SOC 2 readiness is the work you do before the formal audit starts: selecting criteria, implementing controls, and generating the evidence an auditor will sample. SOC 2 is an attestation report produced by a licensed CPA firm against the AICPA Trust Services Criteria - not a certificate, and not a checklist you can simply tick.
Type I or Type II?
- Type I assesses whether your controls are suitably designed at a single point in time. It is faster and often used to satisfy an urgent customer requirement.
- Type II assesses whether those controls operated effectively across an observation window, typically three to twelve months. This is what enterprise buyers usually want.
If a customer has not specified, assume they mean Type II.
Choosing your Trust Services Criteria
Security (the "common criteria") is mandatory. The other four are optional and should be chosen based on the promises you make to customers:
- Security - required in every SOC 2 report.
- Availability - include if you commit to uptime SLAs.
- Confidentiality - include if you handle customer data under confidentiality obligations.
- Processing Integrity - include if you process transactions where accuracy is the product.
- Privacy - include if you handle personal information and make privacy commitments.
Adding criteria you do not need expands the audit and its cost. Start with Security and add deliberately.
The readiness sequence
- Scope the system. Define the product, infrastructure, people and data covered by the report.
- Run a readiness assessment or gap analysis against the selected criteria.
- Write and approve policies - access control, change management, incident response, risk assessment, vendor management, business continuity.
- Implement the controls and, just as importantly, make them produce records automatically.
- Run a risk assessment and document it - auditors always ask.
- Complete vendor due diligence on your subservice organisations.
- Open the observation window and operate cleanly throughout it.
- Engage the CPA firm for fieldwork and evidence sampling.
Know your SOC 2 gaps before your auditor does
GRC Copilot runs a readiness assessment against the Trust Services Criteria, tracks evidence continuously through your observation window, and flags control failures while you can still fix them.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
The gaps that derail first audits
- Access reviews never performed. Quarterly user access reviews with documented approval are among the most sampled controls.
- Offboarding gaps. Auditors compare your HR leaver list against active accounts. Any mismatch is an exception.
- Change management without approval records. Pull requests merged without review break the control.
- No risk assessment. A documented, dated risk assessment is not optional.
- Untested backups and incident response. Auditors want evidence of a test, not the existence of a plan.
- Vendor management theatre. Collect and review subservice organisation reports rather than merely listing suppliers.
The observation window is unforgiving. A control that fails in month two of a six-month Type II window becomes an exception in your final report, so start the window only when your controls genuinely operate.
Frequently asked questions
How long does SOC 2 readiness take?
Two to four months of remediation is typical before the observation window opens, then three to twelve months of observation for Type II, followed by several weeks of fieldwork and report writing.
Is SOC 2 a certification?
No. It is an attestation report issued by a CPA firm describing your controls and the auditor's opinion. There is no certificate or registry.
Can we do Type I first and Type II later?
Yes, and many companies do. Type I unblocks a deal quickly, and the same control set carries into a Type II window afterwards.
Does ISO 27001 help with SOC 2?
Substantially. The underlying controls and much of the evidence overlap, so organisations with a working ISMS usually reach SOC 2 readiness faster.
Key takeaways
- Security criteria are mandatory; add the other four only where you make those commitments.
- Type II tests operating effectiveness over time - evidence history is everything.
- Access reviews, offboarding and change approvals cause the most exceptions.
- Do not open the observation window until controls genuinely run.