SOC 2 is not a certificate — it is a report written by an accountant describing your controls and whether they worked. That single fact explains most of what follows: there is no pass mark, no badge, and the detail your customers read is far richer than anything a certificate conveys.
What a SOC 2 report actually is
An independent CPA firm examines the controls you have described and issues an attestation report. Your customers read that report — including any exceptions the auditor recorded. Unlike a certificate, which is binary and public, a SOC 2 report is detailed and shared under NDA.
Two types, and the difference is the whole timeline:
- Type I — are the controls suitably designed at a point in time? Faster and cheaper, and generally treated as a stopgap.
- Type II — did they operate effectively across a period, typically three to twelve months? This is what enterprise buyers mean when they ask for SOC 2.
The observation window is why SOC 2 cannot be rushed. A Type II report covering three months requires three months of evidence that already exists — you cannot compress it with budget, and starting the clock is the single most time-critical decision in the programme.
Trust services criteria: choose deliberately
Security (the "common criteria") is mandatory. The other four are optional and each expands scope, cost and audit effort:
- Availability — include when you make uptime commitments.
- Confidentiality — include when you hold customer data under confidentiality obligations.
- Processing integrity — rarely needed; relevant for transaction processing.
- Privacy — the heaviest addition, and often better addressed through a privacy programme than through SOC 2.
Ask your customers which criteria they actually require before scoping. Adding criteria "to look thorough" is a common and expensive mistake — most buyers ask only for Security, sometimes Availability.
Get audit-ready before the window opens
GRC Copilot tracks your controls and collects dated evidence continuously, so the observation period produces the record your auditor samples rather than a scramble at the end.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
The path to a report
- Confirm what your buyers need — Type II, which criteria, by when.
- Scope the system — which product, environments and supporting infrastructure the report covers.
- Readiness assessment against the criteria.
- Remediate, prioritising anything that must operate throughout the window.
- Write the system description — your own narrative of the system and its controls, which forms part of the report and which the auditor tests against.
- Open the observation window and operate, collecting dated evidence as you go.
- Fieldwork — sampling, walkthroughs, evidence requests.
- Report issued, then repeat annually — with a bridge letter covering the gap between report periods.
Exceptions, and why they matter more here
When a control did not operate as described, the auditor records an exception in the report. Enough of them, or serious ones, produce a qualified opinion.
The consequence is commercial rather than administrative: unlike an ISO nonconformity, which is resolved privately, a SOC 2 exception is published in the document your prospects read for the next twelve months. An issue you would shrug off in an ISO audit deserves real attention here — which is also why "we have SOC 2" is a weaker claim than it sounds until someone reads the report.
Cost and timeline
Expect readiness work plus the observation window plus fieldwork — commonly six to twelve months end to end for a first Type II, of which the window is the irreducible part. Auditor fees scale with scope, criteria and the number of controls; internal effort typically exceeds the fee.
SOC 2 or ISO 27001?
Follow your buyers. North American enterprise software procurement generally asks for SOC 2; international and Middle East buyers expect ISO 27001. Where both apply, build one control set — the overlap is large — and sequence rather than running parallel programmes.
Detailed guidance
Audit
- Design vs operating effectiveness: the distinction that decides your audit — A control can be perfectly designed and still fail an audit, or operate flawlessly and still be judged inadequate. Two separate tests, two s…
- SOC 2 bridge letters: what they cover, and what they cannot — Your report period ended in March and a customer is asking in September. A bridge letter covers the gap - but it is management's assertion,…
- SOC 2 carve-out vs inclusive: the part of the report customers misread — Your cloud provider's controls are either carved out of your report or included in it. The choice changes what your report actually proves -…
- The compliance evidence matrix: what each framework actually asks you to produce — Auditors do not ask for controls, they ask for artefacts. A control-domain-by-framework matrix of the evidence ISO 27001, SOC 2, the NCA ECC…
Buyer Guides
- How long does SOC 2 take? A realistic timeline — A phase-by-phase SOC 2 timeline - readiness, remediation, the observation window, fieldwork and reporting - plus what genuinely accelerates…
- Which compliance framework should you actually do first? — The right answer is usually decided by your customers and regulators, not by which standard is best. A decision procedure, the sequencing th…
Checklists
- SOC 2 checklist: everything to have in place before fieldwork — A working SOC 2 checklist organised by phase - scoping, policies, controls, evidence and the observation window - with the specific artefact…
Comparisons
- ISAE 3402, ISAE 3000 and SOC reports compared — European and international customers frequently ask for ISAE reports where US customers ask for SOC. What each covers, how they relate, and…
- SOC 1 vs SOC 2 vs SOC 3: which report do you need? — Three reports, three audiences. SOC 1 is about financial reporting, SOC 2 about security, SOC 3 about marketing. Plus Type I versus Type II,…
- SOC 2 vs ISO 27001: which one does your buyer actually want? — SOC 2 and ISO 27001 prove security in different ways - an attestation report versus a certificate. A direct comparison of scope, cost, timel…
Frameworks
- SOC 2 readiness: what to fix before the auditor arrives — A practical SOC 2 readiness guide - Type I versus Type II, choosing your Trust Services Criteria, the observation window, and the control ga…
Frequently asked questions
Is SOC 2 a certification?
No. It is an attestation report from a CPA firm. There is no certificate and no pass mark — the report describes your controls and any exceptions.
Type I or Type II?
Type II is what enterprise buyers mean. Type I is useful only as a stopgap while the Type II observation window runs.
How long should the observation window be?
Three months is the common minimum for a first report; subsequent reports usually cover twelve. Shorter windows are sometimes questioned by sophisticated buyers.
What is a bridge letter?
A short statement covering the gap between the end of your report period and the date a customer is asking, confirming no material changes. It is not an audit and cannot substitute for a report.
Do exceptions mean we failed?
Not necessarily — reports with exceptions are common and can still be accepted. A qualified opinion is far more serious, and everything is visible to whoever reads the report.
Key takeaways
- SOC 2 is a report, not a certificate — customers read the detail, including exceptions.
- The Type II observation window sets the timeline and cannot be compressed with budget.
- Include only the trust services criteria your buyers actually ask for.
- Exceptions are published to prospects, which raises the stakes versus an ISO nonconformity.