← ISO and SOC Certifications

SOC 2

A service organization controls report on the Trust Services Criteria. Updated: September 29, 2026.

SOC 2 is what North American buyers mean when they ask for your security documentation. It is not a certification, and the phrase “SOC 2 certified” does not describe anything real. It is an attestation report: an independent audit firm examines the controls you have described, tests them, and publishes an opinion along with the results of every test — including the ones you failed.

That last part is the thing to internalise, in both directions. When you receive a SOC 2 report you are being handed a list of the vendor's control failures, which is more information than any certificate gives you. When you produce one, your failures are printed in it.

What It Covers Is Your Choice

The five trust services criteria: security required, and availability, confidentiality, processing integrity and privacy optional

Security — the “common criteria” — is in every SOC 2. The other four are included only if you choose them, which is why “we have SOC 2” is an incomplete statement. If you depend on a vendor's uptime, a report that omits Availability has not examined anything about uptime. Ask which criteria are in scope before you accept the report as an answer.

Type I and Type II Are Very Different Documents

Type I tests control design on a single date while Type II tests operation across a period of three to twelve months

Type I says the controls were suitably designed as at one date. It is quick, cheaper, and a reasonable way to show progress to a customer who is waiting — but it proves only that you built something, not that you use it.

Type II says the controls operated effectively throughout a period, usually three to twelve months, with the auditor sampling evidence across that whole window. This is what buyers actually want, and it is the only one that demonstrates the controls are part of how you work. A common path is Type I first to unblock a deal, then Type II covering the following period.

What Is Inside the Report

  1. Management's assertion. Your own statement about your system and controls. You are the one making the claim; the auditor is testing it.
  2. The independent auditor's opinion. The page that matters. Unqualified means clean. A qualified opinion means something material was wrong. Adverse and disclaimer are worse and are rare.
  3. The system description. What the service is, its boundaries, and what is and is not included. This is the scope, and it is written by you.
  4. The controls, the tests, and the results. The longest section and the one worth reading. Every control, how the auditor tested it, and whether any exceptions were found.
  5. Other information, which is unaudited — typically management's response to the exceptions.

The part nobody reads: complementary user entity controls

Buried in most reports is a list of complementary user entity controls — things the report assumes you do for the vendor's controls to be effective. Configuring access properly, enabling multi-factor authentication, reviewing your own user lists. If you do not do them, the vendor's clean opinion does not protect you, and the report says so in a section most readers skip. It is the single most useful page in the document when you are assessing a supplier.

How You Get One

  1. Choose the criteria and the scope — which systems, which services, which of the five criteria. Narrow is legitimate and cheaper; too narrow and customers will reject it.
  2. Readiness assessment. Usually with an advisory firm, identifying what is missing before the auditor sees it.
  3. Implement and, crucially, start generating evidence. Access reviews with records, change tickets, onboarding and offboarding trails, vulnerability scans, incident records. Type II tests evidence across the whole period, so evidence that begins in month five of a six-month window is a finding.
  4. Engage a licensed audit firm. In the United States, a CPA firm — only they may issue the report. Confirm they are licensed and that they do this regularly.
  5. The observation period runs, with the auditor sampling from it.
  6. The report is issued, and you repeat it annually. A report older than about a year stops being accepted.

Realistically: three to six months to a Type I from a reasonable starting position, and a Type II a further three to twelve depending on the window you choose.

The Gap Between Reports

A SOC 2 report describes a period that has already ended. Today's date may be six months past the end of the window. The instrument for covering that interval is a bridge letter (sometimes a gap letter) — but note that it is written by the vendor's management, not by the auditor, and it is unaudited. It is a statement of good faith, not evidence. Treat it as such, in both directions.

SOC 2 or ISO 27001?

Where both are on the table, the market usually decides: SOC 2 for US buyers, ISO 27001 for European and Asian ones and for public tenders. The underlying control work overlaps heavily, so doing both is far less than twice the effort — and doing ISO 27001 first tends to be easier, because its management system produces the evidence discipline that SOC 2 testing depends on. See also SOC 1 for services affecting financial reporting, and SOC 3 for the publishable summary.

This page explains the report from an infrastructure perspective. We are not an audit firm and this is not legal or assurance advice.