If you are a B2B SaaS founder, CTO, or sales leader in North America, you will eventually face a prospect who refuses to sign a contract until you answer a simple question: “Are you SOC 2 compliant?”

But what is SOC 2, really? Is it a certification? A technical test? A legal requirement?

This guide breaks down exactly what SOC 2 is, how the audit process works, the difference between the report types, and what your engineering team needs to do to pass.

The Quick Answer: What is a SOC 2 Report?

SOC 2 (System and Organization Controls 2) is a voluntary compliance standard for service organizations, developed by the American Institute of CPAs (AICPA). It specifies how organizations should manage customer data.

A SOC 2 report is a formal document issued by an independent CPA firm. It proves to your customers that you have implemented the necessary security policies and technical controls to protect their sensitive data against unauthorized access.

The 5 Trust Services Criteria (What is SOC 2 Security?)

A SOC 2 audit evaluates your organization against the AICPA’s Trust Services Criteria (TSC). There are five criteria in total.

You do not need to be audited against all five. The only mandatory criterion is Security. The others are optional, allowing you to tailor the audit scope to the specific services you provide.

Mandatory
🔒

Security

The foundational requirement. Evaluates access controls, firewalls, two-factor authentication, intrusion detection, and how you protect the system against unauthorized access.

⏱️

Availability

Evaluates whether your system is available for operation as committed by SLAs. Includes network performance monitoring, disaster recovery, and incident response.

🤫

Confidentiality

Applies if you agree to keep specific data confidential (e.g., intellectual property, business plans). Requires encryption, strict access controls, and data retention policies.

⚙️

Processing Integrity

Crucial for fintech and data-processing tools. Ensures your system processes data accurately, completely, and exactly as authorized, without accidental manipulation.

👁️

Privacy

Evaluates how your system collects, uses, retains, and disposes of Personal Information (PII) in conformity with your privacy notice and AICPA privacy criteria.

When people ask what is SOC 2 security, they are referring to the mandatory Security criterion (known as the Common Criteria). It contains 33 specific controls covering risk management, HR security, logical access, and change management.

What is a SOC 2 Type 1 vs Type 2 Report?

Once you decide which criteria to include in your scope, you must decide how you want to be audited. There are two variations of the report.

What is a SOC 2 Type 1?

A Type 1 report (or Type I) is a snapshot in time. It evaluates the design of your security controls on a specific date.

The auditor looks at your system and asks, “Did this company design a process that should keep data safe as of today?” It is the fastest way to achieve compliance, taking roughly 4 to 8 weeks of preparation, and is highly recommended for early-stage startups.

What is a SOC 2 Type 2?

A Type 2 report (or Type II) evaluates the operating effectiveness of your controls over a period of time (typically 6 to 12 months).

The auditor looks at your system and asks, “Did this company actually follow their own security rules every day for the last 6 months?” This is the enterprise gold standard. It takes significantly longer because you must endure the observation window before the auditor can pull historical evidence.

Read the full guide on SOC 2 Type 1 vs Type 2 differences.

What is the Difference Between SOC 1, SOC 2, and SOC 3?

A frequent source of confusion during enterprise procurement is the distinction between SOC 1, SOC 2, and SOC 3. While they are all audit frameworks created by the AICPA, they serve entirely different purposes and target different audiences.

FeatureSOC 1SOC 2SOC 3
Primary FocusFinancial reporting controlsSecurity & data protectionSecurity & data protection
Target AudienceFinancial auditors, CFOsSecurity teams, CTOs, B2B buyersThe general public, website visitors
Level of DetailHighly detailed (Restricted)Highly detailed (Requires NDA)High-level summary (Public)
Who Needs It?Payroll providers, billing enginesSaaS platforms, IT servicesSaaS companies wanting marketing

What is the difference between a SOC 1 and SOC 2 report? If your software impacts your customer’s financial statements (e.g., you process their payroll or calculate their revenue), you need a SOC 1. If your software simply holds their sensitive data (e.g., an applicant tracking system, a CRM, or a developer tool), you need a SOC 2.

What is a SOC 3? A SOC 2 report is highly confidential. You can only share it with prospects after they sign a Non-Disclosure Agreement (NDA) because it details your exact security infrastructure. A SOC 3 is a public, redacted version of a SOC 2 report. It contains the auditor’s stamp of approval without revealing the sensitive internal details, allowing you to post it freely on your marketing website.

What are the SOC 2 Compliance Requirements?

Unlike PCI-DSS or HIPAA, SOC 2 does not offer a rigid, prescriptive checklist of technical requirements (e.g., “You must use AES-256 encryption” or “You must rotate passwords every 90 days”).

Instead, the AICPA provides 33 broad criteria. It is up to your organization to define the specific controls (policies and tools) you will use to meet those criteria.

So, what exactly do modern auditors expect from B2B SaaS companies? While flexibility exists, most firms look for this standard baseline of SOC 2 compliance requirements:

  1. Access Controls: Multi-Factor Authentication (MFA) must be enforced across all critical systems (AWS, GitHub, Google Workspace).
  2. Endpoint Security: Employee laptops must be secured using Mobile Device Management (MDM) software to enforce screen locks and hard drive encryption.
  3. Change Management: All code changes must go through version control, require a peer review (pull request approval), and pass automated CI/CD checks before being deployed to production.
  4. Vulnerability Management: You must run regular vulnerability scans on your infrastructure and conduct an annual penetration test by an independent third party.
  5. HR Security: All employees must undergo background checks prior to hiring and complete annual security awareness training.
  6. Incident Response: You must have a formal, documented plan for how your team will detect, report, and remediate a security breach or data leak.

The SOC 2 Audit Process

You cannot issue your own SOC 2 report. To achieve compliance, you must hire an independent, licensed CPA (Certified Public Accountant) firm.

What is a SOC 2 audit? It is the formal evaluation conducted by this CPA firm. The process generally follows these steps:

  1. Readiness Assessment: You evaluate your current systems against the 33 criteria to identify security gaps.
  2. Remediation: Your engineering and HR teams fix the gaps (e.g., writing policies, turning on MFA, setting up MDM).
  3. Observation (Type 2 Only): You run your business normally for 6 to 12 months, ensuring your team actually follows the new rules.
  4. Fieldwork: The CPA firm requests evidence. They will ask for screenshots, log files, and pull request histories to prove your controls work.
  5. Report Issuance: The CPA firm drafts the final report, attaching their formal opinion on your security posture.

Frequently Asked Questions

What is a SOC 2 certificate? Does it exist?

No. There is no official “SOC 2 certificate” or badge. When people ask “soc2 certification what is it”, they are using the wrong terminology. The AICPA does not issue a printable certificate you can hang on a wall.

The output of your audit is a SOC 2 Report — a dense, 40-to-100-page PDF document authored by your CPA firm. When a customer asks for your “SOC 2 certification,” they actually want you to send them this PDF report under an NDA.

Who needs SOC 2 compliance?

Any B2B technology company that stores, processes, or transmits sensitive customer data in the cloud. If you sell software to mid-market or enterprise companies in North America, SOC 2 is a non-negotiable prerequisite for passing their vendor security review.

How much does it cost?

A Type 1 audit typically costs between $10,000 and $20,000 in CPA fees. A Type 2 audit costs between $20,000 and $40,000. These numbers do not include the internal engineering time required to prepare, or the cost of external tools like penetration tests and compliance platforms.

Read our complete breakdown of SOC 2 costs.

How long does it take?

A Type 1 report can be achieved in 8 to 14 weeks. A Type 2 report requires an observation window, pushing the total timeline to 10 to 16 months.


Ready to start mapping your controls? Skip the massive SaaS contracts and start your gap analysis today. → Request early access to our internal tools.

Track your SOC 2 readiness — no enterprise contract required.

SOC2Checklist gives you all 33 AICPA criteria mapped, assigned, and tracked. No sales call. No credit card.

Request Early Access