SOC 2 Compliance: Requirements, Trust Criteria, and Audit Process

SOC 2 compliance is a voluntary audit standard from the American Institute of Certified Public Accountants (AICPA) that evaluates how a service organization protects customer data. No law requires it, but enterprise buyers and companies in regulated industries routinely make a current SOC 2 report a condition of signing a contract. The examination is performed by an independent CPA firm, measures your controls against five categories called the Trust Services Criteria, and produces a detailed report you can share under NDA with clients doing vendor due diligence. Getting one takes months of preparation; keeping one takes ongoing work.

Who Actually Needs SOC 2

If your company stores, processes, or transmits customer data on behalf of other businesses, you are a candidate. Demand is heaviest among SaaS providers, cloud infrastructure companies, managed IT services, data centers, and healthcare technology vendors. Financial services firms handling transaction or account data face the same pressure. The pattern is simple: once your sales pipeline includes enterprise clients or regulated industries, SOC 2 will come up in procurement.

It bears repeating that SOC 2 is not a legal mandate. Government regulators do not require it to open a business or deliver a service. But because many buyers write it into vendor agreements as a term of doing business, lacking a current report can disqualify you from deals entirely. The “voluntary” label describes the legal status, not the commercial reality.

The Five Trust Services Criteria

Every SOC 2 examination is built around the Trust Services Criteria maintained by the AICPA’s Assurance Services Executive Committee.1AICPA & CIMA. 2017 Trust Services Criteria with Revised Points of Focus 2022 There are five categories, and only one is required in every engagement.

  • Security, also called the Common Criteria, is mandatory. It covers protection of the system against unauthorized physical and logical access. Auditors look for access controls, network monitoring, intrusion detection, and incident response procedures.
  • Availability evaluates whether the system is operational and accessible as committed in service level agreements. Disaster recovery, backups, and performance monitoring live here.
  • Processing Integrity confirms that data processing is complete, accurate, timely, and authorized. It matters most for organizations that perform calculations, transactions, or automated decision-making for clients.
  • Confidentiality addresses protection of information designated confidential, such as intellectual property, business plans, or financial data shared under agreement. Encryption, access restrictions, and retention policies are the core controls.
  • Privacy governs the collection, use, retention, disclosure, and disposal of personal information consistent with the organization’s privacy notice. Adding it can raise audit cost substantially.

Which categories you include depends on the commitments you make to customers and the data you handle. A cloud host storing client databases would almost certainly add availability and confidentiality. A vendor processing health data might add privacy. Each additional category beyond security adds auditor workload and cost, so most organizations start with security and expand as clients push for it.

Type 1 Versus Type 2

SOC 2 comes in two versions, and the difference matters more than it looks.

A Type 1 report evaluates the design of your controls at a single point in time. The auditor reviews your system description and decides whether the controls in place are capable of meeting the relevant criteria, assuming they operate as documented. It is an inspection of the blueprint. Type 1 is faster and cheaper, and many companies use it as a first step while they build the operating history needed for Type 2.2AICPA & CIMA. System and Organization Controls: SOC Suite of Services

A Type 2 report goes further. It tests whether those controls actually operated effectively over a sustained observation period, typically twelve months but sometimes as short as six. The auditor collects evidence throughout the window and samples control activities to verify that documented practice matches daily reality. This is where paper compliance falls apart: a company that looks great at a single point in time may struggle to demonstrate consistency across months of staffing changes and system updates.

Enterprise buyers overwhelmingly prefer Type 2. If your goal is to close deals with large organizations, plan for a Type 2 from the start.

How to Prepare Before the Audit

The planning phase decides whether the rest of the process is smooth or brutal. Start with scoping: identify exactly which systems, infrastructure, people, and processes touch customer data and belong inside the audit boundary. Draw the boundary too wide and you create unnecessary cost. Draw it too narrow and the report will not cover what clients care about.

A readiness assessment before the formal audit is one of the highest-value steps you can take. Treat it as a practice run: an advisor reviews your policies, technical controls, and system description against the applicable criteria and flags gaps while there is still time to fix them. Many organizations underestimate the preparation involved and only discover significant deficiencies once the formal audit has begun, when remediation becomes far more disruptive.

You will also need to prepare a management description of the system, a required component of every SOC 2 report.3AICPA & CIMA. 2018 SOC 2 Description Criteria (With Revised Implementation Guidance) It describes the services you provide, the infrastructure supporting them, the control environment, and how data flows through your systems. The auditor tests against this document, so accuracy matters. Overstating controls in the description and then failing to demonstrate them during testing is a fast route to exceptions.

Round out planning with a real risk assessment. You need to identify threats specific to your environment, document how particular controls address them, and show the controls are relevant to the vulnerabilities that actually exist. Generic risk registers copied from a template rarely hold up.

Choosing an Auditor and Budgeting

Only an independent CPA firm can perform a SOC 2 examination and issue the report. The firm must follow AICPA attestation standards, currently codified under SSAE No. 18, and maintain independence from the organization being examined.4AICPA & CIMA. AICPA SSAEs – Currently Effective

Fees vary widely based on report type, the number of criteria in scope, organizational complexity, and whether you engage a boutique firm or a larger practice. As a rough guide for 2026, Type 1 audits run between $5,000 and $20,000, and Type 2 audits run between $7,000 and $50,000 or more. Each additional criterion beyond security can add 10 to 20 percent to the base fee; privacy alone can push costs up by as much as 50 percent because of its complexity.

The audit fee is only part of the total. Budget separately for policy documentation, security awareness training, penetration testing, and risk assessments. Organizations starting from scratch on security controls should expect preparation costs to rival or exceed the audit fee. Compliance automation platforms can streamline evidence collection and control monitoring, though they carry their own subscription costs.

What Happens During the Audit

Once planning wraps up, fieldwork begins. For a Type 2 engagement, the auditor collects evidence throughout the observation period, not just at the end. Testing involves reviewing specific instances of control activities, examining system logs and configuration records, and interviewing staff to verify that security practices are embedded in daily operations rather than living only in a policy document. Auditors also directly observe physical security measures and digital workflows. This phase can stretch over several weeks of active on-site or remote work, depending on the size of the organization.

Handling Exceptions

When an auditor finds a control that did not operate as described, the result is an exception. Not every exception is catastrophic. The auditor evaluates each one against the criteria it affects and considers whether compensating controls mitigate the risk. What you cannot do is fix and retest a failure that occurred during the observation window. If a control failed in month four of a twelve-month period, that failure stays in the report even if you corrected the underlying issue in month five. That is why ongoing internal monitoring matters so much: catching problems early limits the scope of any exception.

The Final Report

The completed report includes the auditor’s opinion, your management description of the system, and detailed results of control testing for each criterion in scope. The opinion states whether the controls were suitably designed (Type 1) or both suitably designed and operating effectively (Type 2). Report creation and delivery typically take two to six weeks after fieldwork closes.

SOC 2 reports are restricted-use documents. You share them under NDA with current clients, prospective customers doing due diligence, business partners, and regulators with enough knowledge to interpret the findings. You cannot post the report on your website. If you need something for marketing, a SOC 3 report summarizes the same findings without the sensitive detail.5AICPA & CIMA. SOC 2 – SOC for Service Organizations: Trust Services Criteria

What a Qualified Opinion Means

A qualified opinion means the auditor found that one or more controls were not properly designed or did not operate effectively during the period. It is roughly analogous to disclosing a material weakness in financial reporting controls. The practical impact depends on which area was qualified. If the qualification touches a control relevant to a particular client’s use of your services, that client may not be able to rely on the report for their own risk assessment. If it covers an area unrelated to that client’s services, the effect may be limited.

Even so, qualified opinions are worth working hard to avoid. Prospective clients reviewing a qualified report often will not take the time to analyze whether the deficiency affects their use case. They move to the next vendor. In competitive markets, a clean opinion is table stakes.

Keeping Compliance Current

A SOC 2 report is not a one-time achievement. Most organizations run an annual audit cycle so clients get continuous assurance. Controls that worked last year can degrade when you change infrastructure, add products, or lose experienced staff. Internal monitoring between audits is what keeps the next examination from producing unpleasant surprises.

Bridge letters, sometimes called gap letters, cover the period between when your last report’s observation window ended and when the next report becomes available. Written on your letterhead, a bridge letter typically runs one to two pages and addresses whether any material changes occurred in the control environment since the last audit. It may confirm that nothing significant changed, or disclose specific modifications and explain their impact. Bridge letters do not carry the weight of a full third-party audit; they provide interim assurance and should cover short gaps only, ideally no more than three months.

Vendor and Subservice Oversight

If your system depends on third-party vendors or subservice organizations, your SOC 2 report must address how you manage that risk. The Trust Services Criteria require organizations to assess and manage risks tied to vendors and business partners, and your system description must disclose how you monitor the services those subservice organizations provide. Most organizations use the carve-out method, which excludes the subservice organization’s controls from the report and notes the reliance, and then address vendor risk by reviewing their vendors’ own SOC reports or performing independent risk assessments during the audit period. If you did no vendor oversight during the observation window, the auditor may accept compensating controls such as continuous monitoring tools, but this is not something to leave to chance.

How SOC 2 Differs From SOC 1, SOC 3, and HIPAA

Mixing up the SOC reports is one of the most common early mistakes. SOC 1 focuses only on controls relevant to a user entity’s financial reporting: revenue recognition, payroll processing, financial statement production. If your service affects a client’s books, SOC 1 is the relevant examination and SOC 2 will not substitute. SOC 3 is a public-facing summary of a SOC 2 Type 2 report that strips out the detailed control descriptions and test results, making it safe for general distribution.

Healthcare vendors should also understand what SOC 2 does not cover. The security criteria overlap meaningfully with the HIPAA Security Rule on access management, encryption, incident response, and risk assessment, so much of the same control infrastructure supports both. But HIPAA includes obligations that fall outside standard SOC 2 scope, including business associate agreements, the minimum necessary rule for protected health information, patient rights management, and formal notices of privacy practices. SOC 2 can show that your technical controls are sound; it does not substitute for a HIPAA compliance program.