Back to blog
Frameworks

SOC 2: the complete guide

What a SOC 2 report is, how Type I and Type II differ, which trust services criteria to include, what the observation window means for your timeline, and how exceptions appear in a report your customers will read.
GRC Copilot Team
SOC 2: the complete guide

SOC 2 is not a certificate — it is a report written by an accountant describing your controls and whether they worked. That single fact explains most of what follows: there is no pass mark, no badge, and the detail your customers read is far richer than anything a certificate conveys.

What a SOC 2 report actually is

An independent CPA firm examines the controls you have described and issues an attestation report. Your customers read that report — including any exceptions the auditor recorded. Unlike a certificate, which is binary and public, a SOC 2 report is detailed and shared under NDA.

Two types, and the difference is the whole timeline:

  • Type I — are the controls suitably designed at a point in time? Faster and cheaper, and generally treated as a stopgap.
  • Type II — did they operate effectively across a period, typically three to twelve months? This is what enterprise buyers mean when they ask for SOC 2.
The observation window is why SOC 2 cannot be rushed. A Type II report covering three months requires three months of evidence that already exists — you cannot compress it with budget, and starting the clock is the single most time-critical decision in the programme.

Trust services criteria: choose deliberately

Security (the "common criteria") is mandatory. The other four are optional and each expands scope, cost and audit effort:

  • Availability — include when you make uptime commitments.
  • Confidentiality — include when you hold customer data under confidentiality obligations.
  • Processing integrity — rarely needed; relevant for transaction processing.
  • Privacy — the heaviest addition, and often better addressed through a privacy programme than through SOC 2.

Ask your customers which criteria they actually require before scoping. Adding criteria "to look thorough" is a common and expensive mistake — most buyers ask only for Security, sometimes Availability.

Get audit-ready before the window opens

GRC Copilot tracks your controls and collects dated evidence continuously, so the observation period produces the record your auditor samples rather than a scramble at the end.

The path to a report

  1. Confirm what your buyers need — Type II, which criteria, by when.
  2. Scope the system — which product, environments and supporting infrastructure the report covers.
  3. Readiness assessment against the criteria.
  4. Remediate, prioritising anything that must operate throughout the window.
  5. Write the system description — your own narrative of the system and its controls, which forms part of the report and which the auditor tests against.
  6. Open the observation window and operate, collecting dated evidence as you go.
  7. Fieldwork — sampling, walkthroughs, evidence requests.
  8. Report issued, then repeat annually — with a bridge letter covering the gap between report periods.

Exceptions, and why they matter more here

When a control did not operate as described, the auditor records an exception in the report. Enough of them, or serious ones, produce a qualified opinion.

The consequence is commercial rather than administrative: unlike an ISO nonconformity, which is resolved privately, a SOC 2 exception is published in the document your prospects read for the next twelve months. An issue you would shrug off in an ISO audit deserves real attention here — which is also why "we have SOC 2" is a weaker claim than it sounds until someone reads the report.

Cost and timeline

Expect readiness work plus the observation window plus fieldwork — commonly six to twelve months end to end for a first Type II, of which the window is the irreducible part. Auditor fees scale with scope, criteria and the number of controls; internal effort typically exceeds the fee.

SOC 2 or ISO 27001?

Follow your buyers. North American enterprise software procurement generally asks for SOC 2; international and Middle East buyers expect ISO 27001. Where both apply, build one control set — the overlap is large — and sequence rather than running parallel programmes.

Detailed guidance

Audit

Buyer Guides

Checklists

Comparisons

Frameworks

Frequently asked questions

Is SOC 2 a certification?

No. It is an attestation report from a CPA firm. There is no certificate and no pass mark — the report describes your controls and any exceptions.

Type I or Type II?

Type II is what enterprise buyers mean. Type I is useful only as a stopgap while the Type II observation window runs.

How long should the observation window be?

Three months is the common minimum for a first report; subsequent reports usually cover twelve. Shorter windows are sometimes questioned by sophisticated buyers.

What is a bridge letter?

A short statement covering the gap between the end of your report period and the date a customer is asking, confirming no material changes. It is not an audit and cannot substitute for a report.

Do exceptions mean we failed?

Not necessarily — reports with exceptions are common and can still be accepted. A qualified opinion is far more serious, and everything is visible to whoever reads the report.

Key takeaways

  • SOC 2 is a report, not a certificate — customers read the detail, including exceptions.
  • The Type II observation window sets the timeline and cannot be compressed with budget.
  • Include only the trust services criteria your buyers actually ask for.
  • Exceptions are published to prospects, which raises the stakes versus an ISO nonconformity.
#soc-2 #complete-guide #pillar #trust-services-criteria #type-ii