Pillar guide
SOC 2 compliance, explained end to end
Who needs SOC 2, and when
The five Trust Service Criteria
| Criterion | What it covers | Include it when |
|---|---|---|
| Security | Access control, change management, risk, incident response, vendor management | Always. It is mandatory. |
| Availability | Uptime commitments, monitoring, backup and recovery | You publish an SLA or customers depend on uptime |
| Confidentiality | Handling of data designated confidential | Contracts define confidential data beyond personal data |
| Processing integrity | Completeness and accuracy of processing | You process transactions or calculations customers rely on |
| Privacy | Collection, use and disposal of personal information | Rarely; GDPR or HIPAA usually cover this better |
Type I versus Type II
The 8 to 12 week path to audit-ready
Weeks 1 to 2
Scope and gap
Weeks 3 to 8
Implement
Weeks 9 to 12
Evidence and readiness
Then
Audit
What SOC 2 costs, and who you pay
| Line item | Paid to | Typical market range |
|---|---|---|
| Compliance platform and implementation | Certifyi | Priced on scope and framework, due at audit sign-off |
| External auditor (CPA firm) | Auditor, directly | $8,000 to $20,000 for a first Type II |
| Penetration test | Testing firm | $4,000 to $12,000 depending on scope |
| Internal time | Your team | 2 to 4 hours a week during implementation |
Keeping the report useful after the audit
Go deeper
Start here
Plan and budget
SOC 2 questions we hear most
Is SOC 2 a certification?
No. SOC 2 is an attestation report with an auditor’s opinion, not a certificate. There is no pass or fail; the report describes your controls and any exceptions. ISO 27001 is the framework that produces a certificate.
Do we need Type II before we can sell?
Usually not to start. Most buyers accept a Type I plus a Type II observation period in progress. Type II becomes a hard requirement at renewal or for larger contracts.
Which auditor should we use?
Any licensed CPA firm that performs SOC 2 attestations. Certifyi introduces you to auditors in its network or works with one you already know. The auditor runs the engagement inside Certifyi’s Auditor Workspace, on your record.
How much engineering time does SOC 2 take?
Two to four hours a week during weeks three to eight, mostly on access, change management and infrastructure controls. After integrations are connected, evidence collection needs almost no ongoing effort.
Can we reuse SOC 2 work for ISO 27001?
Yes. Roughly 70 to 80 percent of SOC 2 controls map to ISO 27001 in Certifyi’s shared library, so the second framework is a mapping exercise rather than a second project.