, and its credibility rests on the auditor's opinion and the exceptions they note.
Because enterprise buyers in North America routinely ask for a SOC 2 report before signing, it has become the de facto security credential for B2B software. For most companies, the trigger to pursue SOC 2 is commercial rather than regulatory: a deal is blocked without it.
Scope
Criteria & systems
Gap assess
Where you stand
Remediate
Close the gaps
Observe
Type II window
Audit
CPA examination
Report
Share with buyers
The five Trust Services Criteria
Security is mandatory — it is the common criteria every SOC 2 report includes. The other four are optional and chosen based on what you promise customers. Adding criteria widens the audit, so pick deliberately rather than defensively.
| Criterion | Covers | Include when |
|---|---|---|
| Security (required) | Protection against unauthorised access and disclosure | Always — this is the common criteria |
| Availability | System uptime and operational resilience | You commit to uptime SLAs |
| Processing Integrity | Complete, accurate, timely processing | You process transactions or financial data |
| Confidentiality | Protection of information designated confidential | You handle customer-confidential business data |
| Privacy | Handling of personal information per your notice | You process significant personal data |
Type I vs Type II: which to pursue
A Type I report assesses whether your controls are suitably designed at a single point in time. A Type II assesses whether they actually operated effectively across an observation window — commonly three to twelve months. Type II is what most enterprise buyers ultimately want.
A common sequence is Type I first, to unblock a deal quickly and prove design, then Type II covering the following period. If you have time before the deal pressure arrives, going straight to Type II avoids paying for two audits.
What auditors look for
- Documented policies and procedures covering security, access, change and incident management.
- Access control with least privilege, strong authentication, and prompt de-provisioning when people leave.
- Change management showing how code and infrastructure reach production with review and approval.
- Monitoring, logging and alerting, with evidence that alerts are actually triaged.
- Risk assessment performed and documented on a defined cadence.
- Vendor management covering the sub-processors in your supply chain.
- Incident response that has been tested, not just written.
Common pitfalls to avoid
- Starting evidence collection near the end of the observation window, when the gaps can no longer be fixed retroactively.
- Over-scoping the criteria, which multiplies audit effort without commercial benefit.
- Treating SOC 2 as an annual project instead of an operating rhythm, then rebuilding everything each year.
- Ignoring the overlap with ISO 27001 and doing the same control work twice.