Compliance · US
AICPA Trust Services CriteriaType I / Type II

SOC 2

Plain-English definition

SOC 2 is an attestation report, not a certification: an independent CPA firm audits your controls against the AICPA's Trust Services Criteria (Security is mandatory; Availability, Processing Integrity, Confidentiality, and Privacy are optional) and issues an opinion. Type I assesses control design at a point in time; Type II assesses operating effectiveness over a 6 to 12 month observation period.

Type II is what most enterprise buyers actually expect; Type I is typically a first step toward it.

Who needs it

SaaS and technology vendors whose enterprise customers require a SOC 2 report as part of vendor security due diligence, which in practice is most B2B software companies selling into mid-market or enterprise accounts.

Key requirements

Documented controls mapped to the selected Trust Services Criteria, evidence the controls actually operated as designed over the audit period (for Type II), and a formal audit performed by a licensed CPA firm.

Cyber/privacy implications

Controls need continuous evidence collection, not a point-in-time snapshot: access reviews, change management logs, and monitoring records have to be maintained consistently across the entire observation window.

Assessment methodology

Trust Services Criteria scoping, control gap assessment, evidence-collection process build-out, and a readiness (pre-audit) review before engaging your CPA firm for the formal attestation.

Implementation phases

01
Scope

Select applicable Trust Services Criteria and define system boundaries.

02
Remediate

Close control gaps and stand up continuous evidence collection.

03
Attest

Support through the formal audit with your chosen CPA firm, Type I then Type II.

Evidence & documentation requirements

Access review logs, change management records, vendor risk assessments, incident response records, and monitoring/alerting evidence, collected continuously rather than assembled after the fact.

Common mistakes

Starting evidence collection only when the audit period begins instead of building the habit beforehand; scoping in Trust Services Criteria your customers don't actually require, which adds audit cost and complexity for no sales benefit.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Do you issue the SOC 2 report?
No, only a licensed CPA firm can issue the attestation. We prepare your controls and evidence so that audit goes smoothly, and can help you select an audit firm.
Should we start with Type I or go straight to Type II?
Depends on your sales timeline: Type I is faster to obtain but Type II is what most enterprise buyers ultimately want. We'll help you decide based on what your pipeline actually needs.
Which Trust Services Criteria should we include?
Security is mandatory. Availability and Confidentiality are common additions for SaaS; we scope the rest based on what your customers actually ask for.

Request a Gap Assessment

See exactly where your controls stand before your first SOC 2 audit.

Request a Gap Assessment →