Skip to content
02/14AttestationSupported in Compscan

SOC 2

An independent auditor's report on how well your controls meet the Trust Services Criteria.

What it is

SOC 2 (governed by the AICPA) is not a certification but an attestation: a licensed CPA firm examines your controls against up to five Trust Services Criteria — Security (always required), Availability, Confidentiality, Processing Integrity, and Privacy — and issues a report. Type I assesses design at a point in time; Type II assesses operating effectiveness over a period (typically 3–12 months). The report is shared under NDA with customers and prospects.

Certifiable?

No — you receive an attestation report, not a certificate.

Where it's used

Very common for SaaS and cloud vendors, startups, and when selling to US customers.

Effort level

Medium; Type II requires an observation window, so plan several months of evidence.

Typical trigger

A prospect's security/vendor-risk team asks "Can you share your SOC 2?" before signing.

Related frameworks

Heavy overlap with ISO 27001 and CIS; one control program can feed both.

Why it matters

SOC 2 is the de-facto trust signal for cloud and SaaS companies selling into the US market. A clean Type II report tells prospects that an independent auditor examined your controls over time and confirmed they work — not just that they exist on paper.

When is it needed?

When prospects ask to see your SOC 2 report during the sales cycle, when entering the US B2B market, or when your security questionnaire response rate is becoming a bottleneck.

Use cases

  • SaaS companies selling to US enterprises
  • Cloud infrastructure providers
  • Data processors handling customer data
  • Startups closing their first enterprise deals
  • Companies wanting to reduce security questionnaire overhead

Who asks for it?

  • US-based enterprise security and compliance teams
  • Vendor risk management functions
  • Prospects during procurement due diligence
  • Channel partners requiring trust documentation
  • Cyber insurance underwriters

Benefits

  • Accelerates sales — share the report instead of answering bespoke questionnaires
  • Independent validation from a licensed CPA firm
  • Type II proves controls work over time, not just at a point-in-time
  • Flexible scope — choose which Trust Services Criteria apply
  • Widely understood in the US market
  • Can be completed faster than ISO 27001 for initial coverage

Legal requirements

Not legally mandated, but commercially expected in the US cloud market. Many enterprise procurement processes will not proceed without a current SOC 2 Type II report.

Key control areas

Security: logical and physical access, change management, risk mitigation
Availability: performance monitoring, disaster recovery, business continuity
Confidentiality: encryption, access restrictions, data classification
Processing Integrity: quality assurance, monitoring, error handling
Privacy: notice, choice, collection, use, disclosure, retention

Want to see how Compscan maps your environment to SOC 2?