SOC 2 is an audit report produced by an independent CPA firm, describing your controls and whether they work. It exists because businesses buying services need assurance about how their data is handled, and vendor assurances are worth less than an auditor's opinion.
It is not a certification and there is no SOC 2 certificate. It is an attestation report, and the distinction matters because what you receive is a document to share under NDA rather than a badge for your website.
Type I and Type II
The difference is time, and it is the difference that matters commercially.
A Type I report examines whether your controls are suitably designed at a single point in time. It confirms you have the right controls in place on the day the auditor looked. It is faster and cheaper, and it is generally treated as a milestone rather than a destination.
A Type II report examines whether those controls operated effectively over a period — typically three to twelve months. This requires you to run the controls, generate evidence continuously, and then be audited on that evidence.
Customers who ask for SOC 2 almost always mean Type II. A Type I satisfies some buyers as an interim step with a committed date for the Type II, but it will not close a procurement process that has SOC 2 as a hard requirement.
What the report covers is your choice
SOC 2 is built on five Trust Services Criteria, and you select which apply:
- Security — mandatory in every SOC 2. Also called the common criteria. Protection against unauthorised access.
- Availability — systems are available as committed. Relevant if you make uptime commitments.
- Processing Integrity — processing is complete, valid, accurate and timely. Relevant for transaction processing.
- Confidentiality — information designated confidential is protected. Common where you handle client business data.
- Privacy — personal information is handled per your privacy notice. The least commonly included.
Most reports cover Security alone, or Security with Confidentiality and Availability. Because scope is elective, two clean reports can mean very different things — which is why anyone receiving a SOC 2 should read the scope and the period before drawing conclusions from the opinion.
What is inside the report
Worth knowing, because you will both produce and receive these:
- The auditor's opinion — the summary judgment, and the first thing anyone reads.
- Management's assertion — your own statement about your controls.
- System description — what the service is, how it works, and what is in scope.
- The controls, the tests the auditor performed, and the results.
- Optional additional information from management.
The section that matters most is the fourth, specifically any exceptions noted. A report can carry a clean opinion and still contain exceptions worth understanding. Reading only the opinion page is a common mistake.
Cost and timeline, realistically
For a small business, the audit fee itself typically runs from the low tens of thousands, varying by scope and auditor. That is the smaller part of the cost.
The larger costs are the readiness work — implementing controls you do not have, documenting policies, and putting evidence collection in place — plus the compliance automation platform most small businesses now use to manage evidence, and the internal time consumed, which is consistently underestimated.
The timeline for a first Type II is usually nine to eighteen months end to end: readiness and remediation, then the observation period, then the audit itself. Businesses that promise a customer a Type II report in three months have generally not understood that the observation period cannot be compressed.
When it is worth it
The honest test is commercial rather than technical. Pursue SOC 2 when:
- Customers are asking for it, and deals are stalling without it
- You sell to enterprises or regulated industries where procurement requires it
- You handle customer data as a core part of your service — SaaS, managed services, BPO, data processing
- Competitors have it and you are losing on that basis
It is generally not worth it when nobody has asked, when your customers are small businesses who will never request it, or when you would be pursuing it as a marketing exercise. It is expensive, ongoing, and produces a document most of your buyers will never read.
There is a middle path worth considering: build the controls SOC 2 would examine, document them properly, and complete a security questionnaire or a lighter assessment for customers who ask. Many buyers accept this, and it gets you most of the security benefit at a fraction of the cost. Commission the audit when a real deal requires it.
If you decide to proceed
- Scope deliberately. Include only the criteria and systems you need. Every addition increases cost permanently, since this repeats annually.
- Run a readiness assessment first to find the gaps before the observation period starts.
- Remediate before the clock begins. Evidence gathered during the period is what gets tested, so entering it with known gaps guarantees exceptions.
- Automate evidence collection. Manual evidence gathering is the single biggest consumer of internal time.
- Choose an auditor experienced with businesses of your size and sector.
- Plan for it to recur. SOC 2 is annual, and the controls must operate continuously rather than being assembled before each audit.
That final point is what separates businesses that find SOC 2 sustainable from those that find it exhausting. Controls designed into normal operations produce evidence automatically. Controls performed for the auditor have to be performed again next year.