What Is SOC 2? A Plain-English Guide for Founders

ISO Cloud Consulting editorial team
Title card: What Is SOC 2? A Plain-English Guide for Founders

SOC 2 is an independent audit report that shows customers how well a service company protects their data. A licensed CPA firm tests your controls against the AICPA Trust Services Criteria and issues an opinion. It is not a certification. Founders usually pursue it because enterprise buyers ask for it before signing.

Key facts

  • SOC 2 is an attestation report by a licensed CPA firm under AICPA standards, not a certificate.
  • It measures you against the 2017 Trust Services Criteria (revised points of focus, 2022): 61 criteria in five categories.
  • Security (33 common criteria, CC1 to CC9) is always in scope; the other four categories are optional.
  • Type 1 covers design at a point in time; Type 2 covers operating effectiveness over a period, commonly 3 to 12 months.
  • Reports are restricted-use: you share them with customers and prospects, typically under NDA.
  • No law requires SOC 2. Customers do.

What is SOC 2 in plain English?

SOC 2 is a structured way for an outside auditor to tell your customers, "we checked, and this company's security controls do what it says they do." It replaces dozens of one-off security reviews with one standard report.

SOC stands for System and Organization Controls. The framework comes from the AICPA, the US accounting profession's standards body, which is why the auditor must be a CPA firm rather than a security consultancy. The criteria describe outcomes, such as "access is removed when people leave", not specific tools. You design the controls; the auditor tests them.

That flexibility is good news for a startup. A 12-person team on one cloud provider is not expected to run the same controls as a bank. It is expected to have sensible controls that fit its risks, written down and actually operating.

Is SOC 2 a certification?

No. SOC 2 is an attestation: a CPA firm gives a professional opinion on your controls. You get a report, not a certificate, and there is no official register of "SOC 2 certified" companies.

The distinction matters in two ways. First, customers read the report itself, including any exceptions the auditor found, so a report is only as reassuring as its contents. Second, the report covers a defined system and period. Saying "we are SOC 2 compliant" without a current report behind it will not survive a careful procurement team.

Why do customers ask for a SOC 2 report?

Customers ask for SOC 2 because they remain accountable for their data even when you hold it. A report from an independent CPA firm lets their security team rely on your controls without auditing you themselves.

In practice it shows up as a line in a security questionnaire, a procurement checklist or a contract. For many US B2B software companies, it becomes a sales requirement the moment they move from small customers to mid-sized and enterprise buyers. It can also shorten reviews with partners and investors.

What does a SOC 2 report contain?

A SOC 2 report has four core sections: the auditor's opinion, management's assertion, the system description and the detailed controls with the auditor's tests. A Type 2 report also includes test results and any exceptions.

Section Who writes it What it says
Independent service auditor's report CPA firm The opinion: whether the description is fair and controls meet the criteria
Management's assertion You Your signed statement that the description and controls are accurate
System description You Services, infrastructure, software, people, data, processes and key vendors
Criteria, controls and tests Both Each control mapped to criteria; in Type 2, the tests performed and results

The system description follows the AICPA SOC 2 description criteria. Writing it well is one of the most underestimated tasks for a first audit.

What are the Trust Services Criteria?

The Trust Services Criteria are the 61 criteria a SOC 2 auditor tests against. They sit in five categories. Security is mandatory; you add the others when your customers need them.

Category Criteria IDs Count Add it when
Security (common criteria) CC1 to CC9 33 Always required
Availability A1.1 to A1.3 3 Customers depend on your uptime
Confidentiality C1.1 to C1.2 2 You hold customers' confidential business data
Processing Integrity PI1.1 to PI1.5 5 You process transactions or calculations customers rely on
Privacy P1 to P8 18 You handle personal information and customers ask for it

CC1 to CC5 mirror the COSO internal control framework: control environment, communication, risk assessment, monitoring and control activities. CC6 to CC9 cover access, operations, change management and risk mitigation, including vendors. The full criteria are published by the AICPA.

What does SOC 2 look like in a small company?

In a small company, SOC 2 is a handful of routines that someone owns and records. It is less about new paperwork and more about proving that sensible habits happen every time.

Take Fernleaf Analytics (fictional), a 15-person SaaS company on one cloud provider. Its SOC 2 controls might look like this:

  • Everyone signs in through single sign-on with MFA, and the CTO reviews who can reach production every quarter.
  • Every code change goes through a pull request that another engineer approves before it can merge.
  • Laptops are managed, encrypted and lock automatically.
  • New hires complete security training and acknowledge policies in their first week; leavers lose access on their last day.
  • A vulnerability scanner runs weekly, and critical findings are fixed within a deadline set in policy.
  • Once a year, leadership updates the risk register, reads key vendors' SOC 2 reports and tests a backup restore.

None of this is exotic. The SOC 2 work is writing it down, doing it consistently and keeping the evidence.

How is SOC 2 different from SOC 1 and SOC 3?

SOC 1 covers controls relevant to your customers' financial reporting. SOC 2 covers security and the other Trust Services categories. SOC 3 is a short, general-use summary of a SOC 2 examination that you can publish openly.

Report Focus Audience
SOC 1 Controls affecting customers' financial statements Customers and their financial auditors
SOC 2 Security, plus optional availability, confidentiality, processing integrity, privacy Customers and prospects, restricted use
SOC 3 Same criteria as SOC 2, summary only Anyone, general use

Most software companies need SOC 2. If you run payroll, billing or other processes that feed customers' financial statements, you may be asked for SOC 1 as well.

How long does SOC 2 take?

A small, cloud-based company with a dedicated owner can often be ready for a Type 1 in about three months. A Type 2 adds an observation period, commonly 3 to 12 months, plus audit fieldwork and reporting.

The biggest variable is not the audit. It is how many controls you already run informally. Teams that already use single sign-on, code review and managed laptops move much faster than teams starting from shared passwords.

How do you start SOC 2 as a founder?

Start by confirming what your customers need, then work in a fixed order: scope, gaps, risks, policies, controls, evidence, auditor. Doing policies before you know your gaps wastes weeks.

  1. Ask the customer who raised it which report type and categories they accept, and by when.
  2. Define scope: the product, systems, people and locations the report will cover.
  3. Run a gap check against the criteria; our free SOC 2 readiness checklist is a quick first pass.
  4. Name one owner with the time and authority to chase evidence.
  5. Assess risks and list your vendors, including your cloud provider.
  6. Adopt policies, fix technical and people gaps, and start collecting evidence.
  7. Choose a licensed CPA firm and agree the Type 1 date or Type 2 period.

Our 12-step SOC 2 checklist expands each step with what good looks like.

What do founders usually get wrong about SOC 2?

The usual mistakes come from treating SOC 2 as paperwork rather than an examination of how you actually operate.

  • Buying a tool and assuming you are done. Software can collect evidence; it cannot run your offboarding or review your pull requests.
  • Over-scoping. Adding Privacy because it sounds responsible can double the work. Scope to what customers ask for.
  • Copying policies you do not follow. Auditors test against your policy wording.
  • Leaving the auditor until last. Good firms book up; talk to them while you are still preparing.
  • Forgetting it is annual. A Type 2 is a habit, not a project.

Can templates get you SOC 2?

Templates get you prepared, not audited. They give you policies, registers and a structure that auditors recognize, which removes weeks of drafting. They do not implement controls, collect evidence or issue the report. For the full picture, see our SOC 2 compliance guide.

Last reviewed: 29 September 2026

Back to blog

Frequently asked questions

Who can perform a SOC 2 audit?

Only a licensed CPA firm can perform a SOC 2 examination and issue the report, because it is an attestation engagement under AICPA standards. Security consultancies and software platforms can help you prepare, but they cannot sign the opinion. Check that the firm is licensed and enrolled in AICPA peer review before you engage it.

Is SOC 2 required by law?

No. SOC 2 is voluntary. It becomes necessary when customers, usually mid-sized and enterprise buyers, require it in their vendor security review or contract. Some regulated customers may lean on it to meet their own obligations, but the requirement to have one comes from the commercial relationship, not a statute.

Can we share our SOC 2 report publicly?

Not the full report. A SOC 2 report is restricted-use and is normally shared with customers and prospects under a non-disclosure agreement. If you want something you can post on your website, ask your auditor about a SOC 3 report, which is a general-use summary based on the same examination.

What is the difference between SOC 2 and ISO 27001?

ISO 27001 is an international standard for an information security management system, and accredited certification bodies issue certificates against it. SOC 2 is a US attestation report by a CPA firm against the Trust Services Criteria. Much of the control work overlaps, but the output, audience and audit process are different.

Templates that do this job

Editable Word and Excel files. Instant download. Licensed for one organization.