SOC 2 Compliance Explained: Plain-English Guide and Templates

SOC 2 is an independent report on how a service company protects customer data. A licensed CPA firm examines your controls against the AICPA Trust Services Criteria and gives an opinion. It is an attestation report, not a certificate. Type 1 checks controls on one date; Type 2 tests them over a period, usually 3 to 12 months.

Key facts about SOC 2

  • What it is: an attestation report issued by a licensed CPA firm under AICPA standards. There is no official "SOC 2 certified" status.
  • The yardstick: the 2017 Trust Services Criteria with revised points of focus (2022), 61 criteria in total.
  • Always in scope: Security, made up of 33 common criteria grouped CC1 to CC9.
  • Optional categories: Availability (3 criteria), Confidentiality (2), Processing Integrity (5) and Privacy (18).
  • Two report types: Type 1 covers design at a point in time; Type 2 covers design and operating effectiveness over a period, commonly 3 to 12 months.
  • Who can read it: it is a restricted-use report, shared with customers and prospects, usually under NDA.

What is SOC 2?

SOC 2 is a report in which an independent CPA firm states whether your controls meet the Trust Services Criteria. It tells customers, in a standard format, that a qualified outsider has checked how you protect their data.

SOC stands for System and Organization Controls. The report contains the auditor's opinion, management's assertion (a statement you sign), a description of your system, and the controls with the auditor's tests. The criteria say what to achieve, not how, so you pick controls that fit your company.

Who asks for a SOC 2 report?

Your customers' security and procurement teams ask for it. If your software or service stores, processes or can access customer data, a SOC 2 report is often the quickest way through a US buyer's vendor review.

The usual trigger is a deal stalled on a long security questionnaire, or a contract clause asking for a current SOC 2 Type 2 report. No law requires SOC 2; it is a market expectation that grows with the size of your buyers.

What is the difference between SOC 2 Type 1 and Type 2?

A Type 1 report says whether your controls are suitably designed and in place on a single date. A Type 2 report also says whether they operated effectively across a period. Most enterprise buyers eventually want Type 2; Type 1 is the faster first step.

Question Type 1 Type 2
What is tested? Design and implementation as of one date Design and operating effectiveness over a period
What evidence? Policies, configurations and one example of each control Samples from across the whole period: tickets, access reviews, logs
How long? Weeks once you are ready The observation period (commonly 3 to 12 months) plus fieldwork and reporting
Best for Unblocking early deals and showing you have started Larger contracts, renewals and mature security teams
Main risk Buyers ask "when is your Type 2?" Skipped controls appear as exceptions

What are the SOC 2 Trust Services Criteria?

The Trust Services Criteria are the 61 criteria a SOC 2 auditor measures you against. Security, the 33 common criteria in series CC1 to CC9, is always included. Availability, Confidentiality, Processing Integrity and Privacy are optional and added only when customers need them.

CC1 to CC5 follow the five COSO internal control components; CC6 to CC9 cover IT-specific areas. Plain meanings are our paraphrase; read the official Trust Services Criteria for the full text.

Series Topic Plain meaning Typical evidence
CC1 Control environment Leaders set the tone: ethics, oversight, clear roles, competent people, accountability. Code of conduct sign-offs, org chart, background checks
CC2 Communication and information Staff and customers know what is expected and how to report problems. Published policies, customer terms, reporting channel
CC3 Risk assessment You identify what could go wrong, including fraud and change, and decide what to do. Risk register, annual risk assessment
CC4 Monitoring activities You check that controls work and fix what does not. Control reviews, penetration test, remediation log
CC5 Control activities You choose controls for your risks and put them into policies. Policies, control matrix
CC6 Logical and physical access Only the right people get in, access is removed promptly, data is protected. Access reviews, MFA, offboarding tickets, encryption settings
CC7 System operations You detect vulnerabilities and anomalies, respond to incidents and recover. Scan results, alerts, incident tickets
CC8 Change management Code and infrastructure changes are authorized, tested and approved. Reviewed pull requests, CI results
CC9 Risk mitigation You plan for disruption and manage vendor and partner risk. Vendor reviews, continuity plan
  • Availability (A1.1 to A1.3): capacity, backups and tested recovery. Add it if customers depend on your uptime.
  • Confidentiality (C1.1 to C1.2): identifying, protecting and disposing of confidential information. Common for B2B data holders.
  • Processing Integrity (PI1.1 to PI1.5): processing that is complete, accurate, timely and authorized. Relevant for payments, payroll or data pipelines.
  • Privacy (P1 to P8, 18 criteria): how you collect, use, keep, disclose and protect personal information. A heavy lift; add it only when customers ask.

What documents do you need for SOC 2?

You need approved policies, a risk assessment, a vendor register, a control matrix, a system description and evidence that each control runs. Policies say what you do; evidence proves it.

  • Policies: usually 15 to 20, covering security, access, change, incidents, vendors, risk, people and continuity. See our SOC 2 policy templates for a mapped set of 20.
  • Risk and vendor registers: the backbone of CC3 and CC9.
  • Control matrix: each control's owner, frequency, criteria IDs and evidence location.
  • System description: your services, infrastructure, software, people, data and processes, plus the controls you rely on at vendors and customers.
  • Evidence: access reviews, onboarding and offboarding records, training completions, change tickets, scan results, incident log and a backup restore test.

How do you get ready for a SOC 2 Type 1 in 90 days?

A small, cloud-based company with one committed owner can often reach Type 1 readiness in about 90 days by working in this order. A Type 2 adds its observation period on top.

  1. Days 1 to 10, scope: choose the product, systems and criteria categories in scope, name an owner and run a gap check.
  2. Days 10 to 25, risk and vendors: build the risk register and vendor inventory; collect key vendors' own SOC 2 reports.
  3. Days 15 to 40, policies: tailor, approve and publish policies; collect staff acknowledgments.
  4. Days 30 to 60, technical controls: enforce single sign-on and MFA, device encryption, logging and alerting, vulnerability scanning, code review rules and backups. Start talking to auditors now.
  5. Days 45 to 70, people controls: training, background checks, onboarding and offboarding checklists.
  6. Days 60 to 80, evidence: complete the control matrix, draft the system description, run a first access review and a restore test.
  7. Days 75 to 90, audit-ready: engage the CPA firm, agree scope and the Type 1 date, and fix what your dry run found.

Our 12-step SOC 2 checklist breaks each stage down further.

How do you choose a SOC 2 auditor?

Choose a licensed CPA firm enrolled in AICPA peer review that regularly audits companies of your size and tech stack. Only a CPA firm can issue a SOC 2 report. Compare at least two written proposals.

  • Ask for their latest peer review result and how many SOC 2 reports they issue for companies like yours.
  • Ask which evidence formats they accept and how they treat your cloud provider (usually the "carve-out" method, where you rely on the provider's own report).
  • Ask how long reporting takes after the period ends and what triggers extra fees.
  • Be wary of "fast and easy" offers; the AICPA has warned they threaten the credibility of SOC reports.
  • Keep independence: your auditor should not also design and run your controls.

How much does SOC 2 cost?

There is no standard price. Cost depends on scope, report type, company size, readiness and the auditor, so request comparable quotes rather than trusting headline figures. Budget for internal time and tools too.

Cost driver Why it moves the budget
Report type and period Type 2 means more testing; a longer period means more samples.
Criteria in scope Each optional category adds controls and tests. Privacy adds the most.
Size and complexity More people, systems, products and locations mean more controls to test.
Readiness Gaps found during fieldwork cost more to fix than gaps found beforehand.
Tools and testing Identity, device, logging and scanning tools, an optional platform, and a penetration test most buyers expect.
Internal time Owner and engineer hours are the cost founders most often underestimate.

Do you need a compliance-automation platform for SOC 2?

No, a platform is optional. It automates evidence collection and monitoring, which pays off for larger or fast-growing teams. A small team with a simple stack can prepare with good templates, a disciplined evidence calendar and a capable auditor. Only the CPA firm issues the report.

Templates give you the documents and structure. They do not connect to your systems or collect evidence.

What are the most common SOC 2 mistakes?

  • Scoping too wide: adding categories nobody asked for.
  • Policies that describe fiction: auditors test what the policy says, so a copied "weekly log review" you never do becomes an exception.
  • Starting the Type 2 period too early, before controls are stable.
  • Late offboarding: access removed days after a leaver goes is a classic exception.
  • Ignoring vendors: never reading your cloud provider's report or the controls it expects you to run.
  • Treating the report as a finish line: customers expect a new one every year.

Which SOC 2 template fits your stage?

Start with the free checklist, then buy only what closes your gaps. All templates are editable Word and Excel files for one organization, with a refund within 5 days if a template does not fit your system.

Your stage Template Price
Just asked for SOC 2, unsure where you stand Free SOC 2 Readiness Checklist Free
Need policies written and approved SOC 2 Policy Templates Pack (20 policies) $129
Scoping and scoring gaps against the criteria SOC 2 Readiness Assessment & Control Matrix $59
Building the risk and vendor registers SOC 2 Risk Assessment & Vendor Management Kit $49
Drafting the system description and preparing fieldwork SOC 2 Audit Prep & System Description Kit $49
Starting from zero and want the core set SOC 2 Starter Bundle (Policies, Readiness Matrix, Risk & Vendor) $199 (was $237)
Want everything through to audit prep SOC 2 Compliance Toolkit $249 (was $286)

Browse the full SOC 2 templates collection. Templates help you prepare. They do not guarantee a clean SOC 2 report, and you still need a CPA firm for the audit itself.

Last reviewed: 29 September 2026

Frequently asked questions

Is SOC 2 a certification?

No. SOC 2 is an attestation report. A licensed CPA firm examines your controls and issues an opinion on them under AICPA standards. You receive a report, not a certificate, and you share it with customers under NDA. Anyone who promises to make you "SOC 2 certified" is using loose language, so check exactly what they will deliver.

How long does it take to get a SOC 2 report?

For a small cloud-based company, readiness often takes around three months with a committed owner. A Type 1 report can follow within weeks of being ready. A Type 2 then needs an observation period, commonly 3 to 12 months, plus fieldwork and reporting time, so a first Type 2 usually lands well after the first Type 1.

Which Trust Services Criteria should a startup include?

Start with Security, which is mandatory and covers the 33 common criteria. Add Availability if customers depend on your uptime and Confidentiality if you hold their sensitive business data. Add Processing Integrity or Privacy only when a customer contract or a clear market need calls for them, because each category adds controls, evidence and audit effort.

Can we write our own SOC 2 policies?

Yes. The criteria do not require any specific wording or supplier. What matters is that each policy is approved by management, communicated to staff, reviewed on a schedule and matches what you actually do. Templates speed this up, but you must tailor frequencies, owners and tools to your real operations before approval.

How often do you need a new SOC 2 report?

The report has no formal expiry date, but most customers expect a current Type 2 report every 12 months. Companies usually run back-to-back annual periods so there is no gap in coverage. Between reports, management can provide a bridge letter describing any significant changes since the last period ended.

Not ready to buy? Start with the free SOC 2 readiness checklist

30 questions that show how close you are to a SOC 2 audit, before you spend money on auditors or platforms.