Pillar guide

SOC 2 compliance, explained end to end

What SOC 2 is, who asks for it, what the auditor checks, how long it takes and what it costs. Written by the Certifyi compliance team for founders, CTOs and IT leads doing their first report.
SOC 2 in one paragraph. SOC 2 is an attestation report issued by an independent CPA firm that says your security controls are designed properly (Type I) and, over an observation period, operated as described (Type II). It is not a certificate and there is no pass mark; the report describes your controls against the Trust Service Criteria and states the auditor’s opinion. US enterprise buyers ask for it before signing.

Who needs SOC 2, and when

If you sell software to US companies and hold their data, a SOC 2 request usually arrives with the first enterprise deal, often from procurement or the customer’s security team. Companies selling into the EU, UK or APAC are more often asked for ISO 27001 first. Many end up needing both, which is why Certifyi maps them to one control library.
The practical trigger is a deal. If a security questionnaire or a “do you have a SOC 2 report?” email is already in your inbox, the clock has started. If it is not, the right time is roughly six months before you expect that email, so Type II observation can run while you sell.

The five Trust Service Criteria

Every SOC 2 report covers Security (the Common Criteria). The other four are optional and should be added only when customers or your service model require them.
CriterionWhat it coversInclude it when
SecurityAccess control, change management, risk, incident response, vendor managementAlways. It is mandatory.
AvailabilityUptime commitments, monitoring, backup and recoveryYou publish an SLA or customers depend on uptime
ConfidentialityHandling of data designated confidentialContracts define confidential data beyond personal data
Processing integrityCompleteness and accuracy of processingYou process transactions or calculations customers rely on
PrivacyCollection, use and disposal of personal informationRarely; GDPR or HIPAA usually cover this better

Type I versus Type II

A Type I report is a point-in-time opinion: on the audit date, the controls were designed and in place. A Type II report adds an observation period, normally three to twelve months, during which the auditor samples evidence to confirm the controls operated. Most enterprise buyers eventually want Type II. Many accept a Type I plus a Type II in progress, which is the sequence Certifyi recommends for a first report.

The 8 to 12 week path to audit-ready

Audit-ready means your scoped controls, policies, risk register and evidence workflows are in place and the auditor is engaged. With a named compliance lead running weekly implementation, Certifyi customers reach that point in 8 to 12 weeks. The sequence is the same every time.

Weeks 1 to 2

Scope and gap

Systems, data flows and criteria agreed. Risk register and policy set drafted from a library that has passed audits.

Weeks 3 to 8

Implement

Controls built with your engineers. Cloud, identity, code and ticketing integrations connected so evidence starts flowing.

Weeks 9 to 12

Evidence and readiness

Access reviews, vendor assessments, vulnerability SLAs and training evidenced. Internal readiness review against every criterion.

Then

Audit

Auditor works in their own workspace on your record. Type I issued; Type II observation period starts.

What SOC 2 costs, and who you pay

There are four line items, and only one of them is the platform. The audit fee goes directly to the CPA firm and is never included in a software subscription, whatever a vendor says. Penetration testing is separate and expected annually by most frameworks. Internal time is the cost most teams forget: with automated evidence it drops to a few hours a week during implementation.
Line itemPaid toTypical market range
Compliance platform and implementationCertifyiPriced on scope and framework, due at audit sign-off
External auditor (CPA firm)Auditor, directly$8,000 to $20,000 for a first Type II
Penetration testTesting firm$4,000 to $12,000 depending on scope
Internal timeYour team2 to 4 hours a week during implementation

Keeping the report useful after the audit

A SOC 2 report is dated. Buyers read the period covered and the exceptions. Continuous monitoring, scheduled access reviews and vendor re-assessments keep the next period clean, and a public Trust Center lets prospects read the current posture without an NDA and an email thread.

SOC 2 questions we hear most

No. SOC 2 is an attestation report with an auditor’s opinion, not a certificate. There is no pass or fail; the report describes your controls and any exceptions. ISO 27001 is the framework that produces a certificate.

Usually not to start. Most buyers accept a Type I plus a Type II observation period in progress. Type II becomes a hard requirement at renewal or for larger contracts.

Any licensed CPA firm that performs SOC 2 attestations. Certifyi introduces you to auditors in its network or works with one you already know. The auditor runs the engagement inside Certifyi’s Auditor Workspace, on your record.

Two to four hours a week during weeks three to eight, mostly on access, change management and infrastructure controls. After integrations are connected, evidence collection needs almost no ongoing effort.

Yes. Roughly 70 to 80 percent of SOC 2 controls map to ISO 27001 in Certifyi’s shared library, so the second framework is a mapping exercise rather than a second project.

Ready to scope your SOC 2?

Twenty minutes with a compliance lead. You leave with the criteria in scope, a gap list and a realistic audit-ready date.
Scroll to Top