AuditXYZ

Lesson 1 of 5

What Is SOC 2? A Complete Introduction

12 min readBeginner

What Is SOC 2?

SOC 2 (System and Organization Controls 2) is a compliance framework developed by the American Institute of Certified Public Accountants (AICPA). It evaluates how well a service organization protects customer data based on the Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.

For most B2B SaaS companies selling to mid-market and enterprise customers, SOC 2 is the first compliance framework they pursue. It has become the baseline expectation for vendors handling customer data — the thing procurement teams ask for before they will even schedule a security review. If your sales team keeps hearing "send us your SOC 2" and you do not have one, this lesson explains exactly what you are being asked for and what it takes to get it.

Why SOC 2 Exists

SOC 2 was created to give businesses a standardized way to evaluate the security practices of their service providers. Before SOC 2, every customer had their own security questionnaire with different questions and formats. A vendor selling to fifty enterprises answered fifty overlapping-but-different questionnaires, and every buyer had to trust self-reported answers with no independent verification.

SOC 2 solves both problems. It provides a common language — the Trust Services Criteria — and a trusted third-party assessment performed by a licensed CPA firm under AICPA attestation standards. Instead of taking a vendor's word for it, a buyer reads an independent auditor's opinion on whether the vendor's controls are designed and operating effectively.

The framework sits within the broader SOC family the AICPA maintains. The current criteria are the 2017 Trust Services Criteria, updated with revised implementation guidance ("points of focus") in 2022. The 2022 revision did not change the criteria themselves — it modernized the guidance around them to reflect cloud infrastructure, data governance, and current threat patterns. When someone says "SOC 2," they mean an examination against these criteria.

An important technical point that trips up newcomers: SOC 2 is an attestation, not a certification. There is no certificate, no badge issued by the AICPA, and no pass/fail registry. The deliverable is a detailed report containing the auditor's professional opinion. Companies that display a "SOC 2 certified" badge are, strictly speaking, misusing the terminology — the accurate phrasing is that they have completed a SOC 2 examination and received an unqualified (clean) opinion.

Who Needs SOC 2

Any company that stores, processes, or transmits customer data on behalf of other businesses may be asked for a SOC 2 report. In practice, that includes:

  • SaaS companies — the largest population by far. If businesses put their data in your product, expect SOC 2 requests.
  • Cloud infrastructure and platform providers — hosting, PaaS, API platforms, data pipelines.
  • Managed service providers and IT outsourcers — anyone with administrative access to client systems.
  • Data analytics, AI, and BI vendors — especially those ingesting customer datasets for processing or model training.
  • Fintech and healthtech companies — usually alongside industry-specific requirements like PCI DSS or HIPAA.
  • Back-office service providers — payroll processors, HR platforms, billing services, customer support tooling.

The trigger is almost always commercial. A prospect's procurement or security team asks for the report during vendor review, and the deal stalls until you produce one. Companies typically start the SOC 2 process when deal sizes cross into the range where buyers run formal vendor risk programs — often around the point they begin selling to companies with more than a few hundred employees. Starting before the first blocked deal is cheaper and far less stressful than starting during one.

There is also an internal case for SOC 2 that founders underrate: the process forces you to formalize access control, change management, vendor management, and incident response while the company is still small enough to do it cleanly. Companies that wait until 200 employees to implement access reviews pay a much higher retrofit cost.

The SOC Family: SOC 1 vs SOC 2 vs SOC 3

"SOC 2" is one of three report types, and buyers occasionally ask for the wrong one, so know the differences:

ReportFocusAudienceTypical Use
SOC 1Controls relevant to customers' financial reporting (ICFR)Customer finance teams and their financial auditorsPayroll, billing, claims, and transaction processors whose output feeds customer financials
SOC 2Controls over security, availability, processing integrity, confidentiality, privacyCustomer security, procurement, and risk teamsThe general-purpose vendor security report; the SaaS default
SOC 3Same criteria as SOC 2, summarizedGeneral publicA short, freely distributable summary with no control detail; marketing use

If a prospect asks for "your SOC report," they almost always mean SOC 2. SOC 1 only applies if your service directly affects customers' financial statements. SOC 3 is optional and derived from a SOC 2 Type 2 — some companies publish one so they can share something publicly without an NDA.

Within SOC 2 there are also two report types — Type 1 (controls designed properly at a point in time) and Type 2 (controls operating effectively over a period, typically 3 to 12 months). Type 2 is what sophisticated buyers expect. We compare them in depth in the Type 1 vs Type 2 lesson.

The Trust Services Criteria at a Glance

Every SOC 2 examination includes Security — also called the Common Criteria — which covers organizational governance, risk assessment, logical and physical access, system operations, and change management. The other four categories are optional and added based on what your service commits to customers:

  • Availability — for services with uptime commitments or SLAs
  • Processing Integrity — for services where accurate, complete processing is the product (payments, calculations, data transformation)
  • Confidentiality — for services holding sensitive business information under confidentiality commitments
  • Privacy — for services making specific commitments about personal information handling

Most first-time reports scope Security only, or Security plus Availability. The full breakdown of each category, and how to scope correctly, is covered in the Trust Service Criteria lesson.

SOC 2 vs ISO 27001

This is the comparison every founder eventually needs to make. The two frameworks overlap heavily in substance — perhaps 70 to 80 percent of the underlying controls are the same — but differ in structure, output, and geography:

DimensionSOC 2ISO 27001
OriginAICPA (United States)ISO/IEC (international)
OutputAttestation report on a period or dateCertificate valid for a 3-year cycle
ApproachCriteria-based — address the Trust Services CriteriaRisk-based — build an ISMS, select controls per your risks
Current versionTSC 2017 (2022 revised points of focus)ISO/IEC 27001:2022, 93 Annex A controls
AuditorLicensed CPA firmAccredited certification body
CadenceAnnual examinationStage 1 + Stage 2, then annual surveillance, recertification every 3 years
Strongest recognitionNorth AmericaEurope, Asia, and globally
Report sharingUnder NDA, full control detailCertificate is public; internal docs stay private

The practical decision rule: follow your customers. If your pipeline is primarily North American, start with SOC 2. If you sell into Europe or Asia, or your buyers explicitly ask for a certificate, start with ISO 27001. Many companies eventually hold both, and because of the control overlap, the second framework costs a fraction of the first — especially if your evidence and policies are managed in a compliance automation platform that maps controls across frameworks.

The SOC 2 Report: What You Actually Get

A SOC 2 report is a substantial document — commonly 40 to 100+ pages — issued by a licensed CPA firm. It contains:

  1. The auditor's opinion — the headline. An unqualified opinion means controls met the criteria. A qualified opinion means the auditor found material problems in specific areas. An adverse opinion (rare) means pervasive failure.
  2. Management's assertion — your formal statement that the system description is accurate and controls meet the criteria.
  3. The system description — a detailed narrative of your service, infrastructure, software, people, procedures, and data, plus the boundaries of the system being examined.
  4. Controls, tests, and results — the matrix of each control, how the auditor tested it, and the results, including any exceptions (instances where a control did not operate as described).
  5. Complementary user entity controls (CUECs) — things your customers must do on their side (for example, managing their own users' access) for the system to be secure.

Buyers read the opinion first, then scan for exceptions, then check the scope covers the product they are buying. A report with a few minor exceptions and a clean opinion is normal; a qualified opinion or an obviously narrow scope invites hard questions.

The report is shared with customers under NDA — usually through your trust portal or on request from sales. It is not published publicly.

What SOC 2 Costs and How Long It Takes

Budget across three buckets:

  • Audit fees: roughly $8,000–$25,000 for a first Type 2 at a startup-focused firm, scaling with scope, criteria, and company size. Larger firms charge more.
  • Tooling: compliance automation platforms typically run $8,000–$30,000 per year depending on company size and frameworks; they replace most manual evidence collection.
  • Internal effort and remediation: the real cost — engineering time for gaps like SSO enforcement, logging, and vendor reviews, plus a compliance owner's time. For a small startup with decent security hygiene, expect 2 to 4 months from kickoff to audit-ready, then the observation window before the Type 2 report is issued.

A realistic end-to-end timeline for a first Type 2 report is about 6 to 9 months: 2 to 3 months of implementation, a 3-month observation period, and 4 to 8 weeks of audit fieldwork and reporting.

Is SOC 2 Right for You? A Decision Checklist

Work through this list before committing budget:

  • Prospects or customers have asked for a SOC 2 report or lengthy security questionnaires
  • Your buyers are primarily in North America (if mostly EU/Asia, evaluate ISO 27001 first)
  • You store, process, or transmit customer data as part of your service
  • Deal sizes justify the investment — enterprise or mid-market contracts are in your pipeline
  • You can name an internal owner for the program (founder, engineering lead, or ops lead)
  • You have, or will adopt, foundational controls: SSO/MFA, access reviews, endpoint management, change management, vendor tracking
  • You have budget for an auditor and, optionally, a compliance automation platform
  • You understand whether buyers will accept a Type 1 or expect a Type 2
  • You have checked whether adjacent requirements (HIPAA, PCI DSS, GDPR) also apply and can share controls

If you checked most of these, SOC 2 is almost certainly the right first framework, and the sooner you start the observation clock, the sooner you have a report to hand to sales.

Frequently Asked Questions

Is SOC 2 legally required?

No. SOC 2 is a market requirement, not a legal one. No law mandates it. But contracts increasingly do — many enterprise MSAs require vendors to maintain a current SOC 2 Type 2 report, which makes it contractually binding once you sign.

How long is a SOC 2 report valid?

Formally, a report covers only its stated period or date — there is no expiration. In practice, buyers treat reports older than 12 months as stale, which is why companies run annual Type 2 examinations with back-to-back observation periods and issue a "bridge letter" to cover the gap between the period end and the report request date.

Can a startup with five people get SOC 2?

Yes. The criteria scale to organization size — auditors evaluate whether controls fit your environment, not whether you have an enterprise security team. Small companies routinely complete SOC 2 with one part-time owner plus an automation platform. The controls (MFA, access reviews, change management via pull requests, vendor lists) are things a well-run five-person company should have anyway.

Does SOC 2 cover our whole company?

Only the system described in the report. You define the scope — typically your production SaaS product and the infrastructure, people, and processes supporting it. Internal IT and unrelated products can be excluded, but be careful: a scope that excludes the product a customer is buying will not satisfy them.

What happens if we fail the audit?

SOC 2 has no formal pass/fail. The auditor issues an opinion. Individual control exceptions are documented in the report and are common; a small number rarely worries buyers. Widespread failures produce a qualified opinion, which most buyers treat as a red flag. Good auditors flag serious problems during fieldwork so you can remediate before the report is finalized or delay the period end.

Do we need a compliance automation platform to get SOC 2?

No, but most startups use one. Doing SOC 2 manually means maintaining spreadsheets of controls, chasing screenshots quarterly, and writing policies from scratch. Platforms automate evidence collection from your cloud, identity provider, and HR systems, provide policy templates, and monitor control drift continuously. For teams without a dedicated compliance hire, the time savings usually exceed the subscription cost.

In the next lesson, we will dive into the Trust Service Criteria.


Choosing the right audit firm and tooling shapes your entire SOC 2 experience. AuditXYZ helps you compare compliance automation platforms and find the right auditor — features, integrations, and pricing side by side — so you start with the right stack.