Information SecurityGlobal (US-led)

SOC 2 compliance

SOC 2 (Service Organization Control 2)

SOC 2 is an attestation against the AICPA Trust Services Criteria — security, and optionally availability, processing integrity, confidentiality and privacy. It's the credential most requested by North American enterprise buyers. Pelta helps you stand up and maintain SOC 2 with controls mapped to evidence that stays current between audits.

Who it's for

Does SOC 2 apply to you?

  • B2B SaaS and technology companies selling to US enterprises
  • Service organisations handling customer data
  • Teams that need to clear security questionnaires quickly

What SOC 2 actually is

SOC 2 is not a certification — it is an attestation. A licensed CPA firm examines your controls against the AICPA's Trust Services Criteria and issues a report describing what they found. That distinction matters: there is no pass/fail badge, there is a report your customers read, and its credibility rests on the auditor's opinion and the exceptions they note.

Because enterprise buyers in North America routinely ask for a SOC 2 report before signing, it has become the de facto security credential for B2B software. For most companies, the trigger to pursue SOC 2 is commercial rather than regulatory: a deal is blocked without it.

The path to a SOC 2 report

Scope

Criteria & systems

Gap assess

Where you stand

Remediate

Close the gaps

Observe

Type II window

Audit

CPA examination

Report

Share with buyers

The five Trust Services Criteria

Security is mandatory — it is the common criteria every SOC 2 report includes. The other four are optional and chosen based on what you promise customers. Adding criteria widens the audit, so pick deliberately rather than defensively.

Trust Services Criteria and when to include them
CriterionCoversInclude when
Security (required)Protection against unauthorised access and disclosureAlways — this is the common criteria
AvailabilitySystem uptime and operational resilienceYou commit to uptime SLAs
Processing IntegrityComplete, accurate, timely processingYou process transactions or financial data
ConfidentialityProtection of information designated confidentialYou handle customer-confidential business data
PrivacyHandling of personal information per your noticeYou process significant personal data

Type I vs Type II: which to pursue

A Type I report assesses whether your controls are suitably designed at a single point in time. A Type II assesses whether they actually operated effectively across an observation window — commonly three to twelve months. Type II is what most enterprise buyers ultimately want.

A common sequence is Type I first, to unblock a deal quickly and prove design, then Type II covering the following period. If you have time before the deal pressure arrives, going straight to Type II avoids paying for two audits.

For Type II, it is not enough that a control exists. The auditor samples evidence across the entire window — so a control you implemented in month five will not carry the earlier months.

What auditors look for

  • Documented policies and procedures covering security, access, change and incident management.
  • Access control with least privilege, strong authentication, and prompt de-provisioning when people leave.
  • Change management showing how code and infrastructure reach production with review and approval.
  • Monitoring, logging and alerting, with evidence that alerts are actually triaged.
  • Risk assessment performed and documented on a defined cadence.
  • Vendor management covering the sub-processors in your supply chain.
  • Incident response that has been tested, not just written.

Common pitfalls to avoid

  • Starting evidence collection near the end of the observation window, when the gaps can no longer be fixed retroactively.
  • Over-scoping the criteria, which multiplies audit effort without commercial benefit.
  • Treating SOC 2 as an annual project instead of an operating rhythm, then rebuilding everything each year.
  • Ignoring the overlap with ISO 27001 and doing the same control work twice.
How Pelta helps

Run SOC 2 on one connected platform

Trust Services Criteria mapped

Manage your controls directly against the SOC 2 criteria with AI-assisted policies.

Type I and Type II ready

Keep evidence continuously linked so a Type II observation window is a byproduct of how you operate.

Reuse across frameworks

Shared control mappings mean SOC 2 evidence also satisfies overlapping ISO 27001 controls.

Answer buyers fast

Evidence on hand to clear enterprise security reviews without slowing sales.

SOC 2 FAQs

What's the difference between SOC 2 Type I and Type II?+

Type I assesses the design of controls at a point in time; Type II assesses whether they operated effectively over a period, commonly 3 to 12 months. Most enterprise buyers ultimately want a Type II report.

Is SOC 2 a certification?+

No. SOC 2 is an attestation, not a certification. A licensed CPA firm examines your controls and issues a report with their opinion — there is no pass/fail certificate, which is why buyers read the report itself.

How long does SOC 2 take?+

A Type I can be reached relatively quickly once controls are designed and in place. A Type II additionally requires an observation window — commonly three to twelve months — during which controls must operate effectively.

Which Trust Services Criteria should I include?+

Security is always required. Add Availability if you commit to uptime SLAs, Processing Integrity if you process transactions, Confidentiality for customer-confidential data, and Privacy if you handle significant personal data. Every extra criterion widens the audit.

How much does SOC 2 cost?+

Costs vary widely by scope, criteria and auditor, and typically include both the audit fee and internal effort. The larger hidden cost is usually the manual work of collecting evidence across the observation window.

Do I need SOC 2 or ISO 27001?+

It depends on your market. SOC 2 is most requested by North American buyers; ISO 27001 is a globally recognised certification. Many companies eventually pursue both.

Can I reuse SOC 2 work for ISO 27001?+

Yes. SOC 2 and ISO 27001 overlap substantially. With shared control mappings and one evidence trail in Pelta, most SOC 2 evidence applies directly to ISO 27001.

See SOC 2 compliance on Pelta

Stand up SOC 2 Type I or Type II on Pelta — map Trust Services Criteria to controls, keep evidence continuously linked, and clear buyer security reviews faster.