What Is SOC 2? A Plain-English Guide for Founders
ISO Cloud Consulting editorial team
SOC 2 is an independent audit report that shows customers how well a service company protects their data. A licensed CPA firm tests your controls against the AICPA Trust Services Criteria and issues an opinion. It is not a certification. Founders usually pursue it because enterprise buyers ask for it before signing.
Key facts
- SOC 2 is an attestation report by a licensed CPA firm under AICPA standards, not a certificate.
- It measures you against the 2017 Trust Services Criteria (revised points of focus, 2022): 61 criteria in five categories.
- Security (33 common criteria, CC1 to CC9) is always in scope; the other four categories are optional.
- Type 1 covers design at a point in time; Type 2 covers operating effectiveness over a period, commonly 3 to 12 months.
- Reports are restricted-use: you share them with customers and prospects, typically under NDA.
- No law requires SOC 2. Customers do.
What is SOC 2 in plain English?
SOC 2 is a structured way for an outside auditor to tell your customers, "we checked, and this company's security controls do what it says they do." It replaces dozens of one-off security reviews with one standard report.
SOC stands for System and Organization Controls. The framework comes from the AICPA, the US accounting profession's standards body, which is why the auditor must be a CPA firm rather than a security consultancy. The criteria describe outcomes, such as "access is removed when people leave", not specific tools. You design the controls; the auditor tests them.
That flexibility is good news for a startup. A 12-person team on one cloud provider is not expected to run the same controls as a bank. It is expected to have sensible controls that fit its risks, written down and actually operating.
Is SOC 2 a certification?
No. SOC 2 is an attestation: a CPA firm gives a professional opinion on your controls. You get a report, not a certificate, and there is no official register of "SOC 2 certified" companies.
The distinction matters in two ways. First, customers read the report itself, including any exceptions the auditor found, so a report is only as reassuring as its contents. Second, the report covers a defined system and period. Saying "we are SOC 2 compliant" without a current report behind it will not survive a careful procurement team.
Why do customers ask for a SOC 2 report?
Customers ask for SOC 2 because they remain accountable for their data even when you hold it. A report from an independent CPA firm lets their security team rely on your controls without auditing you themselves.
In practice it shows up as a line in a security questionnaire, a procurement checklist or a contract. For many US B2B software companies, it becomes a sales requirement the moment they move from small customers to mid-sized and enterprise buyers. It can also shorten reviews with partners and investors.
What does a SOC 2 report contain?
A SOC 2 report has four core sections: the auditor's opinion, management's assertion, the system description and the detailed controls with the auditor's tests. A Type 2 report also includes test results and any exceptions.
| Section | Who writes it | What it says |
|---|---|---|
| Independent service auditor's report | CPA firm | The opinion: whether the description is fair and controls meet the criteria |
| Management's assertion | You | Your signed statement that the description and controls are accurate |
| System description | You | Services, infrastructure, software, people, data, processes and key vendors |
| Criteria, controls and tests | Both | Each control mapped to criteria; in Type 2, the tests performed and results |
The system description follows the AICPA SOC 2 description criteria. Writing it well is one of the most underestimated tasks for a first audit.
What are the Trust Services Criteria?
The Trust Services Criteria are the 61 criteria a SOC 2 auditor tests against. They sit in five categories. Security is mandatory; you add the others when your customers need them.
| Category | Criteria IDs | Count | Add it when |
|---|---|---|---|
| Security (common criteria) | CC1 to CC9 | 33 | Always required |
| Availability | A1.1 to A1.3 | 3 | Customers depend on your uptime |
| Confidentiality | C1.1 to C1.2 | 2 | You hold customers' confidential business data |
| Processing Integrity | PI1.1 to PI1.5 | 5 | You process transactions or calculations customers rely on |
| Privacy | P1 to P8 | 18 | You handle personal information and customers ask for it |
CC1 to CC5 mirror the COSO internal control framework: control environment, communication, risk assessment, monitoring and control activities. CC6 to CC9 cover access, operations, change management and risk mitigation, including vendors. The full criteria are published by the AICPA.
What does SOC 2 look like in a small company?
In a small company, SOC 2 is a handful of routines that someone owns and records. It is less about new paperwork and more about proving that sensible habits happen every time.
Take Fernleaf Analytics (fictional), a 15-person SaaS company on one cloud provider. Its SOC 2 controls might look like this:
- Everyone signs in through single sign-on with MFA, and the CTO reviews who can reach production every quarter.
- Every code change goes through a pull request that another engineer approves before it can merge.
- Laptops are managed, encrypted and lock automatically.
- New hires complete security training and acknowledge policies in their first week; leavers lose access on their last day.
- A vulnerability scanner runs weekly, and critical findings are fixed within a deadline set in policy.
- Once a year, leadership updates the risk register, reads key vendors' SOC 2 reports and tests a backup restore.
None of this is exotic. The SOC 2 work is writing it down, doing it consistently and keeping the evidence.
How is SOC 2 different from SOC 1 and SOC 3?
SOC 1 covers controls relevant to your customers' financial reporting. SOC 2 covers security and the other Trust Services categories. SOC 3 is a short, general-use summary of a SOC 2 examination that you can publish openly.
| Report | Focus | Audience |
|---|---|---|
| SOC 1 | Controls affecting customers' financial statements | Customers and their financial auditors |
| SOC 2 | Security, plus optional availability, confidentiality, processing integrity, privacy | Customers and prospects, restricted use |
| SOC 3 | Same criteria as SOC 2, summary only | Anyone, general use |
Most software companies need SOC 2. If you run payroll, billing or other processes that feed customers' financial statements, you may be asked for SOC 1 as well.
How long does SOC 2 take?
A small, cloud-based company with a dedicated owner can often be ready for a Type 1 in about three months. A Type 2 adds an observation period, commonly 3 to 12 months, plus audit fieldwork and reporting.
The biggest variable is not the audit. It is how many controls you already run informally. Teams that already use single sign-on, code review and managed laptops move much faster than teams starting from shared passwords.
How do you start SOC 2 as a founder?
Start by confirming what your customers need, then work in a fixed order: scope, gaps, risks, policies, controls, evidence, auditor. Doing policies before you know your gaps wastes weeks.
- Ask the customer who raised it which report type and categories they accept, and by when.
- Define scope: the product, systems, people and locations the report will cover.
- Run a gap check against the criteria; our free SOC 2 readiness checklist is a quick first pass.
- Name one owner with the time and authority to chase evidence.
- Assess risks and list your vendors, including your cloud provider.
- Adopt policies, fix technical and people gaps, and start collecting evidence.
- Choose a licensed CPA firm and agree the Type 1 date or Type 2 period.
Our 12-step SOC 2 checklist expands each step with what good looks like.
What do founders usually get wrong about SOC 2?
The usual mistakes come from treating SOC 2 as paperwork rather than an examination of how you actually operate.
- Buying a tool and assuming you are done. Software can collect evidence; it cannot run your offboarding or review your pull requests.
- Over-scoping. Adding Privacy because it sounds responsible can double the work. Scope to what customers ask for.
- Copying policies you do not follow. Auditors test against your policy wording.
- Leaving the auditor until last. Good firms book up; talk to them while you are still preparing.
- Forgetting it is annual. A Type 2 is a habit, not a project.
Can templates get you SOC 2?
Templates get you prepared, not audited. They give you policies, registers and a structure that auditors recognize, which removes weeks of drafting. They do not implement controls, collect evidence or issue the report. For the full picture, see our SOC 2 compliance guide.
Last reviewed: 29 September 2026