What is SOC 2 compliance? A plain-English guide for founders
7 min read · Certifyi research team · Updated July 2026
SOC 2 is an independent audit report showing that your company handles customer data according to defined trust criteria. It is not a certificate you buy, it is an opinion issued by a licensed CPA firm after examining your controls. Most B2B SaaS companies pursue it because an enterprise buyer asked for it during procurement.
What SOC 2 actually is
SOC 2 stands for Service Organization Control 2, a reporting standard from the AICPA. Unlike ISO 27001, there is no certificate and no certification body. A licensed CPA firm examines your controls and issues a report containing their opinion.
That distinction matters commercially. You cannot "be SOC 2 certified" in the strict sense. You have a SOC 2 report, scoped to a defined system and a defined period, and you share it under NDA with customers who ask.
Who actually needs it
SOC 2 is driven by buyers, not regulators. No law requires it. In practice, if you sell software to mid-market or enterprise companies in the US, their security review will ask for it, and the deal stalls until you can produce one.
- B2B SaaS selling into US enterprise accounts
- Companies processing customer data on behalf of another business
- Vendors being onboarded through a formal procurement or TPRM process
- Startups where a specific deal is blocked pending a report
The five Trust Service Criteria
SOC 2 is built on five criteria. Only Security is mandatory. The rest you include based on what you actually promise customers.
| Criterion | Mandatory | Include it when |
|---|---|---|
| Security | Yes | Always. This is the common criteria. |
| Availability | No | You make uptime commitments in an SLA |
| Confidentiality | No | You handle data under NDA or confidentiality terms |
| Processing Integrity | No | You process transactions, payroll or financial data |
| Privacy | No | You handle personal information directly |
A common scoping mistake
- Adding every criterion "to be safe" multiplies evidence work and audit cost with no commercial benefit.
- Leaving out a criterion your customers actually care about means redoing the audit next cycle.
Type 1 versus Type 2
A Type 1 report examines whether controls are designed appropriately at a single point in time. A Type 2 report examines whether those controls operated effectively across a period, usually three to twelve months.
Type 1 is faster and can unblock an early deal. Most enterprise buyers eventually want Type 2, because a snapshot proves intent while a period proves discipline.
What the process looks like
The work splits into readiness and audit. Readiness is where most of the effort sits: scoping, risk assessment, writing policies, implementing controls and collecting evidence. The audit itself is comparatively short.
- Define scope and select your Trust Service Criteria
- Run a risk assessment and map controls to the risks
- Write and publish the policy set, then get workforce acknowledgement
- Implement technical controls: access management, logging, encryption, endpoint security
- Collect evidence continuously across the observation window
- Run a readiness review to catch gaps before the auditor does
- Engage a CPA firm for fieldwork and receive the report
Key takeaways
- SOC 2 is an auditor opinion, not a certificate.
- Security is the only mandatory criterion. Add others only where you make real commitments.
- Type 1 is a snapshot, Type 2 covers a period and is what enterprise buyers eventually expect.
- Most of the cost and time is readiness work, not the audit itself.
Frequently asked questions
Is SOC 2 a certification?
No. A licensed CPA firm issues an attestation report containing their opinion. There is no certificate and no certification body, which is the main structural difference from ISO 27001.
How long is a SOC 2 report valid?
Reports cover a stated period and are generally treated as current for twelve months. Most companies run the audit annually so there is never a gap a buyer can object to.
Can we go straight to Type 2?
Yes, if your controls are already operating. Type 1 is worth doing only when you need something in a buyer's hands quickly while the Type 2 observation window runs.
Do we have to use the platform's auditor?
No. The audit opinion must come from an independent CPA firm and you are free to choose your own. Certifyi will introduce you to auditors or work with yours.
Related reading
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.
Book a 20-min deal readiness call