What Is a SOC 2 Report?
A SOC 2 report is an independent auditor's written opinion on whether your company's security controls are designed properly — and, in most cases, whether they actually operated effectively over a period of months. It is issued by a licensed CPA firm under standards set by the AICPA (American Institute of Certified Public Accountants), and it has become the default proof of security that B2B customers in North America ask for before they will sign a contract.
If a prospect's security questionnaire just asked "Do you have a SOC 2?", this guide explains exactly what that document is, what is inside it, what it costs, and how to get one. For a deeper dive into the framework itself, see our SOC 2 learning hub.
The Short Definition
SOC 2 stands for System and Organization Controls 2. A SOC 2 report is the deliverable of a SOC 2 examination (technically an "attestation engagement"): a third-party CPA evaluates your controls against the AICPA's Trust Service Criteria and writes a formal opinion.
Three things follow from that definition that trip people up:
- It is a report, not a certificate. There is no "SOC 2 certified" badge issued by a governing body. You receive a confidential document, typically 40–100+ pages, that you share with customers under NDA. (Everyone says "SOC 2 certified" anyway — auditors have given up correcting it.)
- It is an attestation, not a pass/fail test against a fixed checklist. You define your own controls; the auditor tests whether they meet the criteria and whether they work. Two companies can both have clean SOC 2 reports with quite different control sets.
- It is opinion-based. The most important sentence in the entire report is whether the auditor's opinion is unqualified (clean) or qualified (problems found).
Who Issues a SOC 2 Report?
Only a licensed CPA firm can issue a SOC 2 report. The AICPA defines the attestation standards (SSAE 18 and its successors) and the Trust Service Criteria; the CPA firm performs the examination and signs the opinion.
This matters practically:
- Compliance automation platforms (Vanta, Drata, Secureframe, and others) cannot issue your report. They prepare you and collect evidence; a CPA firm still performs the audit.
- Consultants and security firms without CPA licensure cannot issue one either, no matter how thorough their assessment.
- Firm reputation affects how much weight your report carries. A Big Four report and a boutique firm's report are both valid, but enterprise procurement teams sometimes look harder at reports from firms they have never heard of. Our directory of US audit firms lists established SOC 2 practices with pricing.
What's Inside a SOC 2 Report
Every SOC 2 report contains four main sections (a fifth, optional section sometimes appears at the end):
1. Independent Auditor's Opinion
The auditor's formal conclusion, usually two or three pages at the front. The possible opinions:
- Unqualified (clean): Controls were suitably designed and (for Type 2) operated effectively. This is what you want.
- Qualified: The controls were mostly fine, except for specific identified failures. Customers can still accept a qualified report, but they will ask about the exceptions.
- Adverse: Pervasive failures. Rare, and effectively unusable with customers.
- Disclaimer: The auditor could not obtain enough evidence to form an opinion at all.
2. Management's Assertion
A signed statement from your leadership asserting that the system description is accurate and controls meet the criteria. This is your company formally putting its name behind the report's contents — which is why the auditor's role is called attestation: they are attesting to your assertion.
3. System Description (Section 3)
A detailed narrative, written by your company and examined by the auditor, describing what is in scope: the services covered, infrastructure and software, data flows, personnel, processes, subservice organizations (like AWS or GCP, usually "carved out"), and complementary controls your customers are expected to maintain themselves. Savvy report readers spend real time here, because scope games hide in this section — a report that only covers a marketing site tells you nothing about the actual product.
4. Controls Matrix and Test Results (Section 4)
The longest section: a table listing every control, mapped to the Trust Service Criteria, with the auditor's test procedure and result for each. In a Type 2 report, each row shows how the control was tested (inquiry, inspection, observation, re-performance) and whether exceptions were noted — e.g., "for 2 of 25 sampled terminations, access was not removed within 24 hours." A handful of minor exceptions is normal and does not by itself prevent a clean opinion.
5. Other Information (optional Section 5)
Management's responses to exceptions, planned remediation, or additional context. Unaudited — treat it as the company's side of the story.
Type 1 vs Type 2
The single most common question about SOC 2 reports. The difference is what the auditor opines on and over what time:
| SOC 2 Type 1 | SOC 2 Type 2 | |
|---|---|---|
| What it tests | Design of controls | Design and operating effectiveness |
| Time basis | A single point in time ("as of" date) | A period, typically 3–12 months |
| What it proves | Controls exist and are suitably designed | Controls actually worked, consistently, for months |
| Typical audit cost | ~$5,000 – $20,000 | ~$10,000 – $30,000+ |
| Time to first report | 1–3 months | 4–15 months (observation window + audit) |
| Market acceptance | Acceptable as a first step; often a stopgap | The standard ask from mid-market and enterprise buyers |
| Common use | New startups proving initial posture | Everyone else; renewed annually |
Most companies do a Type 1 first (or skip it entirely), start their Type 2 observation window immediately, and then renew Type 2 annually with back-to-back periods so there are no coverage gaps. More detail in our Type 1 vs Type 2 guide.
The Five Trust Service Criteria
SOC 2 examinations are scoped to one or more of five Trust Service Criteria categories. Only one is mandatory:
| Criteria | Required? | What it covers | Who typically adds it |
|---|---|---|---|
| Security (Common Criteria) | Yes — always in scope | Access controls, change management, risk management, monitoring, incident response | Everyone |
| Availability | Optional | Uptime commitments, capacity planning, backup and disaster recovery | SaaS with SLAs, infrastructure products |
| Confidentiality | Optional | Protection and disposal of confidential business data | Companies handling sensitive customer business data |
| Processing Integrity | Optional | Complete, accurate, timely, authorized processing | Payments, payroll, billing, data pipelines |
| Privacy | Optional | Personal information lifecycle against the company's privacy notice | Consumer-data-heavy businesses (rarely selected) |
Security alone is a perfectly legitimate report. Security + Availability + Confidentiality is the most common combination for B2B SaaS. Each added category adds controls, evidence, and some audit cost — add them when customers ask, not speculatively.
How to Get a SOC 2 Report: 6-Step Checklist
- 1. Scope the engagement. Decide which product/system is covered, which Trust Service Criteria you need (start with Security; add Availability/Confidentiality if customers expect it), and whether you will do a Type 1 first or go straight to Type 2.
- 2. Run a gap assessment. Compare your current practices against the criteria. Most companies find gaps in formal policies, access reviews, vendor management, and risk assessment — not in technical security.
- 3. Remediate and implement controls. Write and adopt policies, enforce MFA and least privilege, set up change management in your dev workflow, stand up vendor reviews, security training, and incident response. A compliance automation platform shortens this phase dramatically by generating policies and monitoring controls continuously — LowerPlane, for example, uses AI to generate evidence and includes a free tier for early-stage startups.
- 4. Operate through the observation window (Type 2). Run your controls for the 3–12 month period. Collect evidence as you go — access review sign-offs, closed tickets, training records — rather than scrambling at the end.
- 5. Select a CPA firm and undergo the audit. The auditor requests evidence, samples transactions from the period, interviews control owners, and tests each control. Expect 3–8 weeks from fieldwork start to draft report.
- 6. Review and distribute. Check the draft for accuracy, respond to any exceptions in Section 5, receive the final signed report, and share it with customers under NDA — often via a trust center page. Then start next year's period immediately.
How Customers Actually Read Your Report
Understanding what a security reviewer looks for helps you produce a report that closes deals:
- The opinion first. Qualified or clean?
- Report type and period. Type 2 covering a recent, continuous 12 months is the gold standard. A report whose period ended 10 months ago raises freshness questions — expect requests for a bridge letter (a short management-signed statement covering the gap between the period end and today).
- Scope. Does the system description actually cover the product they are buying?
- Criteria selected. If they care about uptime and you did not include Availability, expect follow-up.
- Exceptions. A few minor ones with reasonable management responses are fine; patterns of access-control failures are not.
- Subservice organizations and CUECs. What did you carve out (AWS, etc.), and what controls are customers themselves responsible for?
Common Mistakes That Weaken a SOC 2 Report
Getting a report is not the same as getting a report that survives customer scrutiny. The patterns that come back to bite companies:
- Scoping too narrowly. A report covering only a subset of infrastructure or a single minor product looks like evasion to an experienced reviewer. Scope the system your customers actually buy.
- Choosing only the Security criteria when customers expect Availability. If you sell uptime SLAs, a Security-only report invites the follow-up question. Adding Availability at renewal costs far less than losing momentum in a security review.
- Letting the period lapse. A gap between Type 2 periods (say, a report ending December 31 and the next period starting in April) is visible and raises the question of what happened in between. Run periods back to back from day one.
- Ignoring exceptions instead of responding. Section 5 exists so management can explain an exception and describe remediation. A report with exceptions and no response reads worse than the exception itself.
- Treating the system description as boilerplate. Reviewers read it. Vague descriptions, missing subservice organizations, or CUECs that quietly offload critical controls onto customers all generate questionnaire follow-ups that a precise description would have prevented.
- Picking an auditor purely on price. The cheapest firm that rubber-stamps everything produces a report that sophisticated buyers discount — and some will ask who your auditor is before they even open the PDF.
What Does a SOC 2 Report Cost, and How Long Does It Take?
All-in costs (audit + preparation) for a typical startup in 2026:
| Component | Typical range |
|---|---|
| Type 1 audit fee | $5,000 – $20,000 |
| Type 2 audit fee | $10,000 – $30,000 |
| Compliance automation platform | $4,000 – $25,000/year |
| Readiness consultant (optional) | $10,000 – $30,000 |
| Pen test (commonly expected) | $4,000 – $15,000 |
Lean path: automation platform + right-sized CPA firm, no consultant — commonly $15,000–$30,000 all-in for a first Type 2. Timeline: 2–4 months to become audit-ready, plus a 3-month minimum observation window for Type 2, plus 3–8 weeks of audit and reporting. Companies that start from zero typically hold a Type 2 report in hand 6–9 months after kickoff. See our cheapest SOC 2 guide resources for cost-cutting specifics.
Frequently Asked Questions
What is a SOC 2 report in one sentence?
It is a confidential report, issued by an independent CPA firm under AICPA standards, containing the auditor's opinion on whether your security controls are suitably designed (Type 1) and operated effectively over a period of time (Type 2).
Is SOC 2 a certification?
Technically no — it is an attestation. There is no certificate or registry; the deliverable is the report itself, shared under NDA. In everyday usage, "SOC 2 certified" and "SOC 2 compliant" both mean "we have a current SOC 2 report with a clean opinion."
How long is a SOC 2 report valid?
A Type 2 report covers a specific period and has no formal expiration, but the market treats reports as stale about 12 months after the period ends. Nearly all companies renew annually with consecutive periods, using bridge letters to cover the gap between period end and report issuance.
What is the difference between SOC 1, SOC 2, and SOC 3?
SOC 1 covers controls relevant to customers' financial reporting (payroll processors, billing platforms). SOC 2 covers security and related criteria — the one SaaS buyers ask for. SOC 3 is a short, public, general-use summary of a SOC 2 examination that omits the detailed controls and test results; it is a marketing artifact, not a substitute in security reviews.
Can my report have exceptions and still be "clean"?
Yes. Exceptions are individual control test failures; the opinion reflects the overall picture. A report can list several minor exceptions and still carry an unqualified opinion if the auditor judges the criteria were still met. Widespread or severe failures lead to a qualified opinion.
Who can see my SOC 2 report?
Distribution is restricted — typically to management, customers, and prospects with a legitimate interest, under NDA. Most companies handle distribution through a trust center portal with click-through NDAs rather than emailing PDFs. If you want something fully public, ask your auditor about a SOC 3, which is designed for unrestricted distribution.
What happens during the audit itself?
For a Type 2, expect an evidence request list (often 100–300 items), a kickoff walkthrough of your system description, several weeks of fieldwork where the auditor samples records from the period — pull requests, terminated-employee access removals, access review sign-offs, incident tickets — plus interviews with control owners in engineering, IT, and HR. Well-prepared companies with automated evidence collection spend perhaps 20–40 internal hours across the whole engagement; unprepared ones spend several times that chasing screenshots.
Do I need a lawyer or just an auditor?
Just an auditor (a CPA firm). You may optionally use a readiness consultant or, more commonly today, a compliance automation platform for preparation — but the report itself always comes from the CPA firm.
How AuditXYZ Helps
The two decisions that most affect your SOC 2 cost and timeline are which automation platform prepares you and which CPA firm audits you. AuditXYZ exists to make both comparable: compare compliance automation platforms on price, integrations, and framework coverage, and browse vetted auditors — including US-based CPA firms — with transparent pricing and typical turnaround times. Pick both well and your first SOC 2 report is a project, not an ordeal.